Fourteen capabilities, arranged as one loop.
Each capability exists because a later stage depends on its output. Nothing is listed here as a standalone feature โ every item feeds the assessment that follows it.
- 01
Repository intake
Read the source tree, resolve the language surface, and record the exact revision under assessment.
- 02
Environment validation
Confirm the target can be built and run in isolation before any measurement begins.
- 03
Reconnaissance
Enumerate routes, forms, API endpoints, authentication flows, and static assets.
- 04
Static analysis
Locate risky constructs in source: unsafe query building, unescaped output, weak crypto, permissive configuration.
- 05
Dependency analysis
Identify declared packages and the versions actually resolved at build time.
- 06
Secret detection
Detect credential-shaped values in the repository and redact them in all output.
- 07
Dynamic testing
Exercise the running application within scope and record how it responds.
- 08
Browser investigation
Observe client-side state, storage, and rendering behaviour for issues the server never sees.
- 09
AI triage
Prioritise what is worth investigating first, using severity, reachability, and exposure of the surface.
- 10
Evidence correlation
Link each signal to its source location, the request that reached it, and related observations.
- 11
Targeted verification
Attempt reproduction for the specific claim and set the finding's verification state accordingly.
- 12
Reporting
Produce findings ordered by severity, with evidence, confidence, and stated coverage limits.
- 13
Fix guidance
Describe the remediation for the affected code path and why it removes the condition.
- 14
Retesting
Replay the verification probe against the changed application and record the result.
How to read this list
Items 01โ03 establish scope. Items 04โ08 take measurements. Items 09โ11 turn measurements into evidence. Items 12โ14 deliver a decision and prove it held.
Status of each capability
This is a hackathon-built MVP. Capabilities are implemented at different depths, and the report states which checks actually ran for a given assessment rather than implying uniform coverage.