Skip to content

data: scan corpus refresh — 2026-06-07#30

Open
cloakmaster wants to merge 1 commit into
mainfrom
claude/scan-corpus-2026-06-07
Open

data: scan corpus refresh — 2026-06-07#30
cloakmaster wants to merge 1 commit into
mainfrom
claude/scan-corpus-2026-06-07

Conversation

@cloakmaster

@cloakmaster cloakmaster commented Jun 7, 2026

Copy link
Copy Markdown
Member

Scanned merlvintan/damn-vulnerable-llm-agent: 2 findings (HIGH ×2), governance score 27/100, EU AI Act readiness PARTIAL. Both findings are SQL injection via LLM-generated query in transaction_db.py. Framework detected: LangChain.

Also adds data/scan-corpus-failures.json logging the skipped target szybnev/DVLA (API returned no_agent_code — no detectable LLM agent code).

Corpus grows from 2 → 3 scans; total findings observed 9 → 11; average governance score 16.0 → 19.67.


Generated by Claude Code


Summary by cubic

Refreshed the scan corpus by adding merlvintan/damn-vulnerable-llm-agent and logging a skipped target; updated aggregates. Found 2 HIGH SQL injection issues in transaction_db.py.

  • Data Updates
    • New scan: merlvintan/damn-vulnerable-llm-agent — 2 HIGH (SQL injection), governance 27/100, EU AI Act readiness PARTIAL, langchain detected.
    • Failure logging: added data/scan-corpus-failures.json; recorded skipped szybnev/DVLA (400, reason no_agent_code).
    • Aggregates: total_scans 3, total_findings_observed 11, average_governance_score 19.67, last_refreshed 2026-06-07T19:34:31Z.

Written for commit 46c65df. Summary will update on new commits.

Review in cubic

Adds weekly scan of merlvintan/damn-vulnerable-llm-agent (2 HIGH findings,
governance 27/100). Logs szybnev/DVLA skip (no_agent_code) to failures file.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Re-trigger cubic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants