# Penetration Test Report, a published vault

> A complete penetration test delivered as a vault instead of a PDF: eight audience-specific views over one engagement, evidence per finding, and a retest script that re-runs each check and exits 0 or 1. Entirely fictional, and it says so on its own front page.

*Source: <https://sgit.ai/demos/vaults/pentest-report/index.html> · site v0.6.8 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.*

---

[Home](../../../index.md) / [Vaults](../index.md) / Penetration Test Report

# Penetration Test Report

A penetration test delivered as a **vault** rather than a PDF, and the clearest argument on this site for why that difference matters. One engagement, eight audience-specific views, evidence attached to each finding, and a runnable retest script per finding that exits `0` if it is fixed and `1` if it is not.

**Open it yourself. The key is the whole credential.**
 Read key: `sgit_public_read_14042259ecbec2d0c7c4e68963695c4ceeeeb652767d25b777024a4f05ccd025:o4lrwx02`
 In the official UI: [open it read-only in a new tab](https://dev.vault.sgraph.ai/#sgit_public_read_14042259ecbec2d0c7c4e68963695c4ceeeeb652767d25b777024a4f05ccd025%3Ao4lrwx02) · From the CLI: `sgit clone sgit_public_read_14042259ecbec2d0c7c4e68963695c4ceeeeb652767d25b777024a4f05ccd025:o4lrwx02`
Published deliberately, and **derived** one-way from a vault key that is not published and never will be.

## See it live, here

Both surfaces open automatically below. You can also [**open the app in its own window ↗**](https://dev.vault.sgraph.ai/#sgit_public_read_14042259ecbec2d0c7c4e68963695c4ceeeeb652767d25b777024a4f05ccd025%3Ao4lrwx02).

## What is in it

the reframe

### The same engagement, told for the reader in front of it

A pentest PDF is written once, for everybody, and therefore for nobody. This one opens on **Choose your view**: CEO / Executive, Decision Maker, Financial Decision Maker, Roadmap / Project, Risk Assessment Owner, AppSec Engineer, DevOps Engineer, or the full report.

Each view is its own page, opening on the sections that matter to that audience in their order. The headline numbers stay constant underneath: **10 findings**, **7 internet-reachable and unauthenticated**, a modelled annual exposure against a remediation cost, so the CFO and the AppSec engineer are demonstrably reading the same engagement.

The front page: the verdict, the numbers, and eight ways into one engagement.

the part a PDF cannot do

### Every finding ships a script that re-runs it

Ten findings, and each carries a retest script: `nwp-01_sqli.py`, `nwp-02_jwt_none.py`, `nwp-03_idor.py`, `nwp-05_ssrf.py`, `nwp-06_xss.py`, and so on. Point `BASE_URL` at the environment and `retest_all.py` prints a pass/fail table.

Each script asserts the *fix*, not the bug: a forged `alg:none` admin token is rejected with 401; another user's order id returns 403 or 404 rather than 200; metadata and RFC1918 URLs are refused by the image proxy. Evidence sits beside them, the forged token itself is committed at `evidence/NWP-02/forged-token.txt`.

A report that can re-test itself stops being a snapshot and becomes something you can run again in six months.

The vault browser: retest scripts, evidence and exports beside the report that cites them.

## Notes

**Entirely fictional, and it says so first.** A `SIMULATED DEMO` badge sits next to the engagement id on the front page, and the vault states it in its own text: *"Everything here is fictional, the company (Northwind Provisions), the app…"*. The audit confirmed it: every host is a reserved `.example` domain, every address an `@example.com`, and the only public IP is `169.254.169.254`, the cloud metadata address any SSRF finding cites. The consulting firm and its named team are invented, with no contact details attached.

[← All published vaults](../index.md)


---

*[Site index for agents](../../../llms.txt) · [HTML version](https://sgit.ai/demos/vaults/pentest-report/index.html)*
