CGI L3 — teaser preview
3 HIGH · 3 MEDIUM. Severe risks are on the public surface. This teaser shows counts and titles. The FULL report unlocks proof links, attacker/agent impact, owner, PoC, fix, and va
Summary (teaser)
This is not “just a technical PDF”
A hacker uses these findings as a map. A hacker agent runs the same playbook in a 24/7 loop. Teaser = severity. FULL = proof + impact + fix.
recon → invasion → destructive · detail in FULLSevere risks are on the public surface. This teaser shows counts and titles. The FULL report unlocks proof links, attacker/agent impact, owner, PoC, fix, and validation — so the team acts.
Stack in this run
| Component | Included? | Note |
|---|---|---|
| Sentinel L3 | YES | public-max |
| ParviClaw Core + AWP | YES (lab) | full pack in FULL |
| ParviSight | partial | as run |
| PayBotFin Witness | as engaged | honest scope in FULL |
HIGH findings — locked in teaser
CSP unsafe-inline + unsafe-eval
HIGHCSP trusts polyfill.io + broad CDNs
HIGHMassive third-party script allowlist
HIGHMEDIUM findings — short preview
Large Drupal/JS surface
MEDIUMLarge Drupal/JS surface Full impact, PoC, owner and fix → FULL report.
aide-dev.cgi.com public IIS 200
MEDIUMaide-dev.cgi.com public IIS 200 Full impact, PoC, owner and fix → FULL report.
accel360 / appstore / brand edges public
MEDIUMaccel360 / appstore / brand edges public Full impact, PoC, owner and fix → FULL report.
AWP + Core annexes (preview)
In FULL each file has captions (what it is / what it proves / what it is not) + how to run npx agent-witness-protocol verify.