Coding Horizon

GLM 5.3: The Security Agent Test Starts Right Now

Every figure, date and claim the finished picture puts on screen, chased to a source. Anything that could not be chased is not on screen.

This video is an argument about how a security reviewing model should be tested and permitted, not a benchmark round-up, so it puts very little external data on screen. What it does put there is below.

GLM-5.3, the release

Released 14 August 2026 by Z.ai (Zhipu AI), through the GLM Coding Plan, announced as the strongest open-weights coding model, with the weights held back for roughly two weeks after launch while security review completed.

That date is the only external fact drawn in any shot.

The security framing is the vendor’s own, not this video’s invention

Z.ai shipped GLM-5.3 with cyber capability as a headline claim, reporting 2,436 vulnerabilities across 269 open-source projects, 1,097 of them critical or high severity, and benchmark gains on ExploitBench (54.4% against GLM-5.2’s 24.4%) and CyberGym (84.5% against 77.2%). None of those figures is drawn in this cut, but they are why the video treats GLM-5.3 as a security reviewer rather than as a general coding model.

Which harnesses run it

GLM-5.3 is used through existing coding agents rather than only a first-party one: Claude Code, OpenCode and Z.ai’s own ZCode are named at launch. That is what makes the “let one model write and another attack the diff” arrangement in this video practical rather than hypothetical.

The marks shown alongside it in the diff-attack shots are the coding agents the narration names as writing the feature.

Not checked