Home / Vaults / Penetration Test Report
Penetration Test Report
A penetration test delivered as a vault rather than a PDF — and the clearest argument on this site for why that difference matters. One engagement, eight audience-specific views, evidence attached to each finding, and a runnable retest script per finding that exits 0 if it is fixed and 1 if it is not.
Read key:
sgit_rk1_14042259ecbec2d0c7c4e68963695c4ceeeeb652767d25b777024a4f05ccd025:o4lrwx02In the official UI: open it read-only in a new tab · From the CLI:
sgit clone sgit_rk1_14042259ecbec2d0c7c4e68963695c4ceeeeb652767d25b777024a4f05ccd025:o4lrwx02Published deliberately, and derived one-way from a vault key that is not published and never will be.
See it live, here
Both surfaces open automatically below. You can also open the app in its own window ↗.
What is in it
The same engagement, told for the reader in front of it
A pentest PDF is written once, for everybody, and therefore for nobody. This one opens on Choose your view: CEO / Executive, Decision Maker, Financial Decision Maker, Roadmap / Project, Risk Assessment Owner, AppSec Engineer, DevOps Engineer — or the full report.
Each view is its own page, opening on the sections that matter to that audience in their order. The headline numbers stay constant underneath: 10 findings, 7 internet-reachable and unauthenticated, a modelled annual exposure against a remediation cost — so the CFO and the AppSec engineer are demonstrably reading the same engagement.
Every finding ships a script that re-runs it
Ten findings, and each carries a retest script: nwp-01_sqli.py, nwp-02_jwt_none.py, nwp-03_idor.py, nwp-05_ssrf.py, nwp-06_xss.py, and so on. Point BASE_URL at the environment and retest_all.py prints a pass/fail table.
Each script asserts the fix, not the bug: a forged alg:none admin token is rejected with 401; another user's order id returns 403 or 404 rather than 200; metadata and RFC1918 URLs are refused by the image proxy. Evidence sits beside them — the forged token itself is committed at evidence/NWP-02/forged-token.txt.
A report that can re-test itself stops being a snapshot and becomes something you can run again in six months.
Notes
Entirely fictional, and it says so first. A SIMULATED DEMO badge sits next to the engagement id on the front page, and the vault states it in its own text: "Everything here is fictional — the company (Northwind Provisions), the app…". The audit confirmed it: every host is a reserved .example domain, every address an @example.com, and the only public IP is 169.254.169.254 — the cloud metadata address any SSRF finding cites. The consulting firm and its named team are invented, with no contact details attached.