JC·HARNESS

pentest-2026-06-12-372608e0

mbarbine/platphormnews-www-prod · api-multi-model

Plan Status

completed

Execution

completed

Storage

neon_persisted

Spend

$0.0684

Classes

1 / 1 finding-backed

Updated

Jun 12, 2026, 05:08 AM

Evidence-Backed Execution

This run has persisted execution evidence from bounded passive recon, AI Gateway Hunt/Validate work, findings, and scorecard derivation.
  1. 01 / setupcompleted

    Operator setup and responsible-use gate completed.

    View details
    run id
    pentest-2026-06-12-372608e0
    target repo
    mbarbine/platphormnews-www-prod
    execution mode
    api-multi-model
    planned classes
    1
    budget usd
    0
    created
    Jun 12, 2026, 05:08 AM
  2. 02 / scope validationcompleted

    Allowed hosts and target scope validated before launch.

    View details
    target name
    platphormnews.com authorized smoke
    base url
    https://platphormnews.com
    repos
    mbarbine/platphormnews-www-prod
    allowed hosts
    platphormnews.com
    responsible use accepted
    yes
  3. 03 / reconcompleted

    6 bounded passive recon routes fetched.

    View details
    fetched routes
    6
    recon errors
    1
    sample routes
    https://platphormnews.com/, https://platphormnews.com/robots.txt, https://platphormnews.com/sitemap.xml, https://platphormnews.com/llms.txt
  4. 04 / huntcompleted

    2 AI Gateway hunt/validate calls recorded.

    View details
    attempted classes
    1
    completed classes
    1
    evidence source
    persisted findings
    model cost events
    2
    spend usd
    0.0684
    pipeline errors
    2
  5. 05 / validatecompleted

    1 confirmed findings persisted.

    View details
    candidate findings
    1
    persisted findings
    1
    confirmed findings
    1
    persistence complete
    yes
  6. 06 / gapfillqueued

    Gapfill remains available for refused or uncovered classes.

    View details
    uncovered classes
    0
  7. 07 / tracequeued

    Reachability analysis links findings to trust boundaries when evidence is present.

    View details
    finding records
    1
  8. 08 / reportqueued

    Report generation waits for an explicit protected report action.

    View details
    artifact source
    persisted run evidence
  9. 09 / scorecardcompleted

    Scorecard metrics were derived from persisted run findings.

    View details
    scorecards
    1
    findings scored
    1
    confirmed findings
    1

Class Execution Evidence

artifact backed
security-misconfigurationcompleted

1 found · 1 retained

View evidence
Hunt calls
0
Validate calls
0
Errors
0
Records
1
Source
persisted findings

Retained findings

LOWdowngraded
Security policy relies on robots.txt to hide sensitive/admin routes (security misconfiguration)

The evidence supports that the application’s robots.txt discloses where “admin/protected” routes appear (e.g., /admin, /api/admin, and wildcard patterns). However, this is not an access-control failure by itself: robots.txt is explicitly not an authorization mechanism and, on its own, does not permit access to those endpoints. For this to be a true security misconfiguration finding, the report would need evidence that backend authorization is missing or inconsistent on those routes, or that the site relies on robots.txt to prevent access rather than only to reduce indexing. No such access-control weakness is provided—only that discoverability is improved. Therefore the likelihood/impact is likely overstated for a standalone “security misconfiguration” classification. At most, this is an information-disclosure/recon enhancement issue that can facilitate targeted probing, which aligns better with a lower severity.

remediation: Do not rely on robots.txt for security. Ensure all admin/protected endpoints enforce server-side authentication/authorization independent of crawler directives. Additionally, remove/avoid leaking route naming patterns in publicly readable documents where feasible, and treat robots.txt as purely advisory for indexing.

Class errors

hunt:security-misconfiguration · anthropic/claude-fable-5

Free tier users do not have access to this model. Upgrade to paid credits at https://vercel.com/d?to=%2F%5Bteam%5D%2F%7E%2Fai%3Fmodal%3Dtop-up for unrestricted access.

validate:security-misconfiguration · anthropic/claude-fable-5

Free tier users do not have access to this model. Upgrade to paid credits at https://vercel.com/d?to=%2F%5Bteam%5D%2F%7E%2Fai%3Fmodal%3Dtop-up for unrestricted access.

Scorecards

fable5artifact backed

50.8

0 confirmed / 1 findings

Execution Log

artifact backed
#001infosetup
completedJun 12, 2026, 05:08 AM

Run pentest-2026-06-12-372608e0 persisted for mbarbine/platphormnews-www-prod.

#002infoexecution
completedJun 12, 2026, 05:08 AM

Execution status is completed.

#003warnrecon
partialJun 12, 2026, 05:08 AM

6 passive recon route(s) fetched; 1 recon error(s) recorded.

#004errorhunt:security-misconfiguration
pipeline errorJun 12, 2026, 05:08 AM

Free tier users do not have access to this model. Upgrade to paid credits at https://vercel.com/d?to=%2F%5Bteam%5D%2F%7E%2Fai%3Fmodal%3Dtop-up for unrestricted access.

#005errorvalidate:security-misconfiguration
pipeline errorJun 12, 2026, 05:08 AM

Free tier users do not have access to this model. Upgrade to paid credits at https://vercel.com/d?to=%2F%5Bteam%5D%2F%7E%2Fai%3Fmodal%3Dtop-up for unrestricted access.

#006infocost
recordedJun 12, 2026, 05:08 AM

2 model cost event(s) recorded for 0.0684 USD.

#007infocompletion
completedJun 12, 2026, 05:08 AM

Run is completed with 1 finding(s) and 1 confirmed finding(s).