license: other
license_name: qwen-research
base_model: rohit267/Qwen3.8-9B-heretic-uncensored
tags:
- uncensored
- cybersecurity
- xrpl
- bug-triage
- exploit-writeup
- qlora
- gguf
- agent
language: - en
pipeline_tag: text-generation
library_name: transformers
Qwen3.8-9B Cyber Exploit Agent — v3 (Writer + Host Agent)
- Host classifies C0–C8; 9B writes under CLASS_LOCK.
- GGUF alone is NOT an XRPL triage oracle — run agent_v3.py.
- Measured, frozen lock-eval: v3.3 adapter alone 7/9 gates (FAIL, refusals 2/8) · v3c DPO continue 6/9 + L2 regression (FAIL, discarded) · smoke v2 with agent_v3.py: 6/6.
- SFT format adapter; live fetch XRPLF/rippled develop + XRPL-Standards via the host. No Mythos/GLM claims.
What this is
An uncensored (heretic base, refusal-smoke 8/8 pre-SFT) QLoRA SFT adapter that reliably
produces structured offensive-security output (<think> + ### TRIGGER + ### EXPLOIT WRITEUP
### VERDICT) for C/C++/Python labs, public CVE writeups and XRPL bug reports.
Triage classification is done by the bundled host agent (agent_v3.py), which fetches
live source (raw.githubusercontent.com, XRPLF repos only, rippled@develop) and applies
deterministic rules C0–C8. The 9B writes the trigger/writeup underCLASS_LOCK; the host
enforces the verdict line and strips track-tag drift on memory labs.
What this is NOT
- Not an oracle: without
agent_v3.py, XRPL VALID/FALSE_POSITIVE verdicts oscillate
(see gate table). Do not use the GGUF alone for XRPL VALID/FP decisions. - No built-in web search. All fetching happens in the host script.
- SFT-only (no RL). Not trained on the frozen lock set.
Gate table (frozen eval_lock_v4.json, 3 draws @ 0.6/0.95/20/rep1.05/1600)
| Config | Lock-Eval result |
|---|---|
| v3.3 adapter alone | 7/9 gates, refusals 2/8 — FAIL |
| v3c (DPO continue, discarded) | 6/9 + L2 regression — FAIL |
| v3.3 + agent_v3.py (host C0–C8) | agent_smoke_v2: 6/6 — PASS |
Per-item draws and rule evidence: agent_smoke_v2.md, ship_gate_v4.log, eval_lock_v4.json.
Usage
# 1) serve the Q4 GGUF (no mmproj):
llama-server -m Qwen3.8-9B-Cyber-Exploit-Agent-v3-Q4_K_M.gguf \
--jinja -c 8192 -ngl 99 --port 8739
# 2) run the two-role pipeline (host classifies on live source, 9B writes):
python agent_v3.py --smoke2 # 6-item acceptance smoke
python agent_v3.py --ask "<bug report>"
python agent_v3.py --ask "..." --hunt
python agent_v3.py --test-rules # offline rule unit tests, no GPU
Sampling: temp 0.6, top_p 0.95, top_k 20, repeat_penalty 1.05, max_tokens ≥ 3000
(see INFERENCE_RUNBOOK.md). Host allowlist: raw.githubusercontent.com + api.github.com,
XRPLF repos only, rippled@develop / XRPL-Standards@master / clients@main.
LM Studio instead of llama-server
The host speaks plain OpenAI-style chat completions, so LM Studio works too:
- Load the Q4 GGUF in LM Studio, open Developer → Start Server (default
http://127.0.0.1:1234). - Point the agent at it:
AGENT_API_URL=http://127.0.0.1:1234/v1/chat/completions python agent_v3.py --ask "<report>"
(or edit theAPIdefault at the top ofagent_v3.py). Sampling (temp 0.6 / top_p 0.95 /
top_k 20 / repeat_penalty 1.05 / max_tokens ≥ 3000) is sent with every request by the host. - In OpenCode / any agent harness: keep the xrpl-drill skill on the orchestrating agent
(fetch + six tests + CLASS_LOCK) and let this 9B serve as the writer endpoint. Never ask
the bare GGUF for XRPL VALID/FP.
Bug Hunting — CVE sources (via the xrpl-drill skill, hand-in-hand with this model)
For bug hunting and triage, download the paired skill xrpl-drill.zip from this
repo's Files section and unpack it next to agent_v3.py. The skill is decisive: it encodes
the hunt engine (CVE → rippled develop map), the six ledger tests, the FP catalog from
maintainer-closed issues (xrpl_raw_comments_full.jsonl in Files) and the N11–N18 pattern
families. Model (writer) + host (classifier) + skill (drill) work hand-in-hand — for XRPL
none of them is optional.
The hunt walks live public CVE feeds before any "no new C++/Python/JS primitive in the
tree" claim. Generic C++ CVEs are the funnel; blockchain CVEs are optional. Rule:primitive + symbol + patch, then grep a local rippled develop clone andraw.githubusercontent.com/XRPLF/rippled/develop. A CVE name-drop without a develop or
client file:line is not a finding.
| Priority | Sources (public only) |
|---|---|
| P0 — earliest, fetch first | oss-security (openwall.com/lists/oss-security) · OSS-Fuzz bugs (bugs.chromium.org/p/oss-fuzz) + oss-fuzz-vulns · OSV (osv.dev, api.osv.dev/v1/query) · GHSA (github.com/advisories, github/advisory-database) · Full Disclosure (seclists.org) · Project Zero · ZDI published · syzbot (only if same allocator idiom) |
| P1 — official CVE | cve.org · NVD (nvd.nist.gov + services.nvd.nist.gov REST 2.0) · OpenCVE (app.opencve.io) · CISA KEV (in-the-wild only) · EPSS · EUVD · distro trackers (Debian/Ubuntu/RedHat) |
| P2 — public PoCs | Exploit-DB · Packet Storm · AttackerKB · huntr · HackerOne Hacktivity · GitHub code search (poc CVE-… + lib) |
| P3 — XRPL dependency feeds | Boost / OpenSSL / RocksDB / Protobuf / libsecp256k1 / NuDB releases · npm (xrpl) · PyPI (xrpl-py) · Maven (xrpl4j) via OSV/GHSA |
Per hunt session: at least 2× P0 + 1× P1 + local grep, then map into develop /
clients (references/15-cve-to-rippled-hunt.md, full feed catalog inreferences/17-cve-feeds.md inside the zip). N11 is XRPL self-protection — never a kernel
UAF label. linux-distros embargo list: know it exists, do not crawl. Darknet/0day
brokers/leaked embargo drops: skip. Full raw crawl corpus (issues + maintainer comments)
ships in Files: xrpl_raw_issues_v3.jsonl, xrpl_raw_comments_full.jsonl.
Acknowledgments
This work stands on the public track record of the rippled maintainers and contributors.
Their bug submissions, reproductions and — above all — their verdict comments ("intentional",
"working as designed", fix confirmations) in the XRPLF/rippled GitHub tracker are the raw
material this model's triage discipline and the false-positive catalog were built on
(xrpl_raw_issues_v3.jsonl / xrpl_raw_comments_full.jsonl in Files; 105 contributors in
the crawl, 1,930 unique issues).
Special thanks to the top contributors whose historical records shaped the corpus:
mvadari · JoelKatz (David Schwartz) · vinniefalco · ahbritto · nbougalis · seelabs ·
ximinez · scottschurr · HowardHinnant · miguelportilla · mellery451 · rec · bthomee ·
mathbunnyru · justmoon
…plus the wider v3 crawl — among them WietseWind, RichardAH, RareData, BobWay, Bronek,
Silkjaer, MarkusTeufelberger and all others in the public tracker. Every "not a bug" a
maintainer once wrote by hand is, decades of their judgment compressed, exactly what this
pipeline refuses to guess. Thank you.
Caution
Use it only for whitehat intent — not to damage other systems, never for harmful purposes.
Think twice; be a good person and do good things: help other people find bugs. Think always twice.
This is an uncensored version, meaning the safety filters placed by the Qwen maintainers were
removed (heretic base, refusal-smoke 8/8 before SFT) and the model was fine-tuned into a custom
bug-triage / bug-hunting mode. I am not responsible for any damages or harm you create by yourself.
Repo contents
| File | What |
|---|---|
Qwen3.8-9B-Cyber-Exploit-Agent-v3-Q4_K_M.gguf / …Q5_K_M.gguf |
v3.3 build (adapter SHA256 c2e5196b…, see MANIFEST) |
agent_v3.py / agent_v3.sh |
host agent: fetch allowlist, classifier C0–C8, writer CLASS_LOCK |
INFERENCE_RUNBOOK.md |
serving, sampling, fetch contract, gate tables |
inference_system.txt |
system prompt incl. rules 11–14 (fetch-or-UNPROVEN) |
train_all_v3.jsonl |
SFT dataset, 334 unique rows (gate report included) |
dataset_gate_report_v3.txt |
16/16 dataset gate PASS |
eval_lock_v4.json |
frozen 16-item lock eval (chmod a-w; never trained on) |
ship_gate_v4.log |
v3.3 vs v3c gate table |
agent_smoke_v2.md |
two-role pipeline acceptance: 6/6 |
BASE.txt |
base model + shard SHAs + pre-SFT refusal smoke 8/8 |
Honest limitations
- VALID vs by-design/FP boundary is not stable from the weights alone at 9B; four SFT
iterations and a DPO continue shifted but never dominated it. The agent pipeline is the
working configuration (host classifies, model writes). - The agent alone is not 100% either. The working configuration is a triple:
model (writer) +agent_v3.py(host classifier C0–C8) + the xrpl-drill skill
(hunt bars, six ledger tests, N11–N18 families, maintainer FP catalog). The skill runs
hand-in-hand with the model — without it, hunt coverage, claim discipline and FP
recognition drop well below the measured 6/6; treat it as a required component, not an
accessory. - Memory labs occasionally attract XRPL track tags from the model; the host strips them (C1).
- On GGUF/LM Studio without the host, expect hedging on XRPL items — that is the documented
behavior, not a defect you can prompt away.