The idea is the same as Codex Security.
1. Build a threat model 2. Launch a lot of probing agents looking into the security based on the threat model 3. Deduplication 4. Validation 5. Severity and likelihood calibration
We did a deep dive article here on it as well https://x.com/GustavHartz/status/2084926544800035266