Start Authorized Assessment
Dry run is selected by default. Real run executes bounded passive recon plus AI Gateway Hunt/Validate work after authorization, protected context, and typed confirmation are present.
Execution mode
Gateway-backed Hunt/Validate execution when AI Gateway credentials are present.
Selected model and attack classes
All 44Fable 5 · api-multi-model · 44 classes · injection, broken-access-control, cryptographic-failures, security-misconfiguration, supply-chain-failures + 39 more
Runtime Credentials
Server credentials are used for downstream calls. A browser-session PlatPhorm key authenticates explicit operator actions when no Authorization header is present.
Downstream PlatPhorm credential is present server-side; browser operator auth is still explicit.
Used for model routing checks, future gateway-backed model calls.
Used for future sandbox job creation when server OIDC is unavailable.
No run launched yet.