Security-native LLM system for AI-generated application security.
- capability exposureinferred+35
- trust mitigatorsmixed−3
inferredmixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 2m ago · see ecosystem CVEs →
- A · 0 → B · 32
No known CVEs for this server.
- lowdangerous code
env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (/scratch/obs-code-noE3NA/trynullse
analyzed commit d959d85 · analyzer v20 · 14h ago
danger signals7
- suspicious endpoint169.254.169.254 (cloud metadata)trynullsec-nullsec-s1-d959d85/training/sprint_data/sprint001_batch2.py:46
exploit="url=http://169.254.169.254/latest/meta-data/iam/security-credentials/ leaks cloud creds.", - suspicious endpoint169.254.169.254 (cloud metadata)trynullsec-nullsec-s1-d959d85/training/sprint_data/sprint002_cases_p1.py:135
exploit="image_url=http://169.254.169.254/latest/meta-data/ reaches cloud metadata; GitLab's image pipeline (CVE-2021-22205) shows the class of server-side fetch/processing risk.", - suspicious endpoint169.254.169.254 (cloud metadata)trynullsec-nullsec-s1-d959d85/training/sprint_data/sprint002_cases_sup.py:16
exploit="target=http://169.254.169.254/ probes cloud metadata; same SSRF class as the GitLab image fetch (CVE-2021-22205).", - suspicious endpoint169.254.169.254 (cloud metadata)trynullsec-nullsec-s1-d959d85/training/sprint_data/sprint003_cases_p2.py:280
exploit="endpoint=http://169.254.169.254/ or internal admin URL is reachable from the server.", - suspicious endpoint169.254.169.254 (cloud metadata)trynullsec-nullsec-s1-d959d85/training/sprint_data/sprint003_cases_p3.py:136
exploit="The agent fetches http://169.254.169.254/ via the tool, leaking cloud metadata.", - suspicious endpoint169.254.169.254 (cloud metadata)trynullsec-nullsec-s1-d959d85/training/sprint_data/sprint004_cases_p3.py:16
exploit="url=http://169.254.169.254/latest/meta-data/iam/security-credentials/ reaches cloud metadata from the server.", - suspicious endpoint169.254.169.254 (cloud metadata)trynullsec-nullsec-s1-d959d85/training/sprint_data/sprint005_cases_p3.py:43
exploit="u=http://169.254.169.254/ reaches cloud metadata from the server.",
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of trynullsec.