Skip to content

data: scan corpus refresh — 2026-07-12#36

Open
cloakmaster wants to merge 1 commit into
mainfrom
claude/scan-corpus-2026-07-12
Open

data: scan corpus refresh — 2026-07-12#36
cloakmaster wants to merge 1 commit into
mainfrom
claude/scan-corpus-2026-07-12

Conversation

@cloakmaster

@cloakmaster cloakmaster commented Jul 12, 2026

Copy link
Copy Markdown
Member

Scanned merlvintan/damn-vulnerable-llm-agent (Tier A). Found 2 findings (0 critical, 2 high, 0 medium, 0 low) — both sql_injection via LLM-generated queries in transaction_db.py. Governance score 27/100, EU AI Act readiness PARTIAL.

Also adds data/scan-corpus-failures.json logging szybnev/DVLA as unscannable (no_agent_code — no LLM agent code detected); merlvintan/damn-vulnerable-llm-agent was the successful fallback pick.


Generated by Claude Code


Summary by cubic

Refreshes the public scan corpus for 2026-07-12 and adds failure logging for unscannable repos.

  • New Features
    • Added a new scan entry for merlvintan/damn-vulnerable-llm-agent: 2 high sql_injection findings in transaction_db.py; governance 27/100; risk 22; EU AI Act readiness PARTIAL.
    • Updated data/scan-corpus.json aggregates (total_scans 3, findings 11, average governance 19.7), added frameworks_covered: ['langchain'], refreshed timestamp; added data/scan-corpus-failures.json logging szybnev/DVLA as no_agent_code (fell back to merlvintan/damn-vulnerable-llm-agent).

Written for commit 35e4dfd. Summary will update on new commits.

Review in cubic

Weekly corpus scan of merlvintan/damn-vulnerable-llm-agent (Tier A). Found 2
HIGH findings (both sql_injection via LLM-generated queries), governance score
27/100, EU AI Act readiness PARTIAL. Also logs szybnev/DVLA as a scan failure
(no_agent_code) — the repo has no detectable LLM agent code.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

Re-trigger cubic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants