{"ok":true,"data":{"findings":[{"id":"47736515-9924-409c-abef-fe2a58777485","run_db_id":"148c2d2b-c4b4-4044-a66f-063aa36fcde6","run_id":"pentest-public-51classes-20260611","run_target_repo":"OhanaSec/jc-pentest-harness","run_target_url":null,"run_status":"completed","run_execution_mode":"api-multi-model","finding_ref":"PUB-F016","fingerprint":"f6b87aafab0ad5f4861f5ab4135450c63f3cefc72ac4dbd0be0cc8d17bfde03c","title":"tier1Gate TOCTOU: non-atomic check-then-reset enables concurrent runs","description":"The gate check and reset are not atomic, so two concurrent runs can both observe an armed gate and proceed past per-run budget controls.","remediation":"Make gate check-and-reset atomic (compare-and-swap / advisory lock).","attack_class":"excessive-agency","framework":"agentic","severity_raw":"medium","severity_band":"MEDIUM","priority_score":0.58,"hunt_model":"opus48","validate_status":"confirmed","validate_rationale":null,"chain_depth":1,"poc_available":false,"asset_kind":"source-file","asset_path":null,"reachability":null,"novel_to_baseline":true,"discovered_at":"Thu Jun 11 2026 14:20:00 GMT+0000 (Coordinated Universal Time)","created_at":"Thu Jun 11 2026 19:55:46 GMT+0000 (Coordinated Universal Time)"},{"id":"4d155b96-d5ac-4369-bf83-5ec4905de3d1","run_db_id":"148c2d2b-c4b4-4044-a66f-063aa36fcde6","run_id":"pentest-public-51classes-20260611","run_target_repo":"OhanaSec/jc-pentest-harness","run_target_url":null,"run_status":"completed","run_execution_mode":"api-multi-model","finding_ref":"PUB-F015","fingerprint":"9608755858e6fe2c7d493d72e4cc46098b89b608637e48de67184b45e6c5e117","title":"Auto-gapfill routes around model safety refusals with no human checkpoint","description":"When the primary Hunt model refuses an attack class, gapfill silently reroutes the task to a secondary model with no human-in-the-loop checkpoint.","remediation":"Add a mandatory operator approval gate before gapfill reroutes refused classes.","attack_class":"agent-identity-abuse","framework":"agentic","severity_raw":"medium","severity_band":"MEDIUM","priority_score":0.55,"hunt_model":"opus48","validate_status":"confirmed","validate_rationale":null,"chain_depth":1,"poc_available":false,"asset_kind":"source-file","asset_path":null,"reachability":null,"novel_to_baseline":true,"discovered_at":"Thu Jun 11 2026 14:20:00 GMT+0000 (Coordinated Universal Time)","created_at":"Thu Jun 11 2026 19:55:46 GMT+0000 (Coordinated Universal Time)"},{"id":"c6aa6277-5ad3-411b-8c74-7241d9eb1357","run_db_id":"148c2d2b-c4b4-4044-a66f-063aa36fcde6","run_id":"pentest-public-51classes-20260611","run_target_repo":"OhanaSec/jc-pentest-harness","run_target_url":null,"run_status":"completed","run_execution_mode":"api-multi-model","finding_ref":"PUB-F007","fingerprint":"0e4cb3fc39ddd3a93bcc58d43c8d6c719b2e6375704eec1d4e746910d27de623","title":"tier1Gate reset swallows failure silently — gate can remain armed","description":"The tier1Gate reset path swallows exceptions, so a failure during reset can leave the gate armed for a subsequent run with no operator signal.","remediation":"Fail closed on reset error; surface a hard error and require explicit re-arm.","attack_class":"agent-goal-hijacking","framework":"agentic","severity_raw":"medium","severity_band":"MEDIUM","priority_score":0.52,"hunt_model":"opus48","validate_status":"confirmed","validate_rationale":null,"chain_depth":1,"poc_available":false,"asset_kind":"source-file","asset_path":null,"reachability":null,"novel_to_baseline":true,"discovered_at":"Thu Jun 11 2026 14:20:00 GMT+0000 (Coordinated Universal Time)","created_at":"Thu Jun 11 2026 19:55:46 GMT+0000 (Coordinated Universal Time)"},{"id":"f333783b-a53f-43e6-ace0-cc4d0ead16e6","run_db_id":"148c2d2b-c4b4-4044-a66f-063aa36fcde6","run_id":"pentest-public-51classes-20260611","run_target_repo":"OhanaSec/jc-pentest-harness","run_target_url":null,"run_status":"completed","run_execution_mode":"api-multi-model","finding_ref":"PUB-F004","fingerprint":"c0ad509ada05e81ffbe45c235975f7b1e9c129a046e8b15c1fd7ef3d7f9b7713","title":"Boot prompt YES/NO natural-language flow has no provenance binding","description":"The boot confirmation accepts free-form YES/NO with no provenance binding, enabling prompt-injected confirmation of dangerous operations.","remediation":"Bind confirmation to a signed nonce; reject natural-language affirmations.","attack_class":"injection","framework":"owasp-top-10","severity_raw":"medium","severity_band":"MEDIUM","priority_score":0.49,"hunt_model":"opus48","validate_status":"confirmed","validate_rationale":null,"chain_depth":1,"poc_available":false,"asset_kind":"source-file","asset_path":null,"reachability":null,"novel_to_baseline":true,"discovered_at":"Thu Jun 11 2026 14:20:00 GMT+0000 (Coordinated Universal Time)","created_at":"Thu Jun 11 2026 19:55:46 GMT+0000 (Coordinated Universal Time)"},{"id":"4953bf3d-a72f-4cfb-8e8d-6d0d1de75cb5","run_db_id":"148c2d2b-c4b4-4044-a66f-063aa36fcde6","run_id":"pentest-public-51classes-20260611","run_target_repo":"OhanaSec/jc-pentest-harness","run_target_url":null,"run_status":"completed","run_execution_mode":"api-multi-model","finding_ref":"PUB-F001","fingerprint":"9dde3a1cf8070bdd89958ca65284fb51fba5d9b11ae5c8d3eab4ab692f334ae3","title":"Default executionMode in example config is api-multi-model (live API)","description":"The example config defaults to api-multi-model, which makes live (paid) API calls if copied verbatim.","remediation":"Default example config to dry-run; require explicit opt-in for live mode.","attack_class":"security-misconfiguration","framework":"owasp-top-10","severity_raw":"low","severity_band":"LOW","priority_score":0.24,"hunt_model":"opus48","validate_status":"confirmed","validate_rationale":null,"chain_depth":1,"poc_available":false,"asset_kind":"source-file","asset_path":null,"reachability":null,"novel_to_baseline":true,"discovered_at":"Thu Jun 11 2026 14:20:00 GMT+0000 (Coordinated Universal Time)","created_at":"Thu Jun 11 2026 19:55:46 GMT+0000 (Coordinated Universal Time)"},{"id":"e573e9a9-bb02-47bb-88ce-1dfd7294ec03","run_db_id":"148c2d2b-c4b4-4044-a66f-063aa36fcde6","run_id":"pentest-public-51classes-20260611","run_target_repo":"OhanaSec/jc-pentest-harness","run_target_url":null,"run_status":"completed","run_execution_mode":"api-multi-model","finding_ref":"PUB-F002","fingerprint":"491f528595578b1955dd34b6e47bbd0e9f836d057f282bdbc0de353576db0dcd","title":"Example budget caps default to $5/$25 — should default to $0","description":"Example budget caps default to non-zero values, allowing unexpected spend if the config is used as-is.","remediation":"Default budget caps to $0; require explicit budget before live runs.","attack_class":"security-misconfiguration","framework":"owasp-top-10","severity_raw":"low","severity_band":"LOW","priority_score":0.24,"hunt_model":"opus48","validate_status":"confirmed","validate_rationale":null,"chain_depth":1,"poc_available":false,"asset_kind":"source-file","asset_path":null,"reachability":null,"novel_to_baseline":true,"discovered_at":"Thu Jun 11 2026 14:20:00 GMT+0000 (Coordinated Universal Time)","created_at":"Thu Jun 11 2026 19:55:46 GMT+0000 (Coordinated Universal Time)"},{"id":"3d9fcea8-e35c-4bf4-a10c-3c4b3b92bd0e","run_db_id":"148c2d2b-c4b4-4044-a66f-063aa36fcde6","run_id":"pentest-public-51classes-20260611","run_target_repo":"OhanaSec/jc-pentest-harness","run_target_url":null,"run_status":"completed","run_execution_mode":"api-multi-model","finding_ref":"PUB-F013","fingerprint":"6c46a1b6fcb5f1338c7334357bd65112c33ad7ef9ecdb1ff4007668ff6a9bde8","title":"keyFile setup uses echo; API key leaks to shell history","description":"Documented keyFile setup uses echo, which writes the API key into shell history in plaintext.","remediation":"Use printf with a heredoc or a secrets manager; document history hygiene.","attack_class":"non-human-identity-abuse","framework":"nhi-container-cicd","severity_raw":"low","severity_band":"LOW","priority_score":0.22,"hunt_model":"opus48","validate_status":"confirmed","validate_rationale":null,"chain_depth":1,"poc_available":false,"asset_kind":"source-file","asset_path":null,"reachability":null,"novel_to_baseline":true,"discovered_at":"Thu Jun 11 2026 14:20:00 GMT+0000 (Coordinated Universal Time)","created_at":"Thu Jun 11 2026 19:55:46 GMT+0000 (Coordinated Universal Time)"},{"id":"6220a51d-916d-484c-8419-1ac9ad82545b","run_db_id":"81601b7d-f5ae-46c6-ab49-73706454114d","run_id":"pentest-2026-06-12-controlled-44-3287b226","run_target_repo":"mbarbine/platphormnews-www-prod","run_target_url":"https://platphormnews.com","run_status":"completed","run_execution_mode":"api-multi-model","finding_ref":"pentest-2026-06-12-001","fingerprint":"5c020384d77c003da12603c407438a281f907d4050736d9325a123968dd9575e","title":"LLM/public discovery surfaces risk of sensitive context exfil via model outputs/tool invocations","description":"The site explicitly positions itself as an LLM-readable “contract hub” and “network discovery root” (llms.txt, llms-full.txt, llms-index.json, llm-index.json) and exposes MCP/LLM discovery endpoints (/api/mcp and /.well-known/*). While the provided evidence does not show actual secret leakage in responses, this architecture commonly enables inference-time exfiltration if the LLM or agent is induced to echo hidden system/context data, or to include tool invocation results containing protected data. The site also advertises a strict boundary where protected capabilities require PLATPHORM_API_KEY, but the presence of multiple LLM/agent discovery artifacts increases the risk that a careless downstream agent prompts the model to disclose hidden instructions/context or to leak protected tool outputs through generated text.","remediation":"Treat all LLM-visible artifacts (llms*.txt/json, ai-plugin/agent/MCP manifests) as untrusted prompt input and ensure the inference layer has hard redaction/allowlisting for any “protected” tool outputs. Specifically: (1) ensure tool implementations for protected capabilities never execute in public flows; (2) enforce response-level filtering so protected results cannot be serialized into model output; (3) add structured separation between public context and any internal policies/instructions; (4) include automated tests that run prompt-injection style requests against the LLM/agent and verify no protected data appears in generated or tool-result text.","attack_class":"llm-inference-data-exfil","framework":"llm-pipeline","severity_raw":"MEDIUM","severity_band":"MEDIUM","priority_score":0.21,"hunt_model":"fable5","validate_status":"pending","validate_rationale":"Validation stage failed; finding is pending operator review.","chain_depth":2,"poc_available":false,"asset_kind":"web","asset_path":null,"reachability":"model_assessed_from_passive_recon","novel_to_baseline":true,"discovered_at":"Fri Jun 12 2026 20:45:52 GMT+0000 (Coordinated Universal Time)","created_at":"Fri Jun 12 2026 20:45:52 GMT+0000 (Coordinated Universal Time)"},{"id":"62fbf11e-47c9-4023-a600-29754d12b215","run_db_id":"148c2d2b-c4b4-4044-a66f-063aa36fcde6","run_id":"pentest-public-51classes-20260611","run_target_repo":"OhanaSec/jc-pentest-harness","run_target_url":null,"run_status":"completed","run_execution_mode":"api-multi-model","finding_ref":"PUB-F012","fingerprint":"63a1f193c211ef2f9e9a1f55d991edc22358251bd310ccdc58478c0c62f8dfbc","title":"No credential rotation strategy documented","description":"There is no documented rotation strategy for long-lived API keys used by the harness.","remediation":"Document a rotation cadence and automate via secrets manager.","attack_class":"non-human-identity-abuse","framework":"nhi-container-cicd","severity_raw":"low","severity_band":"LOW","priority_score":0.2,"hunt_model":"opus48","validate_status":"confirmed","validate_rationale":null,"chain_depth":1,"poc_available":false,"asset_kind":"source-file","asset_path":null,"reachability":null,"novel_to_baseline":true,"discovered_at":"Thu Jun 11 2026 14:20:00 GMT+0000 (Coordinated Universal Time)","created_at":"Thu Jun 11 2026 19:55:46 GMT+0000 (Coordinated Universal Time)"},{"id":"613b3aed-ad57-4cad-8970-6d9138e10137","run_db_id":"148c2d2b-c4b4-4044-a66f-063aa36fcde6","run_id":"pentest-public-51classes-20260611","run_target_repo":"OhanaSec/jc-pentest-harness","run_target_url":null,"run_status":"completed","run_execution_mode":"api-multi-model","finding_ref":"PUB-F011","fingerprint":"dd6ad39f8965e038eb7c446bd75338b498edae5ef6e25e4678df9059b54c55a0","title":"SQS IAM permissions absent from documentation","description":"SQS permissions used by the queue workers are not documented, causing over-broad IAM grants.","remediation":"Document the minimal SQS permission set for queue workers.","attack_class":"iac-privilege-escalation","framework":"owasp-top-10","severity_raw":"low","severity_band":"LOW","priority_score":0.18,"hunt_model":"opus48","validate_status":"confirmed","validate_rationale":null,"chain_depth":1,"poc_available":false,"asset_kind":"source-file","asset_path":null,"reachability":null,"novel_to_baseline":true,"discovered_at":"Thu Jun 11 2026 14:20:00 GMT+0000 (Coordinated Universal Time)","created_at":"Thu Jun 11 2026 19:55:46 GMT+0000 (Coordinated Universal Time)"},{"id":"2bb36cdf-2a19-436a-8369-5ab4322dda58","run_db_id":"148c2d2b-c4b4-4044-a66f-063aa36fcde6","run_id":"pentest-public-51classes-20260611","run_target_repo":"OhanaSec/jc-pentest-harness","run_target_url":null,"run_status":"completed","run_execution_mode":"api-multi-model","finding_ref":"PUB-F010","fingerprint":"b9d4fa9f66abf4811713370fa9ceef6af94dee3133b1e7c72a24fe1b7c7e87a6","title":"ssm:PutParameter missing from README IAM table","description":"The documented IAM permission table omits ssm:PutParameter, leading operators to grant broader policies than needed.","remediation":"Add the precise ssm:PutParameter permission to the IAM table.","attack_class":"iac-privilege-escalation","framework":"owasp-top-10","severity_raw":"low","severity_band":"LOW","priority_score":0.18,"hunt_model":"opus48","validate_status":"confirmed","validate_rationale":null,"chain_depth":1,"poc_available":false,"asset_kind":"source-file","asset_path":null,"reachability":null,"novel_to_baseline":true,"discovered_at":"Thu Jun 11 2026 14:20:00 GMT+0000 (Coordinated Universal Time)","created_at":"Thu Jun 11 2026 19:55:46 GMT+0000 (Coordinated Universal Time)"},{"id":"e19938a5-137c-4c9d-bb59-b74cc520a9d6","run_db_id":"81601b7d-f5ae-46c6-ab49-73706454114d","run_id":"pentest-2026-06-12-controlled-44-3287b226","run_target_repo":"mbarbine/platphormnews-www-prod","run_target_url":"https://platphormnews.com","run_status":"completed","run_execution_mode":"api-multi-model","finding_ref":"pentest-2026-06-12-002","fingerprint":"2a0c5f061bd6ad06b89270210bf6c449058edfd48ec8bc157f0171e7d7be981e","title":"LLMs/agents exposed discovery artifacts that define agent objectives (potential goal-hijack target)","description":"The site advertises itself as an “LLM-readable contract hub” and publishes agent-related policy/discovery surfaces (e.g., /llms.txt, /llms-full.txt, /llms-index.json, /api/v1/public-contract, and multiple /.well-known/* policy JSON endpoints). These artifacts explicitly define the system’s public vs protected capabilities and describe agent workflows (“agent_policy”, “agentic workflow discovery”, MCP readiness, route/compliance evidence). In an agent-goal-hijacking scenario, an attacker attempts to inject or override agent instructions so an agent’s objective mid-flight is changed (e.g., from read-only discovery to protected/mutating actions). With the provided evidence, we cannot confirm that an override is possible, only that the architecture includes goal-defining instructions distributed in machine-readable form, which are the primary preconditions for goal hijacking against agentic systems.","remediation":"Treat all LLM/agent-readable policy/discovery documents as untrusted input for downstream decision-making. Enforce a strict objective hierarchy in the agent runtime (e.g., hard-coded tool allow-lists and capability gates server-side), and require authenticated confirmation for any protected capability regardless of what appears in agent-policy/llms/contract documents. Add integrity/authentication to policy/contract artifacts (signatures) and implement runtime checks that prevent mid-flight objective changes (e.g., disable instruction-following from any retrieved third-party content; apply “prompt injection” protections to tool-selection).","attack_class":"agent-goal-hijacking","framework":"agentic","severity_raw":"MEDIUM","severity_band":"MEDIUM","priority_score":0.175,"hunt_model":"fable5","validate_status":"pending","validate_rationale":"Validation stage failed; finding is pending operator review.","chain_depth":2,"poc_available":false,"asset_kind":"web","asset_path":null,"reachability":"model_assessed_from_passive_recon","novel_to_baseline":true,"discovered_at":"Fri Jun 12 2026 20:45:53 GMT+0000 (Coordinated Universal Time)","created_at":"Fri Jun 12 2026 20:45:53 GMT+0000 (Coordinated Universal Time)"},{"id":"edabccc0-63b8-428e-b1f4-de2ca0079010","run_db_id":"148c2d2b-c4b4-4044-a66f-063aa36fcde6","run_id":"pentest-public-51classes-20260611","run_target_repo":"OhanaSec/jc-pentest-harness","run_target_url":null,"run_status":"completed","run_execution_mode":"api-multi-model","finding_ref":"PUB-F009","fingerprint":"c5774919ed7ec1f207b11fec1a36c8c905936321f0ca6e7634cef5be5cd17556","title":"js-yaml loaded inline; may be missed by some SBOM scanners","description":"js-yaml is required inline rather than at module top, so some SBOM scanners may not detect the dependency.","remediation":"Hoist the import to module scope so SBOM tooling captures it.","attack_class":"supply-chain-failures","framework":"owasp-top-10","severity_raw":"low","severity_band":"LOW","priority_score":0.16,"hunt_model":"opus48","validate_status":"confirmed","validate_rationale":null,"chain_depth":1,"poc_available":false,"asset_kind":"source-file","asset_path":null,"reachability":null,"novel_to_baseline":true,"discovered_at":"Thu Jun 11 2026 14:20:00 GMT+0000 (Coordinated Universal Time)","created_at":"Thu Jun 11 2026 19:55:46 GMT+0000 (Coordinated Universal Time)"},{"id":"0380a124-8e2b-42ee-9ff9-928277fa7b00","run_db_id":"148d05eb-39b3-4ba5-b71c-17a7553fc7c8","run_id":"pentest-2026-06-12-372608e0","run_target_repo":"mbarbine/platphormnews-www-prod","run_target_url":"https://platphormnews.com","run_status":"completed","run_execution_mode":"api-multi-model","finding_ref":"pentest-2026-06-12-001","fingerprint":"da594842b8df0cbfcc8058fca65ce4b85a4a42a5a657a2dea6c387cc13725862","title":"Security policy relies on robots.txt to hide sensitive/admin routes (security misconfiguration)","description":"The site exposes multiple admin/protected URL patterns in robots.txt (e.g., Disallow: /admin, /api/admin, /api/private, /api/protected, /api/*/admin, /api/*/private, /api/*/protected) and also disallows URLs containing common secret query parameters (/*?token=, /*?key=, /*?secret=). Using robots.txt as a control mechanism is a misconfiguration risk because robots.txt is not an access-control boundary; it only affects crawling behavior. If backend authorization is not consistently enforced for these routes, this discoverability pattern can directly accelerate attacks by revealing which routes are intended to be sensitive.\n\nEvidence:\n- robots.txt contains explicit Disallow entries for admin/protected API surfaces and patterns.\n- Multiple public discovery surfaces (/robots.txt, OpenAPI, llms.txt) provide additional routing intelligence.","remediation":"Do not rely on robots.txt for security. Ensure all admin/protected endpoints enforce server-side authentication/authorization independent of crawler directives. Additionally, remove/avoid leaking route naming patterns in publicly readable documents where feasible, and treat robots.txt as purely advisory for indexing.","attack_class":"security-misconfiguration","framework":"owasp-top-10","severity_raw":"LOW","severity_band":"LOW","priority_score":0.1375,"hunt_model":"fable5","validate_status":"downgraded","validate_rationale":"The evidence supports that the application’s robots.txt discloses where “admin/protected” routes appear (e.g., /admin, /api/admin, and wildcard patterns). However, this is not an access-control failure by itself: robots.txt is explicitly not an authorization mechanism and, on its own, does not permit access to those endpoints. For this to be a true security misconfiguration finding, the report would need evidence that backend authorization is missing or inconsistent on those routes, or that the site relies on robots.txt to prevent access rather than only to reduce indexing. No such access-control weakness is provided—only that discoverability is improved. Therefore the likelihood/impact is likely overstated for a standalone “security misconfiguration” classification. At most, this is an information-disclosure/recon enhancement issue that can facilitate targeted probing, which aligns better with a lower severity.","chain_depth":2,"poc_available":false,"asset_kind":"web","asset_path":null,"reachability":"model_assessed_from_passive_recon","novel_to_baseline":true,"discovered_at":"Fri Jun 12 2026 05:08:47 GMT+0000 (Coordinated Universal Time)","created_at":"Fri Jun 12 2026 05:08:47 GMT+0000 (Coordinated Universal Time)"},{"id":"2142ba83-575e-4b24-8ac3-4dc634ceadfc","run_db_id":"81601b7d-f5ae-46c6-ab49-73706454114d","run_id":"pentest-2026-06-12-controlled-44-3287b226","run_target_repo":"mbarbine/platphormnews-www-prod","run_target_url":"https://platphormnews.com","run_status":"completed","run_execution_mode":"api-multi-model","finding_ref":"pentest-2026-06-12-003","fingerprint":"fff1920d51b8cdc14d647489ee291ef7c3ec42ef0b4950e11cc9d730aef16e7e","title":"Public API routes explicitly include story/search/news content that may be fed into LLM context (possible indirect data leakage)","description":"The public API includes endpoints for aggregated stories, comments, discussion metadata, and search (/api/v1/stories, /api/v1/stories/{id}/comments, /api/v1/search, /api/v1/hn/item/*, etc.). In an LLM inference pipeline, these endpoints can become “context ingestion” sources. If any upstream pipeline mistakenly merges protected/internal metadata with public content (e.g., internal route compliance details, tool credentials, or traces), an LLM could reproduce it in its output. The provided evidence shows public boundaries and disallows token/key/secret query parameters in robots.txt, but it does not show that the LLM integration is protected from context-mixing at inference time.","remediation":"At the boundary between retrieval and generation: (1) maintain strict schema/field-level allowlists so only intended public fields are inserted into the LLM prompt; (2) explicitly strip tracing/headers/cookies and any internal metadata from the prompt context; (3) add logging/telemetry to detect whether any protected-looking strings (keys/tokens/secrets/Authorization) are present in prompts or generation outputs; (4) include regression tests for context-window leakage (ensure model outputs never include internal system prompts/tool instructions).","attack_class":"llm-inference-data-exfil","framework":"llm-pipeline","severity_raw":"LOW","severity_band":"LOW","priority_score":0.07,"hunt_model":"fable5","validate_status":"pending","validate_rationale":"Validation stage failed; finding is pending operator review.","chain_depth":2,"poc_available":false,"asset_kind":"web","asset_path":null,"reachability":"model_assessed_from_passive_recon","novel_to_baseline":true,"discovered_at":"Fri Jun 12 2026 20:45:53 GMT+0000 (Coordinated Universal Time)","created_at":"Fri Jun 12 2026 20:45:53 GMT+0000 (Coordinated Universal Time)"},{"id":"e1c0e07e-d6a5-4076-b6a4-55e5a17da81c","run_db_id":"81601b7d-f5ae-46c6-ab49-73706454114d","run_id":"pentest-2026-06-12-controlled-44-3287b226","run_target_repo":"mbarbine/platphormnews-www-prod","run_target_url":"https://platphormnews.com","run_status":"completed","run_execution_mode":"api-multi-model","finding_ref":"pentest-2026-06-12-004","fingerprint":"1e9268df2f6abc6127adb4ec33fc21e0a9564a4a3ae6ef345f273433519c6813","title":"Insufficient evidence of a trojanized LLM weight backdoor (BadSeek-style) in provided passive data","description":"Your repository is in scope, but the provided target context is limited to public HTTP GET responses (HTML, robots.txt, sitemap(s), llms.txt, and portions of openapi.yaml/health). For the specific attack class “LLM Model Weight Backdoor (llm-model-weight-backdoor)” (e.g., Trojanized open-source weights such as BadSeek with a poisoned-trace influence on downstream ASR), confirming evidence would require at least one of: (1) model artifact identifiers/hashes, (2) model weight provenance/registry and a known-bad version reference, (3) presence of backdoor metadata (e.g., weight-source indicators), (4) audit logs/results showing anomalous behavioral ASR tied to specific trigger traces, or (5) source-code/CI clues showing poisoned weight ingestion or model replacement. None of that is present in the supplied passive HTTP data, so the backdoor cannot be validated or ruled out from this context alone.","remediation":"Provide one of the following for evidence-based classification: (a) the exact model name(s)/revision(s) used by the application (from code/lockfiles/CI) and their cryptographic hashes, (b) the source location(s) and integrity verification steps used when downloading weights, (c) any internal model-evaluation outputs that report ASR/behavioral anomalies (including any trigger/trace definitions), or (d) repository files/paths related to model loading (e.g., where weights are referenced or pulled). With those, we can check provenance and compare against known trojaned distributions, and/or validate whether behavior is consistent with a 2%-poisoned-traces/80%+ ASR scenario.","attack_class":"llm-model-weight-backdoor","framework":"llm-pipeline","severity_raw":"LOW","severity_band":"LOW","priority_score":0.0625,"hunt_model":"fable5","validate_status":"confirmed","validate_rationale":"The proposed finding is essentially a scope/evidence statement: the only provided context is passive public HTTP GET responses (HTML, robots.txt, sitemap(s), llms.txt, and partial openapi.yaml/health). For an “LLM Model Weight Backdoor (BadSeek-style)” determination, the hunter listed concrete validation requirements (e.g., model artifact hashes/IDs, provenance/known-bad version references, backdoor metadata, audit results linking anomalous ASR to triggers and specific traces, or CI/source clues for poisoned weight ingestion/replacement). None of those evidentiary artifacts are present in the described passive data. Therefore, the inability to validate or rule out the backdoor from this dataset is justified and not contradicted by any additional evidence.","chain_depth":1,"poc_available":false,"asset_kind":"web","asset_path":null,"reachability":"model_assessed_from_passive_recon","novel_to_baseline":true,"discovered_at":"Fri Jun 12 2026 20:45:53 GMT+0000 (Coordinated Universal Time)","created_at":"Fri Jun 12 2026 20:45:53 GMT+0000 (Coordinated Universal Time)"}]}}