SOC-in-a-Box for AI purple teaming
- capability exposure inferred + 35
- recent drift inferred + 20
- tool safety inferred + 12
- trust mitigators mixed − 3
inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
grade last moved 6d ago · see ecosystem CVEs →
- C · 56 → D · 64
- C · 44 → C · 56
- C · 56 → C · 44
- B · 32 → C · 56
- C · 35 → B · 32
- A · 0 → C · 35
No known CVEs for this server.
- high dangerous code
committed secret: private key · dynamic exec: unsafe yaml.load(), __import__(), __import__ sink · credential logged in 1 file(s)
analyzed commit e0b22d1 · analyzer v33 · 14h ago
skills & prompt files 8
- skill Brad-Edwards-aptl-e0b22d1/.claude/skills/gh-workflow-monitor/SKILL.md
- skill Brad-Edwards-aptl-e0b22d1/.claude/skills/ship/SKILL.md
- skill Brad-Edwards-aptl-e0b22d1/.claude/skills/stage/SKILL.md
- skill Brad-Edwards-aptl-e0b22d1/.claude/skills/wave-issue-coverage/SKILL.md
- agent-rules Brad-Edwards-aptl-e0b22d1/.cursor/rules/no-jumping-ahead.mdc
- agent-rules Brad-Edwards-aptl-e0b22d1/.github/copilot-instructions.md
- agent-rules Brad-Edwards-aptl-e0b22d1/AGENTS.md
- agent-rules Brad-Edwards-aptl-e0b22d1/CLAUDE.md
danger signals7
- dynamic code execution unsafe yaml.load() Brad-Edwards-aptl-e0b22d1/src/aptl/core/experiment/spec_loading.py :147
yaml.load(text, Loader=_DuplicateKeyRejectingLoader) - dynamic code execution __import__() Brad-Edwards-aptl-e0b22d1/tests/test_appliance_seat_cli.py :64
side_effect=__import__( - dynamic code execution __import__ sink Brad-Edwards-aptl-e0b22d1/tests/test_experiment_trial_plan.py :531
_os = __import__("os") - dynamic code execution __import__ sink Brad-Edwards-aptl-e0b22d1/tests/test_host_ports.py :172
assert "APTL_HP_WAZUH_DASHBOARD_5601" not in __import__("os").environ - committed secret private key Brad-Edwards-aptl-e0b22d1/mcp/aptl-mcp-common/tests/redaction.test.ts :313
PEM private key block (redacted) - committed secret private key Brad-Edwards-aptl-e0b22d1/tests/test_redaction.py :286
PEM private key block (redacted) - credential in logs credential in log Brad-Edwards-aptl-e0b22d1/src/aptl/core/ssh.py :157
log.debug("SSH key already exists at %s", private_key)
- recent drift +20 capability drift →
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of Brad-Edwards.