Default executionMode in example config is api-multi-model (live API)
Finding PUB-F001 · 9dde3a1cf807 · discovered by pentest-public-51classes-20260611
LOWconfirmedsecurity-misconfigurationopus48artifact backed
- Target
- OhanaSec/jc-pentest-harness
- Target URL
- not recorded
- Run status
- completed · api-multi-model
- Framework
- owasp-top-10
- Priority score
- 0.2400
- Reachability
- unknown
- Chain depth
- 1
- PoC available
- no
- Asset
- not recorded
- Discovered
- Jun 11, 2026, 02:20 PM
Description
The example config defaults to api-multi-model, which makes live (paid) API calls if copied verbatim.
Validation
No validation rationale recorded.
Remediation
Default example config to dry-run; require explicit opt-in for live mode.
Evidence Boundary
This page shows persisted finding evidence, validator rationale, target context, and run linkage. Raw prompts, raw target responses, provider payloads, secrets, cookies, and authorization headers are not rendered publicly. Use the linked run page for class execution evidence, run logs, cost events, and pipeline errors.