Summarise and de-duplicate vulnerability scanner output
A scan of a few hundred hosts produces thousands of rows, most of them the same missing patch repeated. Apex Flash can group those rows into a short list of fixes and a plain summary, as long as you keep the counts and scores under your own control.
Set it up
- Export the scan as CSV or JSON from your own scanner.
- Drop columns the model does not need, such as long plugin output.
- Send rows in batches with the grouping prompt below.
- Check that the totals in and out reconcile.
- Re-attach asset context (internet-facing, owner) yourself.
- Hand each group to the team that owns the fix.
Authorisation boundary
Only triage scans of systems you own or have written authority to assess. Do not feed in results from scans of third-party hosts you had no permission to scan.
Sanitised sample input
id,host,plugin,cve,cvss,port
1,web-01,OpenSSL 1.1.1 outdated,CVE-2023-0286,7.4,443
2,web-02,OpenSSL 1.1.1 outdated,CVE-2023-0286,7.4,443
3,db-01,OpenSSL 1.1.1 outdated,CVE-2023-0286,7.4,5432
4,web-01,TLS 1.0 enabled,,5.9,443
5,web-02,TLS 1.0 enabled,,5.9,443
6,app-03,Default admin page exposed,,6.5,8080The prompt and the call
CVSS v3.1 qualitative bands are Low 0.1 to 3.9, Medium 4.0 to 6.9, High 7.0 to 8.9 and Critical 9.0 to 10.0 (FIRST specification). Tell the model to copy scores, never recalculate them.
Group these scanner findings by root cause and fix. Copy the cvss score from the input; do not change it or compute your own.
For each group give: title, finding ids, count of hosts, the highest cvss in the group, the single fix, and a one-line reason.
End with a reconciliation line: total input rows and total rows placed in groups. They must match.
Do not rank by business impact; I will add that.
<findings>
...csv rows...
</findings>import os
from openai import OpenAI
client = OpenAI(base_url="https://wildwestapi.com/v1",
api_key=os.environ["WILDWEST_API_KEY"])
resp = client.chat.completions.create(
model="apex-flash",
temperature=0.2,
messages=[
{"role": "system", "content": "You deduplicate vulnerability scan results accurately."},
{"role": "user", "content": open("scan_prompt.txt", encoding="utf-8").read()},
],
)
print(resp.choices[0].message.content)Keys look like sk-ww-...; keep yours in the WILDWEST_API_KEY environment variable, never in the script. Calls to /v1/chat/completions use the OpenAI format, billing is pay-as-you-go, and prompts are not retained on /v1.
What to check in the output
- The reconciliation line. If the model says 6 in and 5 out, a row was lost. Rerun in smaller batches.
- Scores match the CSV. Models sometimes round or restate them.
- Groups are real: the three OpenSSL rows share one fix, a library upgrade, while the default admin page is its own item.
- The model does not know which hosts face the internet. Add that before you set deadlines.
Both apex-flash and glm-5.3-flash-cyber are security-tuned models with a 1M-token context window, tool calling and vision. They are not uncensored models, and they are meant for defensive and authorised work like this. Parse its output with a script and compare counts, rather than reading by eye.
Where this fits
Feed confirmed items into a pentest report, or review the code behind them with security code review. More background in penetration testing use cases.
FAQ
Can it decide what to patch first?
It can suggest an order if you give asset criticality and exposure. The decision stays with your team.
How many rows fit in one call?
The context window is 1M tokens, but accuracy is better in batches of a few hundred rows with a reconciliation check.
Will it find new vulnerabilities?
No. It organises findings your scanner already reported.