{"service":"pentest","url":"https://pentest.platphormnews.com","publicReadAccess":["/","/runs","/runs/new","/findings","/matrix","/models","/scorecard","/reports","/artifacts","/activity","/integrations","/settings","/known-gaps","/registry","/app/setup","/app/setup/responsible-use","/docs","/docs/getting-started","/docs/safety","/docs/responsible-use","/docs/modes","/docs/pipeline","/docs/findings","/docs/integrations","/api/health","/api/v1/health","/api/coverage","/api/events","/api/findings","/api/stats","/api/v1/setup/status","/api/v1/responsible-use","/api/v1/models","/api/v1/models/status","/api/v1/integrations/status","/api/v1/integrations/platphorm/registry","/api/v1/integrations/platphorm/discovery","/api/v1/runtime/credentials","/api/v1/reports","/api/v1/events","/api/v1/webhooks","/api/docs","/api/mcp","/openapi.yaml","/openapi.json","/llms.txt","/llms-full.txt","/llms-index.json","/humans.txt","/robots.txt","/sitemap.xml","/sitemap-index.xml","/sitemap-full.xml","/rss.xml","/feed.xml","/manifest.webmanifest","/.well-known/mcp.json","/.well-known/agents.json","/.well-known/ai-plugin.json","/.well-known/agent-policy.json","/.well-known/ai-policy.json","/.well-known/security.txt","/.well-known/trust.json"],"protectedActions":["/api/v1/runs custom dry-run scopes","/api/v1/runs/real-run","/api/v1/runs/:runId/rerun","/api/v1/runs/:runId/(pause|resume|cancel)","/api/v1/sandbox/jobs","/api/v1/integrations/sandbox/handoff","/api/v1/integrations/browserops/handoff","/api/v1/integrations/*","/api/v1/webhooks/*","/api/mcp protected tools"],"auth":{"platformKey":"PLATPHORM_API_KEY","acceptedHeaders":["Authorization: Bearer $PLATPHORM_API_KEY","X-PlatPhorm-API-Key: $PLATPHORM_API_KEY"],"forbiddenPlatformKeyNames":["TRACE_API_KEY","CLAWS_API_KEY","BROWSEROPS_API_KEY","PENTEST_API_KEY"]},"dataExposureBoundary":{"public":["health","docs","responsible-use","taxonomy","known gaps","discovery"],"protected":["target scope","run creation","raw logs","findings","reports","artifacts","webhooks"]},"responsibleUse":["Authorized testing only.","Only test systems you own or have explicit written permission to assess.","The operator is responsible for target authorization and scope.","No anonymous active testing against arbitrary targets.","No denial-of-service testing unless explicitly scoped and separately enabled.","No destructive testing.","No persistence, malware, credential theft, exfiltration, or public exploitation.","No social engineering.","No attacks against third-party infrastructure outside the approved scope.","No remediation, PR creation, or branch push actions.","Findings are assessment outputs, not automatic fixes.","Human review is required before real execution and before publishing reports.","Private findings and artifacts remain protected."],"trustPolicy":"Web dashboard, public-safe discovery, browser-based operations, trusted-domain discovery, standard route compliance, Vercel metadata capture, trace inspection, and agentic workflow discovery are intentionally supported for public read-only debugging and operator workflows. Mutating, administrative, ingestion, replay, fork, remediation, deployment, sync, test-triggering, reporting, and write actions require PLATPHORM_API_KEY."}