Security teams triaging a known weakness class
Narrow a repository to likely files after mapping an advisory, CVE, or GHSA to an applicable CWE.
Independent tool overview
Cisco Antares is a family of compact, open-weight security models built to explore a source repository and rank the files most likely to contain a known class of vulnerability.
Visit the official Antares site ↗
Overview
Antares is not a conventional hosted scanner or general coding assistant. Cisco Foundation AI trained the models for a narrow task: given a CWE and a repository snapshot, use terminal-style exploration to identify likely vulnerable files. The publicly released Antares-350M and Antares-1B weights can run in an organization's own environment, while Cisco's CLI packages the agent loop and can emit human-readable, JSON, Markdown, and SARIF results.
The narrow specialization and local deployment are the attraction, but the output is only a triage lead. Antares does not establish that a vulnerability exists, identify the exact line, explain the bug, produce a validated fix, or replace static analysis, dependency scanning, dynamic testing, threat modeling, and expert security review.
Use cases
The strongest fit depends on the job you need the product to complete, not the size of its feature list.
Narrow a repository to likely files after mapping an advisory, CVE, or GHSA to an applicable CWE.
Run the weights and repository exploration in a controlled local or on-premises environment.
Study a compact terminal-agent workflow and compare it under Cisco's documented vulnerability-localization protocol.
Produce reviewable file candidates or SARIF alongside established application-security checks.
Experiment with a smaller, task-specific model without routing every investigation through a frontier hosted model.
Capabilities
Starts from a CWE identifier and generic weakness description rather than requiring a natural-language coding request.
Uses terminal commands such as grep, find, and file inspection to narrow likely locations.
Returns repository-relative files believed to contain the target weakness for analyst review.
Can revise its search path as repository evidence is added to the agent context.
Open weights enable inference inside a controlled environment rather than requiring source upload to a hosted AI service.
Cisco publicly released a smaller 350M model and a stronger 1B-family model for different resource and quality tradeoffs.
The gated model repository includes a CLI that packages the model's agent loop and connects to a configured OpenAI-compatible inference endpoint.
Profiles the repository and previews a bounded portfolio of potentially relevant CWE checks without claiming a vulnerability was found.
Runs one targeted CWE investigation against a repository snapshot.
Runs independent investigations across a selected set of CWEs after the operator reviews the plan.
The CLI can produce terminal output plus JSON, Markdown, and SARIF for review and pipeline integration.
The documented agent explores the repository directly instead of relying on an external embedding index.
Cisco publishes the VLoc Bench task definition, evaluation protocol, and file-level precision, recall, and F1 results.
Process
Step 1
Accept the official Hugging Face repository conditions, review the Apache 2.0 license, and use only code you are authorized to assess.
Step 2
Mount a disposable copy read-only inside a container with networking disabled, resource limits, command timeouts, and no credentials or production secrets.
Step 3
Preview a small set of repository-relevant CWEs and treat selection scores only as relevance rankings—not vulnerability probabilities.
Step 4
Investigate a justified CWE first and record the exact repository revision, model version, inference settings, and CLI version.
Step 5
Review every command and candidate file, then confirm the weakness by reading the relevant control flow, data flow, configuration, and tests.
Step 6
Compare findings with static analysis, dependency and secret scanning, dynamic tests, advisories, and qualified manual review.
Step 7
Develop a reviewed fix, add regression tests, rerun the security toolchain, and require human approval before merge or release.
Cost
Cisco publishes Antares-350M and Antares-1B as Apache 2.0 open-weight models with no model subscription price. Organizations still pay for hardware or hosted inference, storage, engineering, sandboxing, monitoring, CI integration, and security review. The official model repositories require Hugging Face authentication, acceptance of conditions, and sharing contact information with the publisher.
Open weight
The smaller public model for lower-resource experimentation and defensive localization workflows.
Open weight
The stronger public model and the focus of Cisco's current quickstart.
Not publicly released at review
Cisco reports benchmark results for a larger family member, but its launch article and public collection list only the 350M and 1B releases.
Pricing checked . Check current pricing at the source ↗
Assessment
Compare
The right alternative depends on the specific output, workflow, controls and budget your project requires.
Agents
A broader hosted security agent aimed at repository scanning and patch development rather than only local file-level localization.
Explore Codex Security →Coding
A managed repository-security workflow with scanning, patch suggestions, scheduled operation, and team-tool exports.
Explore Claude Security →Coding
A pull-request-oriented application-security option for teams that want contextual findings inside the development workflow.
Explore DryRun Security →Questions
Antares is a family of compact security language models from Cisco Foundation AI. It is trained to explore a repository from a CWE description and identify the source files most likely to contain that weakness.
It is better described as a model component for vulnerability localization. The CLI can run focused checks and sweeps, but the resulting files are hypotheses for analyst review, not confirmed vulnerabilities.
Antares-350M and Antares-1B were publicly released on Hugging Face when reviewed. Cisco discusses Antares-3B and publishes benchmark results for it, but the public collection did not list released 3B weights.
The public weights use the Apache 2.0 license and do not have a model subscription price. You still bear inference, hardware, storage, engineering, sandbox, monitoring, and security-review costs.
Yes. Local or on-premises deployment is a central use case. Cisco recommends an isolated container with networking disabled, command timeouts, resource limits, access controls, and human oversight.
No. Its intended output is a set of likely affected files. It does not provide a validated patch, and Cisco explicitly places autonomous remediation outside the intended use.
Cisco's model card reports 0.209 File F1 on VLoc Bench under its documented protocol. That is a useful research result for a compact model, but it also means outputs require substantial verification and should not be described as an accuracy percentage.
No. Cisco positions it as a complement to the broader application-security stack, including static and dynamic analysis, dependency and secret scanning, container and infrastructure checks, and expert review.
Only inside a tightly isolated, disposable, read-only environment. Disable networking, remove secrets and credentials, restrict commands and resources, log the trajectory, and never allow model output to trigger remediation or deployment without review.
Bottom line
Antares is an interesting open-weight building block for teams that need private, low-cost, CWE-guided repository triage. Its value is narrowing an investigation inside a controlled environment; it should never be presented as a complete scanner, a confirmed finding, or an autonomous security authority.
Visit Antares website ↗
Sonic-3.5 & Ink-2 - Cartesia's new top-ranked speech and transcription models for voice agents
.jpeg)
Lyria 3.5 - Google's new music model with more realistic vocals

DiffusionGemma - Google's open diffusion model that can quadruple text generation speed

Inkling-Small - Thinking Machines' compact open model that rivals full-size version

Get access to all our AI courses, hundreds of real-world AI use cases, live expert-led workshops, an exclusive network of AI early adopters, and more.
Get unlimited access to all of our current & upcoming industry-specific AI courses for the duration of your subscription.
To keep up with the rapid pace of AI, our team publishes AI implementation guides daily. Our library contains 300+ practical use cases to automate real-world work.
Join weekly, live, interactive sessions with industry leaders who are at the forefront of AI for hands-on implementation guidance and exclusive insights.
Network with an exclusive community of AI-first professionals who are working smarter with AI. Learn how early adopters are using AI in their work and businesses.