{"ok":true,"data":{"service":"pentest","name":"JC PenTest Harness","version":"1.2.0","url":"https://pentest.platphormnews.com","productionUrl":"https://pentest.platphormnews.com","description":"Enterprise-grade, multi-model penetration testing harness. A Hunt → Validate → Score pipeline runs frontier models (Fable 5, Claude Opus 4.8, GPT-5.5) across 44 attack classes spanning 9 security frameworks — OWASP Top 10:2025, MCP, RAG, OWASP Agentic:2026, MITRE ATLAS, API Security, Business Logic Abuse, NHI/Container/CI-CD, and LLM/AI Pipeline.","purpose":"Evidence-first, human-in-the-loop web cockpit for the Jean-Claude multi-model pentest harness.","status":"operational_with_operator_checkpoints","updatedAt":"2026-07-20T00:00:00.000Z","providerSelection":{"platform":"platphorm","deployment":"vercel","database":"neon-postgres","storage":"local-plus-platphorm-files","sandbox":"platphorm-sandbox","webhooks":"vercel-functions","aiGateway":"vercel-ai-gateway"},"selectedProviders":{"platform":{"id":"platphorm","label":"PlatPhorm","kind":"operator-platform","status":"selected","authEnv":"PLATPHORM_API_KEY","baseDomain":"platphormnews.com","services":[{"id":"docs","label":"PlatPhorm Docs","url":"https://docs.platphormnews.com","capability":"publish reports and operator documentation"},{"id":"sheets","label":"PlatPhorm Sheets","url":"https://sheets.platphormnews.com","capability":"export structured findings and scorecards"},{"id":"files","label":"PlatPhorm Files","url":"https://files.platphormnews.com","capability":"store protected run artifacts"},{"id":"trace","label":"PlatPhorm Trace","url":"https://trace.platphormnews.com","capability":"trace and span inspection"},{"id":"webhooklab","label":"PlatPhorm WebhookLab","url":"https://webhooklab.platphormnews.com","capability":"webhook simulation and delivery verification"},{"id":"sandbox","label":"PlatPhorm Sandbox","url":"https://sandbox.platphormnews.com","capability":"safe replay, bounded command validation, and evidence handoff"},{"id":"browserops","label":"PlatPhorm BrowserOps","url":"https://browserops.platphormnews.com","capability":"trusted browser journey preview, screenshots, accessibility, console, network, and trace evidence"},{"id":"agentops","label":"PlatPhorm AgentOps","url":"https://agentops.platphormnews.com","capability":"agent operation review and optional workflow telemetry"},{"id":"trustops","label":"PlatPhorm TrustOps","url":"https://trustops.platphormnews.com","capability":"trust, authorship, disclosure, correction, attribution, and policy validation"},{"id":"evals","label":"PlatPhorm Evals","url":"https://evals.platphormnews.com","capability":"release gates, quality scoring, and eval suite handoff"},{"id":"agentui","label":"PlatPhorm AgentUI","url":"https://agentui.platphormnews.com","capability":"agent-facing workflow UI and form validation"},{"id":"webhooks","label":"PlatPhorm Webhooks","url":"https://webhooks.platphormnews.com","capability":"event delivery, signature replay, and async evidence"},{"id":"spec","label":"PlatPhorm Spec","url":"https://spec.platphormnews.com","capability":"OpenAPI validation, schema examples, and contract workbench handoff"},{"id":"mcp","label":"PlatPhorm MCP","url":"https://mcp.platphormnews.com","capability":"MCP tool registry discovery and JSON-RPC validation"},{"id":"phorm","label":"Phorm","url":"https://phorm.platphormnews.com","capability":"interface prototypes and workflow UI prompts"},{"id":"ascii","label":"PlatPhorm ASCII","url":"https://ascii.platphormnews.com","capability":"ASCII artifact inspection and transformation handoff"},{"id":"desa","label":"PlatPhorm Desa","url":"https://desa.platphormnews.com","capability":"optional deASCII/desa artifact transformation checks"},{"id":"xml","label":"PlatPhorm XML","url":"https://xml.platphormnews.com","capability":"XML, RSS, Atom, and sitemap validation"},{"id":"json","label":"PlatPhorm JSON","url":"https://json.platphormnews.com","capability":"JSON validation and formatting"},{"id":"markdown","label":"PlatPhorm Markdown","url":"https://markdown.platphormnews.com","capability":"Markdown report parsing and validation"},{"id":"searchops","label":"PlatPhorm SearchOps","url":"https://searchops.platphormnews.com","capability":"technical search monitoring and crawl evidence"},{"id":"sitemapops","label":"PlatPhorm SitemapOps","url":"https://sitemapops.platphormnews.com","capability":"index policy and sitemap validation"}]},"deployment":{"id":"vercel","label":"Vercel","kind":"serverless-web","status":"selected","productionUrl":"https://pentest.platphormnews.com","capabilities":["nextjs","functions","webhooks","sandbox","ai-gateway","oidc","edge-network"],"envAny":["VERCEL_OIDC_TOKEN","VERCEL_TOKEN","VERCEL_URL","VERCEL_PROJECT_PRODUCTION_URL","VERCEL_AUTOMATION_BYPASS_SECRET"],"notes":"Current production target. Keep provider-specific behavior behind adapters and config."},"database":{"id":"neon-postgres","label":"Neon Postgres","kind":"postgres","status":"selected","envAny":["DATABASE_URL","POSTGRES_URL","DATABASE_URL_UNPOOLED","POSTGRES_URL_NON_POOLING","PGHOST","PGUSER","PGPASSWORD","PGDATABASE","POSTGRES_URL_NO_SSL"],"notes":"Primary persistent backend for run, finding, scorecard, event, and audit state."},"storage":{"id":"local-plus-platphorm-files","label":"Local storage plus PlatPhorm Files","kind":"hybrid-artifact-storage","status":"selected","envAny":["PLATPHORM_API_KEY"],"notes":"Local function state remains honest and ephemeral; protected artifact upload can hand off to PlatPhorm Files."},"sandbox":{"id":"platphorm-sandbox","label":"PlatPhorm Sandbox","kind":"safe-replay","status":"selected","envAny":["PLATPHORM_API_KEY"],"notes":"Selected platform handoff target for replay, schema validation, and safe execution workflows."},"webhooks":{"id":"vercel-functions","label":"Vercel Functions Webhooks","kind":"http-functions","status":"selected","envAny":["VERCEL","VERCEL_URL"],"notes":"Current webhook receiver/delivery surface for the Next.js app."},"aiGateway":{"id":"vercel-ai-gateway","label":"Vercel AI Gateway","kind":"model-gateway","status":"selected","envAny":["VERCEL_OIDC_TOKEN","AI_GATEWAY_API_KEY","VERCEL_AI"],"notes":"Current provider-neutral model gateway for Vercel-hosted and local pulled environments. VERCEL_AI is accepted as the deployed PlatPhorm alias for AI_GATEWAY_API_KEY presence."}},"attackClassCount":44,"frameworkCount":9,"models":[{"slug":"fable5","label":"Fable 5","provider":"anthropic","harnessModelId":"claude-fable-5","gatewayModel":"anthropic/claude-fable-5","role":"Primary Hunt + Validate","validatePin":true},{"slug":"opus48","label":"Claude Opus 4.8","provider":"anthropic","harnessModelId":"claude-opus-4-8","gatewayModel":"anthropic/claude-opus-4.8","role":"Scorer of record + gapfill","validatePin":false},{"slug":"gpt55","label":"GPT-5.5","provider":"openai","harnessModelId":"gpt-5.5","gatewayModel":"openai/gpt-5.5","role":"Cross-validation","validatePin":false}],"publicRoutes":["/","/runs","/runs/new","/findings","/matrix","/models","/scorecard","/reports","/artifacts","/activity","/integrations","/settings","/known-gaps","/registry","/app/setup","/app/setup/responsible-use","/docs","/docs/getting-started","/docs/safety","/docs/responsible-use","/docs/modes","/docs/pipeline","/docs/findings","/docs/integrations","/api/health","/api/v1/health","/api/coverage","/api/events","/api/findings","/api/stats","/api/v1/setup/status","/api/v1/responsible-use","/api/v1/models","/api/v1/models/status","/api/v1/integrations/status","/api/v1/integrations/platphorm/registry","/api/v1/integrations/platphorm/discovery","/api/v1/runtime/credentials","/api/v1/reports","/api/v1/events","/api/v1/webhooks","/api/docs","/api/mcp","/openapi.yaml","/openapi.json","/llms.txt","/llms-full.txt","/llms-index.json","/humans.txt","/robots.txt","/sitemap.xml","/sitemap-index.xml","/sitemap-full.xml","/rss.xml","/feed.xml","/manifest.webmanifest","/.well-known/mcp.json","/.well-known/agents.json","/.well-known/ai-plugin.json","/.well-known/agent-policy.json","/.well-known/ai-policy.json","/.well-known/security.txt","/.well-known/trust.json"],"protectedRoutePatterns":["/api/v1/runs custom dry-run scopes","/api/v1/runs/real-run","/api/v1/runs/:runId/rerun","/api/v1/runs/:runId/(pause|resume|cancel)","/api/v1/sandbox/jobs","/api/v1/integrations/sandbox/handoff","/api/v1/integrations/browserops/handoff","/api/v1/integrations/*","/api/v1/webhooks/*","/api/mcp protected tools"],"capabilities":[{"id":"setup-wizard","title":"Jean-Claude boot and setup wizard","href":"/runs/new","body":"Setup wizard and run planner for scoped dry runs and protected real runs.","status":"live_surface","updateMode":"Live UI; submitted plans persist to Neon when configured.","category":"operate","includeInRss":true},{"id":"dry-real-run-gate","title":"Dry-run and real-run selection with dry-run default","href":"/runs/new","body":"Dry-run default, real-run gate, budget controls, and authorization confirmation.","status":"live_surface","updateMode":"Live UI; run state is persisted when a run is created.","category":"operate"},{"id":"execution-modes","title":"Execution modes: api-multi-model, local-client, local-model, multi-mode","href":"/docs/modes","body":"Documented execution modes from the original harness configuration.","status":"source_backed","updateMode":"Source-backed static docs; updates on deploy.","category":"docs"},{"id":"model-roster","title":"Model roster: fable5, opus48, gpt55","href":"/models","body":"Configured model roster, provider selection, fallback models, pricing inputs, and stage role mapping.","status":"source_backed","updateMode":"Source-backed model registry; updates on deploy.","category":"operate"},{"id":"credential-resolution","title":"Key resolution status for env, runtime keys, key files, AWS SSM, and Vercel AI Gateway","href":"/settings","body":"Presence-only key status for server envs and browser-session runtime keys.","status":"live_surface","updateMode":"Live server/runtime credential status; raw values are never rendered.","category":"platform"},{"id":"scope-validation","title":"Target base URL, repositories, trust boundaries, and allowed-host validation","href":"/runs/new","body":"Target base URL, repositories, trusted hosts, and responsible-use scope controls.","status":"live_surface","updateMode":"Live UI validation; submitted run scope is persisted with the run.","category":"governance"},{"id":"pipeline-timeline","title":"RECON, HUNT, VALIDATE, GAPFILL, TRACE, REPORT, SCORECARD pipeline timeline","href":"/runs","body":"Pipeline timeline and run history with persisted stage, log, finding, and scorecard evidence.","status":"live_data","updateMode":"Live data-backed surface from Neon and local run storage.","category":"operate","includeInRss":true},{"id":"attack-class-taxonomy","title":"44 attack-class taxonomy across 9 harness frameworks","href":"/matrix","body":"Canonical Jean-Claude attack-class matrix, framework mapping, and latest class-level execution evidence.","status":"source_backed","updateMode":"Source-backed taxonomy plus persisted coverage evidence; taxonomy updates on deploy.","category":"evidence","includeInRss":true},{"id":"findings","title":"Finding normalization, schema validation, run linkage, and evidence drilldown","href":"/findings","body":"Finding explorer with run linkage, target context, validation rationale, remediation text, and evidence boundaries.","status":"live_data","updateMode":"Live data-backed surface from persisted finding records.","category":"evidence","includeInRss":true},{"id":"scorecard","title":"Priority scoring, persisted scorecards, and comparative-scorecard gap disclosure","href":"/scorecard","body":"Priority scoring method, persisted scorecard rows, and explicit rubric boundary for evidence-backed findings.","status":"live_data","updateMode":"Live data-backed rows from persisted scorecards; rubric notes update on deploy.","category":"evidence"},{"id":"reports","title":"Public-safe report packages and report ledger","href":"/reports","body":"Report packages generated from persisted runs, findings, scorecards, class evidence, and sanitized logs.","status":"live_data","updateMode":"Live data-backed report packages; generated from current persisted evidence at request time.","category":"evidence","includeInRss":true},{"id":"artifacts","title":"Prompt packages, class evidence grids, scorecards, findings summaries, and artifact inventory","href":"/artifacts","body":"Public-safe artifact inventory for run outputs, report package routes, class evidence, and downstream handoff artifacts.","status":"live_data","updateMode":"Live data-backed artifact ledger; no artifact is claimed without persisted evidence.","category":"evidence"},{"id":"activity","title":"Event outbox, audit trail, and live run progress refresh","href":"/activity","body":"Durable lifecycle event outbox, structured audit rows, canonical event catalog, and live refresh for in-flight runs.","status":"live_data","updateMode":"Live data-backed surface from ph.events, ph.audit_log, and server-rendered run refresh.","category":"platform","includeInRss":true},{"id":"responsible-use","title":"Responsible-use audit and protected operator actions","href":"/docs/responsible-use","body":"Responsible-use audit policy and protected operator action boundary.","status":"source_backed","updateMode":"Source-backed static docs; updates on deploy.","category":"governance"},{"id":"runtime-credentials","title":"Runtime browser-session credential entry for protected setup and handoff operator auth","href":"/settings","body":"Browser-session runtime credential entry for explicit operator auth and missing runtime dependencies.","status":"live_surface","updateMode":"Live browser-session state; secrets stay in sessionStorage and are sent only on explicit actions.","category":"platform"},{"id":"sandbox-handoff","title":"PlatPhorm Sandbox handoff preview and protected receive-handoff delivery","href":"/integrations","body":"Sandbox handoff preview and protected receive-handoff delivery controls.","status":"live_surface","updateMode":"Live integration status; protected delivery only claims confirmed downstream receipt.","category":"platform"},{"id":"browserops-handoff","title":"PlatPhorm BrowserOps handoff preview and protected receive-handoff delivery","href":"/integrations","body":"BrowserOps handoff preview and protected receive-handoff delivery controls.","status":"live_surface","updateMode":"Live integration status; protected delivery only claims confirmed downstream receipt.","category":"platform"},{"id":"discovery","title":"MCP, OpenAPI, llms, sitemap, RSS, robots, and well-known discovery","href":"/docs","body":"Discovery routes, API docs, MCP metadata, sitemap, RSS, robots, and well-known policy files.","status":"generated","updateMode":"Mixed generated/source-backed discovery surfaces; route smoke verifies public availability.","category":"docs","includeInRss":true}],"responsibleUse":["Authorized testing only.","Only test systems you own or have explicit written permission to assess.","The operator is responsible for target authorization and scope.","No anonymous active testing against arbitrary targets.","No denial-of-service testing unless explicitly scoped and separately enabled.","No destructive testing.","No persistence, malware, credential theft, exfiltration, or public exploitation.","No social engineering.","No attacks against third-party infrastructure outside the approved scope.","No remediation, PR creation, or branch push actions.","Findings are assessment outputs, not automatic fixes.","Human review is required before real execution and before publishing reports.","Private findings and artifacts remain protected."],"trustPolicy":"Web dashboard, public-safe discovery, browser-based operations, trusted-domain discovery, standard route compliance, Vercel metadata capture, trace inspection, and agentic workflow discovery are intentionally supported for public read-only debugging and operator workflows. Mutating, administrative, ingestion, replay, fork, remediation, deployment, sync, test-triggering, reporting, and write actions require PLATPHORM_API_KEY."}}