AI-orchestrated penetration testing — independent finding verification, ATT&CK/OWASP mapping, and retest tracking, driven over MCP
OWASP Juice Shop v20.0.0 — a deliberately vulnerable web application. Full-scope web assessment with active recon, vulnerability scanning, directory discovery, and manual verification. 16 controls assessed across 4 security domains.
Top findings: Overly Permissive CORS · No HTTPS · Directory Listing on /ftp · Exposed Prometheus Metrics
zerodaybrief.blog — a production Hugo blog behind Cloudflare. Excellent hardening: hidden origin IP, strong CSP with hash-based allowlisting, HSTS with subdomain pinning, dual-layer clickjacking protection, SPF hard-fail.
Only action item: publish security.txt with vulnerability disclosure contact
Drives the toolchain from any MCP client (Claude Code / Desktop, Cursor) with scope, VPN, rate-limit, and audit guardrails enforced in code — not just documented. Destructive tools stay operator-run.
Findings tagged with MITRE ATT&CK techniques and OWASP Top 10 (2021) categories render a Framework Mapping coverage section in every report.
15 pre-approved, pre-tagged finding templates rendered into an engagement with add-finding.py — consistent language, ready for the report.
Mark findings open / fixed / regressed across rounds; the report shows a Remediation Progress section with the remediation rate. Every change is audited.