Skip to content

data: scan corpus refresh — 2026-06-28#34

Open
cloakmaster wants to merge 1 commit into
mainfrom
claude/scan-corpus-2026-06-28
Open

data: scan corpus refresh — 2026-06-28#34
cloakmaster wants to merge 1 commit into
mainfrom
claude/scan-corpus-2026-06-28

Conversation

@cloakmaster

@cloakmaster cloakmaster commented Jun 28, 2026

Copy link
Copy Markdown
Member

Scanned merlvintan/damn-vulnerable-llm-agent (LangChain-based DVLA fork): 2 findings, both HIGH-severity SQL injection via LLM-generated queries, governance score 27/100, EU AI Act readiness PARTIAL.

First attempt against szybnev/DVLA failed (no_agent_code — repo has no LLM/agent code); logged to data/scan-corpus-failures.json.

Corpus grows from 2 → 3 scans; total_findings_observed 9 → 11; average_governance_score 16.0 → 19.67.


Generated by Claude Code


Summary by cubic

Refreshes the scan corpus by adding a new scan for merlvintan/damn-vulnerable-llm-agent and introducing a failure log for rejected targets. Totals now 3 scans and 11 findings.

  • New Features
    • Added scan for merlvintan/damn-vulnerable-llm-agent: 2 HIGH SQL injection findings; governance 27/100; EU AI Act readiness PARTIAL.
    • Created data/scan-corpus-failures.json logging a failed attempt for szybnev/DVLA (HTTP 400: no_agent_code) with fallback to merlvintan/damn-vulnerable-llm-agent.
    • Updated data/scan-corpus.json aggregates: total_scans 3, total_findings_observed 11, average_governance_score 19.67, last_refreshed 2026-06-28.

Written for commit c855d45. Summary will update on new commits.

Review in cubic

Scanned merlvintan/damn-vulnerable-llm-agent (2 findings, governance 27/100).
First attempt (szybnev/DVLA) failed no_agent_code; logged to scan-corpus-failures.json.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Re-trigger cubic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant