Abliterated models for cybersecurity
Security engineers use an abliterated model when a stock chatbot refuses to discuss the bug in front of them. The work is still theirs: a diff, a log, a ticket, a detection they mean to ship. The model is a reader and a drafter. It is not a permission slip, and this page is not a set of exploit steps. Refuseless hosts the model. You bring the system you are allowed to look at.
The lineup is aimed at that reading. GLM 5.3 Abliterated is described on the site as the frontier coding and cybersecurity checkpoint in the set, and GLM 5.3 Flash Abliterated as the cheaper sibling. Benchmark chips on the homepage are published scores for the base checkpoints, not Refuseless evals. Use them as a hint about the starting model. Do not quote them as our measurements.
Where a completion actually helps
- Triage. Paste a stack trace, a WAF sample, or a suspicious auth log you already collected. Ask for the three hypotheses worth checking first, and which field would confirm each one.
- Diff reading. Hand it a change in code you maintain. Ask which branches treat a user-controlled string as a query, a path, or a command, and where a safer API already exists in the file.
- Detection notes. Describe a behavior you have already confirmed. Ask for a draft of the log sources and the fields a detection would need. You still write the rule in your own tooling.
- Naming. Ask it to name the vulnerability class in plain language so a ticket is readable. The class name is not a payload.
How to prompt it without making a mess
Put the constraint in the system message: the code is ours, the goal is a fix or a detection, and you want the answer as a list of checks. Paste the smallest snippet that still contains the bug. Ask for the safer function by name if you know it. Ask what evidence is missing before anyone claims the issue is real. A model that has had refusals removed will discuss the dangerous case directly. That is the feature. Your review of the answer is still the control.
Call it as chat completions on https://api.refuseless.com/v1 with a lineup id. The Python and Node pages are the base-URL change. Prompts are not retained after the response, which is the published retention line and the reason a security team can send a real internal snippet without standing up a log they did not ask for. Read what that sentence does and does not cover.
What this page will not do
It will not list payloads, proof-of-concept strings, or steps for breaking a system you do not own. If that is the search you arrived with, it is the wrong page. Authorized testing of a model, as opposed to a network, is the red team page. Training a classifier on security text you are allowed to hold is closer to synthetic data.