JC·HARNESS

pentest-public-51classes-20260611

OhanaSec/jc-pentest-harness · api-multi-model

Plan Status

completed

Execution

artifact_backed

Storage

neon_persisted

Spend

$2.84

Classes

8 / 44 finding-backed

Updated

Jun 11, 2026, 02:39 PM

Evidence-Backed Execution

This historical run has persisted finding records but no pipeline classResults payload. The class grid below is derived from retained finding records and links to each finding's public-safe evidence.
  1. 01 / setupcompleted

    Operator setup and responsible-use gate completed.

    View details
    run id
    pentest-public-51classes-20260611
    target repo
    OhanaSec/jc-pentest-harness
    execution mode
    api-multi-model
    planned classes
    44
    budget usd
    5
    created
    Jun 11, 2026, 07:55 PM
  2. 02 / scope validationcompleted

    Allowed hosts and target scope validated before launch.

    View details
    responsible use accepted
    no
  3. 03 / reconoperator checkpoint

    Historical run did not persist passive recon route metadata.

    View details
    fetched routes
    0
    recon errors
    0
  4. 04 / huntcompleted

    11 retained findings persisted across 8 finding-backed class(es).

    View details
    attempted classes
    8
    completed classes
    8
    evidence source
    persisted findings
    model cost events
    0
    spend usd
    2.8400
    pipeline errors
    0
  5. 05 / validatecompleted

    11 confirmed findings persisted.

    View details
    candidate findings
    0
    persisted findings
    11
    confirmed findings
    11
    persistence complete
    no
  6. 06 / gapfillqueued

    Gapfill remains available for refused or uncovered classes.

    View details
    uncovered classes
    36
  7. 07 / tracequeued

    Reachability analysis links findings to trust boundaries when evidence is present.

    View details
    finding records
    11
  8. 08 / reportqueued

    Report generation waits for an explicit protected report action.

    View details
    artifact source
    persisted run evidence
  9. 09 / scorecardcompleted

    Scorecard metrics were derived from persisted run findings.

    View details
    scorecards
    3
    findings scored
    11
    confirmed findings
    11

Operator Checkpoint

A supervised stage needs operator action before the run can advance.

operator checkpoint

To continue from the browser, use the rerun action. A real-run rerun requires responsible-use acceptance, typed authorization, valid scope, budget, and model credentials; a dry-run rerun validates the plan only.

Class Execution Evidence

artifact backed
agent-goal-hijackingcompleted

1 found · 1 retained

View evidence
Hunt calls
0
Validate calls
0
Errors
0
Records
1
Source
persisted findings

Retained findings

MEDIUMconfirmed
tier1Gate reset swallows failure silently — gate can remain armed

No validation rationale recorded.

remediation: Fail closed on reset error; surface a hard error and require explicit re-arm.

agent-identity-abusecompleted

1 found · 1 retained

View evidence
Hunt calls
0
Validate calls
0
Errors
0
Records
1
Source
persisted findings

Retained findings

MEDIUMconfirmed
Auto-gapfill routes around model safety refusals with no human checkpoint

No validation rationale recorded.

remediation: Add a mandatory operator approval gate before gapfill reroutes refused classes.

excessive-agencycompleted

1 found · 1 retained

View evidence
Hunt calls
0
Validate calls
0
Errors
0
Records
1
Source
persisted findings

Retained findings

MEDIUMconfirmed
tier1Gate TOCTOU: non-atomic check-then-reset enables concurrent runs

No validation rationale recorded.

remediation: Make gate check-and-reset atomic (compare-and-swap / advisory lock).

iac-privilege-escalationcompleted

2 found · 2 retained

View evidence
Hunt calls
0
Validate calls
0
Errors
0
Records
2
Source
persisted findings

Retained findings

LOWconfirmed
SQS IAM permissions absent from documentation

No validation rationale recorded.

remediation: Document the minimal SQS permission set for queue workers.

LOWconfirmed
ssm:PutParameter missing from README IAM table

No validation rationale recorded.

remediation: Add the precise ssm:PutParameter permission to the IAM table.

injectioncompleted

1 found · 1 retained

View evidence
Hunt calls
0
Validate calls
0
Errors
0
Records
1
Source
persisted findings

Retained findings

MEDIUMconfirmed
Boot prompt YES/NO natural-language flow has no provenance binding

No validation rationale recorded.

remediation: Bind confirmation to a signed nonce; reject natural-language affirmations.

non-human-identity-abusecompleted

2 found · 2 retained

View evidence
Hunt calls
0
Validate calls
0
Errors
0
Records
2
Source
persisted findings

Retained findings

LOWconfirmed
keyFile setup uses echo; API key leaks to shell history

No validation rationale recorded.

remediation: Use printf with a heredoc or a secrets manager; document history hygiene.

LOWconfirmed
No credential rotation strategy documented

No validation rationale recorded.

remediation: Document a rotation cadence and automate via secrets manager.

security-misconfigurationcompleted

2 found · 2 retained

View evidence
Hunt calls
0
Validate calls
0
Errors
0
Records
2
Source
persisted findings

Retained findings

LOWconfirmed
Example budget caps default to $5/$25 — should default to $0

No validation rationale recorded.

remediation: Default budget caps to $0; require explicit budget before live runs.

LOWconfirmed
Default executionMode in example config is api-multi-model (live API)

No validation rationale recorded.

remediation: Default example config to dry-run; require explicit opt-in for live mode.

supply-chain-failurescompleted

1 found · 1 retained

View evidence
Hunt calls
0
Validate calls
0
Errors
0
Records
1
Source
persisted findings

Retained findings

LOWconfirmed
js-yaml loaded inline; may be missed by some SBOM scanners

No validation rationale recorded.

remediation: Hoist the import to module scope so SBOM tooling captures it.

Scorecards

opus48artifact backed

83.4

11 confirmed / 11 findings

fable5artifact backed

77.0

8 confirmed / 9 findings

gpt55artifact backed

70.6

6 confirmed / 8 findings

Execution Log

artifact backed
#001infosetup
completedJun 11, 2026, 07:55 PM

Run pentest-public-51classes-20260611 persisted for OhanaSec/jc-pentest-harness.

#002infocompletion
completedJun 11, 2026, 02:39 PM

Run is completed with 11 finding(s) and 11 confirmed finding(s).