Skip to content

data: scan corpus refresh — 2026-06-21 - #33

Open
cloakmaster wants to merge 2 commits into
mainfrom
claude/scan-corpus-2026-06-21
Open

data: scan corpus refresh — 2026-06-21#33
cloakmaster wants to merge 2 commits into
mainfrom
claude/scan-corpus-2026-06-21

Conversation

@cloakmaster

@cloakmaster cloakmaster commented Jun 21, 2026

Copy link
Copy Markdown
Member

Scanned merlvintan/damn-vulnerable-llm-agent: 2 findings (0 critical, 2 high), governance score 27/100, EU AI Act readiness PARTIAL. Both findings are SQL injection via LLM-generated queries in transaction_db.py.

Also adds data/scan-corpus-failures.json logging the initial target szybnev/DVLA which returned no_agent_code (no detectable LLM agent code in that repo).

Corpus grows from 2 → 3 scans; total_findings_observed 9 → 11; average_governance_score 16.0 → 19.67.


Generated by Claude Code


Summary by cubic

Refreshes the public scan corpus: adds results for merlvintan/damn-vulnerable-llm-agent (2 high SQL injection findings in transaction_db.py) and logs failed target szybnev/DVLA (no_agent_code, 400) to avoid re-queuing. Aggregates updated: total scans 3, total findings 11, average governance 19.67; last refreshed 2026-06-21T19:35:33Z.

Written for commit d9baf0c. Summary will update on new commits.

Review in cubic

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1 issue found across 2 files

Prompt for AI agents (unresolved issues)

Check if these issues are valid — if so, understand the root cause of each and fix them. If appropriate, use sub-agents to investigate and fix each issue separately.


<file name="data/scan-corpus-failures.json">

<violation number="1" location="data/scan-corpus-failures.json:2">
P3: New corpus JSON artifact lacks `_schema_version` metadata, inconsistent with the existing versioned `data/scan-corpus.json` companion file.</violation>
</file>

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

@@ -0,0 +1,12 @@
{
"_description": "Log of public scan attempts that failed during corpus refresh. Used to avoid re-queuing known-bad targets.",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P3: New corpus JSON artifact lacks _schema_version metadata, inconsistent with the existing versioned data/scan-corpus.json companion file.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At data/scan-corpus-failures.json, line 2:

<comment>New corpus JSON artifact lacks `_schema_version` metadata, inconsistent with the existing versioned `data/scan-corpus.json` companion file.</comment>

<file context>
@@ -0,0 +1,12 @@
+{
+  "_description": "Log of public scan attempts that failed during corpus refresh. Used to avoid re-queuing known-bad targets.",
+  "failures": [
+    {
</file context>

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant