Research
Minisøk
A fast vulnerability-identification model for scans that need findings without generated solutions.
Overview
Minisøk is the lightweight Vaktex model for vulnerability identification. It is designed to answer one question quickly: where is the risky code, and what class of vulnerability does it look like?
Use Minisøk when you want a focused security pass, a triage report for another tool, or a low-friction scan before handing solution work to a developer or a separate agent.
Minisøk does not provide solutions. In JSONL output, expect finding metadata such as file, vulnerability identifiers, and vulnerability name, but not solution code.
Benchmarks
Vaktex Vulnerability Detection
| Model | Identification | Solutions |
|---|---|---|
| Minisøk | 59.26% | - |
| Vakttårn | 69.16% | 76.82% |
| GPT-5.5 | 46.30% | 34.63% |
| Snyk | 44.44% | - |
OWASP Java
| Model | Identification | Solutions |
|---|---|---|
| Minisøk | 72.15% | - |
| Vakttårn | 80.44% | 63.70% |
| GPT-5.5 | 80.00% | 74.59% |
| Snyk | 70.44% | - |
How to Read the Benchmarks
Identification measures whether a model finds the vulnerable code. Solutions measure whether a model returns useful code. A dash means that model does not provide a solution result in that workflow. Minisøk is identification-only, so its solution column is always a dash.
The Vaktex Vulnerability Detection benchmark is a private corpus of vulnerable and secure code with more than 1,000 files across 20 different languages. That breadth gives a more accurate impression of how a model will perform in the real world than a narrow single-language test set. Minisøk clears the industry-standard scanner baseline by a wide margin while staying focused on identification only.
The OWASP Java benchmark is a public benchmark on a well documented language, which makes the spread tighter. Minisøk stays comfortably ahead of the scanner baseline there as well.
Capabilities
- Identifies likely vulnerable code paths and dependency risks
- Returns structured findings suitable for reports, CI, and agent pipelines
- Works well when the next step is human review or a custom solution workflow
- Avoids proposing patches when the workflow only needs evidence and classification
Limitations
Minisøk is not a solution model. It will not generate replacement code, explain a full solution strategy, or populate solution code in JSONL output.
Because it is optimized for identification, teams should pair Minisøk findings with code review, tests, and security judgment before deciding that a vulnerability is exploitable or fully resolved.
Recommended Use
Choose Minisøk for fast vulnerability discovery, continuous scanning, and report-only workflows.
Choose Vakttårn when the scan should also return suggested solutions.