{
  "schema_version": "1.0",
  "methodology": "Dated evaluations are limited to the recorded version, fixtures and scope. A scoped pass is not a security certification. Reference reviews are not software execution. Failed, partial, blocked, not runnable and not tested remain distinct.",
  "records": [
    {
      "id": "d4538935ccfe",
      "name": "APIs for OSINT",
      "status": "reference_review",
      "kind": "directory",
      "checked_at": "2026-10-10T16:44:05.180550Z",
      "version": "Source commit 820435b653d5d2f7bc7fc16cfb9562ec2517e0aa",
      "summary": "A useful shortlist of OSINT APIs; provider execution and access remain untested.",
      "scope": "Select domain metadata and archive sources for a synthetic company domain.",
      "observed": "Selected DomainsDB, host.io and Wayback documentation; all 3 sampled references responded.",
      "limitations": [
        "Sample is 3 outbound references, not the whole directory.",
        "No API query, account, payment, authentication, data accuracy or freshness was tested."
      ],
      "checks": [
        {
          "name": "Source-selection task",
          "outcome": "passed",
          "observation": "Choose domain metadata and archive sources for a synthetic company domain."
        },
        {
          "name": "Outbound reference 1",
          "outcome": "passed",
          "observation": "domain-index: HTTP 200; reference page retrieved."
        },
        {
          "name": "Outbound reference 2",
          "outcome": "passed",
          "observation": "domain-metadata: HTTP 200; reference page retrieved."
        },
        {
          "name": "Outbound reference 3",
          "outcome": "passed",
          "observation": "archive-history: HTTP 200; reference page retrieved."
        },
        {
          "name": "Selection control",
          "outcome": "passed",
          "observation": "Selection excludes active scans; topic match is a reading decision, not a tool execution result."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://github.com/cipher387/API-s-for-OSINT",
        "https://domainsdb.info",
        "https://host.io/",
        "https://archive.org/help/wayback_api.php",
        "https://github.com/cipher387/API-s-for-OSINT/tree/820435b653d5d2f7bc7fc16cfb9562ec2517e0aa"
      ]
    },
    {
      "id": "fdb43475d429",
      "name": "Awesome-Search-Engines-for-Cybersecurity-Researchers",
      "status": "reference_review",
      "kind": "directory",
      "checked_at": "2026-10-10T16:44:05.181258Z",
      "version": "Source commit 2869ddb823489b7e29cd6fc87b43ad03adf08fc3",
      "summary": "Reference selection worked for three existing search/index sources.",
      "scope": "Choose certificate and website indexes for a synthetic domain without submitting a scan.",
      "observed": "Selected crt.sh, Censys and urlscan documentation; 3 of 3 references responded.",
      "limitations": [
        "Sample is 3 references; search results, subscriptions and current access were not exercised.",
        "Existing indexed results do not establish ownership, accuracy or permission for active scanning."
      ],
      "checks": [
        {
          "name": "Source-selection task",
          "outcome": "passed",
          "observation": "Choose existing certificate and website-index sources for a synthetic domain; avoid submitting scans."
        },
        {
          "name": "Outbound reference 1",
          "outcome": "passed",
          "observation": "certificate-transparency: HTTP 200; reference page retrieved."
        },
        {
          "name": "Outbound reference 2",
          "outcome": "passed",
          "observation": "internet-index: HTTP 200; reference page retrieved."
        },
        {
          "name": "Outbound reference 3",
          "outcome": "passed",
          "observation": "historical-web-index: HTTP 200; reference page retrieved."
        },
        {
          "name": "Selection control",
          "outcome": "passed",
          "observation": "Selection excludes active scans; topic match is a reading decision, not a tool execution result."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://github.com/onhexgroup/Awesome-Search-Engines-for-Cybersecurity-Researchers",
        "https://crt.sh/",
        "https://censys.io/",
        "https://urlscan.io/",
        "https://github.com/onhexgroup/Awesome-Search-Engines-for-Cybersecurity-Researchers/tree/2869ddb823489b7e29cd6fc87b43ad03adf08fc3"
      ]
    },
    {
      "id": "2b2b6beee96e",
      "name": "awesome-security-hardening",
      "status": "reference_review",
      "kind": "directory",
      "checked_at": "2026-10-10T16:44:05.181601Z",
      "version": "Source commit 1f021665c4547308e6132c3bc03e543813996ca1",
      "summary": "The reading-selection workflow exposed unavailable and outdated material.",
      "scope": "Prepare a platform-matched reading shortlist for synthetic Ubuntu and macOS hosts; sample 3 references.",
      "observed": "One reference responded; Ubuntu documentation returned HTTP 503 and the feature wiki timed out. The reachable macOS IPv6 guide describes a historical OS X version.",
      "limitations": [
        "This is a reading review; no operating-system settings were changed or verified.",
        "Two of 3 sampled references could not be retrieved.",
        "Historical guides need version matching and current vendor confirmation before applying commands."
      ],
      "checks": [
        {
          "name": "Source-selection task",
          "outcome": "passed",
          "observation": "Prepare a reading shortlist for synthetic Ubuntu and macOS hosts; flag guides that do not match current platform versions."
        },
        {
          "name": "Outbound reference 1",
          "outcome": "blocked",
          "observation": "ubuntu-security: HTTP Error 503: Service Unavailable."
        },
        {
          "name": "Outbound reference 2",
          "outcome": "blocked",
          "observation": "ubuntu-security-features: <urlopen error timed out>."
        },
        {
          "name": "Outbound reference 3",
          "outcome": "passed",
          "observation": "macos-ipv6: HTTP 200; reference page retrieved."
        },
        {
          "name": "Selection control",
          "outcome": "passed",
          "observation": "Historical macOS guide retained as a rejected current baseline; Ubuntu version compatibility still requires checking."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://github.com/decalage2/awesome-security-hardening",
        "https://help.ubuntu.com/lts/serverguide/security.html.en",
        "https://wiki.ubuntu.com/Security/Features",
        "https://www.ernw.de/download/ERNW_Hardening_IPv6_MacOS-X_v1_0.pdf",
        "https://github.com/decalage2/awesome-security-hardening/tree/1f021665c4547308e6132c3bc03e543813996ca1"
      ]
    },
    {
      "id": "f06d0eb5c9b2",
      "name": "crucible-sigint",
      "status": "failed",
      "kind": "software",
      "checked_at": "2026-10-10T17:02:34.001966Z",
      "version": "5.0; source commit 4322826f2622c3632862655e59ad01c7f223b48d",
      "summary": "An exercised entropy-scoring control failed; other selected helpers worked.",
      "scope": "Unmodified seed validation, certificate-name extraction, mocked JavaScript indicators and legitimate-domain entropy scoring in an offline container.",
      "observed": "Seed and JavaScript controls passed. For apple.example, the original scorer returned 0.0 instead of 1.92 after character-set lstrip removed a legitimate label prefix.",
      "limitations": [
        "Overall failed denotes the demonstrated scoring error in this bounded workflow.",
        "HTTP responses were mocked; the full multi-source investigation and web UI were not run.",
        "The source includes direct target HTML/bundle fetching, so the whole pipeline cannot be treated as only third-party index lookups.",
        "Heuristic indicators and domain correlations are not proof of compromise or ownership."
      ],
      "checks": [
        {
          "name": "Seed validation and certificate deduplication",
          "outcome": "passed",
          "observation": "Normalized a valid seed, rejected an invalid seed and deduplicated certificate names."
        },
        {
          "name": "JavaScript positive and clean control",
          "outcome": "passed",
          "observation": "Seeded approval/wallet markers were found; clean HTML produced none. All requests were intercepted."
        },
        {
          "name": "Legitimate-prefix entropy control",
          "outcome": "failed",
          "observation": "apple.example expected 1.92; original function returned 0.0."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://github.com/neatlabs-ai/crucible-sigint",
        "https://github.com/neatlabs-ai/crucible-sigint/tree/4322826f2622c3632862655e59ad01c7f223b48d"
      ]
    },
    {
      "id": "337d95a9a885",
      "name": "DNS Lookup CLI Tool",
      "status": "partial",
      "kind": "educational",
      "checked_at": "2026-10-10T17:02:34.001966Z",
      "version": "0.1.1; source commit 83666be936f09ebde5a43be01006d37796c1b08e",
      "summary": "The original DNS resolver worked on local fixtures; complete CLI coverage remains open.",
      "scope": "Query a synthetic UDP DNS server from the original resolver inside an isolated container; compare an A answer with NXDOMAIN.",
      "observed": "example.test returned 192.0.2.123 with TTL 60. missing.test produced empty records and empty errors. The broader upstream suite stopped on missing async-test support.",
      "limitations": [
        "Original resolver behavior was exercised; CLI output, WHOIS, reverse lookup and public resolver behavior were not tested.",
        "NXDOMAIN is swallowed into an empty result without an error, limiting diagnosis.",
        "Initial upstream run had 11 passing and 6 failed tests because async support was absent; it is not a demonstrated resolver defect.",
        "An implementation exists at the pinned educational source; no substitute tool was invented."
      ],
      "checks": [
        {
          "name": "Local A-answer fixture",
          "outcome": "passed",
          "observation": "Original resolver returned the seeded A address and TTL."
        },
        {
          "name": "NXDOMAIN control",
          "outcome": "passed",
          "observation": "Missing synthetic name returned no records; no error detail was exposed."
        },
        {
          "name": "Broader original test-suite setup",
          "outcome": "blocked",
          "observation": "Six async tests could not run without the async pytest plugin; 11 other tests passed."
        },
        {
          "name": "Complete CLI and WHOIS workflow",
          "outcome": "not_run",
          "observation": "Only the original resolver was exercised against the local DNS fixture."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://github.com/CarterPerez-dev/Cybersecurity-Projects/tree/83666be936f09ebde5a43be01006d37796c1b08e/PROJECTS/beginner/dns-lookup",
        "https://github.com/CarterPerez-dev/Cybersecurity-Projects/tree/83666be936f09ebde5a43be01006d37796c1b08e"
      ]
    },
    {
      "id": "85cc972acacd",
      "name": "exs-cyberjob-scraper",
      "status": "partial",
      "kind": "software",
      "checked_at": "2026-10-10T17:02:34.001966Z",
      "version": "0.1.0; source commit e84a126d6aa2485d19aa6ee9c348c4d9fedf0815",
      "summary": "Original certification analysis passed offline; job collection was not exercised.",
      "scope": "Run original Certification/Posting/Analyzer modules and selected ExUnit tests on two synthetic postings, without loading live configuration.",
      "observed": "Six tests passed. A certification repeated in one of two postings counted once, yielding 50%.",
      "limitations": [
        "No job API, external HTML scraping, access token, CLI ingestion or complete storage workflow was tested.",
        "Only the selected original analysis modules were loaded; this is not proof that the live scraper operates."
      ],
      "checks": [
        {
          "name": "Original module tests",
          "outcome": "passed",
          "observation": "Six selected ExUnit tests passed."
        },
        {
          "name": "Repeated-certification and empty-posting control",
          "outcome": "passed",
          "observation": "One matching posting out of two produced count 1 and 50%; repeated mentions did not double count."
        },
        {
          "name": "Live job collection",
          "outcome": "not_run",
          "observation": "Provider requests and credential configuration were excluded."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://github.com/CarterPerez-dev/exs-cyberjob-scraper",
        "https://github.com/CarterPerez-dev/exs-cyberjob-scraper/tree/e84a126d6aa2485d19aa6ee9c348c4d9fedf0815"
      ]
    },
    {
      "id": "80b9fef412b4",
      "name": "Gitleaks",
      "status": "passed",
      "kind": "software",
      "checked_at": "2026-10-10T16:39:10.679375Z",
      "version": "8.30.1; official Linux ARM64 release",
      "summary": "Filesystem secret detection worked on a seeded file and a clean control.",
      "scope": "Run Gitleaks dir on a synthetic credential-shaped string and a clean document in an offline container.",
      "observed": "The seeded file produced 2 findings and exit 1; the clean directory produced 0 findings and exit 0. Secret text in reports is redacted.",
      "limitations": [
        "The string is synthetic and was never validated with a provider.",
        "Git history, custom policies, pre-commit hooks and real repository coverage were not tested.",
        "Maintainer describes the project as feature complete with security maintenance; suitability still depends on the required workflow."
      ],
      "checks": [
        {
          "name": "Official release identity",
          "outcome": "passed",
          "observation": "Version and publisher checksum matched the downloaded 8.30.1 release."
        },
        {
          "name": "Seeded filesystem detection",
          "outcome": "passed",
          "observation": "Two findings; exit 1 is the intended detection signal."
        },
        {
          "name": "Clean filesystem control",
          "outcome": "passed",
          "observation": "Zero findings and exit 0."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://github.com/gitleaks/gitleaks",
        "https://github.com/gitleaks/gitleaks/tree/b58d3f102cf3a2c84cb7f923d05c25c9b1aed84b"
      ]
    },
    {
      "id": "71af2d078352",
      "name": "HTTP Headers Scanner",
      "status": "passed",
      "kind": "educational",
      "checked_at": "2026-10-10T17:02:34.001966Z",
      "version": "1.0.0; source commit 83666be936f09ebde5a43be01006d37796c1b08e",
      "summary": "The original header scanner and CLI distinguished strong and bare localhost responses.",
      "scope": "Scan two synthetic HTTP responses with the original library and CLI; run its 13 original tests in a container.",
      "observed": "Strong headers scored 100/A with CLI exit 0; bare headers scored 0/F with exit 2. All 13 original tests passed.",
      "limitations": [
        "Plain HTTP localhost evaluates header scoring; browsers ignore HSTS on HTTP.",
        "HTTPS/TLS, authentication, redirects, real sites and exhaustive vulnerability detection were not tested.",
        "An educational implementation exists; the grade is a heuristic rather than a security guarantee."
      ],
      "checks": [
        {
          "name": "Original tests",
          "outcome": "passed",
          "observation": "13 original tests passed."
        },
        {
          "name": "Strong-header positive case",
          "outcome": "passed",
          "observation": "Score 100/A and CLI exit 0 for the synthetic strong response."
        },
        {
          "name": "Missing-header control",
          "outcome": "passed",
          "observation": "Score 0/F and CLI exit 2 for the bare response."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://github.com/CarterPerez-dev/Cybersecurity-Projects/tree/83666be936f09ebde5a43be01006d37796c1b08e/PROJECTS/foundations/http-headers-scanner",
        "https://github.com/CarterPerez-dev/Cybersecurity-Projects/tree/83666be936f09ebde5a43be01006d37796c1b08e"
      ]
    },
    {
      "id": "decc84a7b403",
      "name": "Image Scrubber",
      "status": "partial",
      "kind": "software",
      "checked_at": "2026-10-10T17:02:34.001966Z",
      "version": "Served app matches source commit 390b166cfc61326476ed9d6cb376291f87e35c23",
      "summary": "Actual export achieved EXIF removal and opaque redaction, but strict pixel equality failed.",
      "scope": "Lead uploaded one synthetic 640×400 JPEG to the official app, inspected EXIF, painted a rectangle and exported the actual downloaded PNG; artifacts independently reviewed.",
      "observed": "Dimensions stayed 640×400, 3 EXIF tags became 0, and all 52,800 intended redaction pixels were opaque black. The unpainted control differed by at most 1/255 per channel.",
      "limitations": [
        "One JPEG and opaque rectangular paint only; blur, rotation, orientation, large images and batch behavior were not tested.",
        "Only EXIF in this exported PNG was checked; no claim covers every metadata format.",
        "Network privacy was not tested.",
        "Strict untouched-pixel equality failed; rounding is a possible explanation, not proven.",
        "Browser download-event observation timed out; the native output was independently found and verified by timestamp/content."
      ],
      "checks": [
        {
          "name": "Actual export dimensions",
          "outcome": "passed",
          "observation": "Actual downloaded PNG retained 640×400 dimensions."
        },
        {
          "name": "Synthetic EXIF removal",
          "outcome": "passed",
          "observation": "Input had 3 synthetic EXIF tags; actual exported PNG had zero."
        },
        {
          "name": "Opaque redaction",
          "outcome": "passed",
          "observation": "All 52,800 pixels in the intended redaction rectangle were opaque black."
        },
        {
          "name": "Untouched-region tolerance control",
          "outcome": "passed",
          "observation": "Maximum unpainted-region difference was 1 on a 0–255 channel scale."
        },
        {
          "name": "Initial strict equality control",
          "outcome": "failed",
          "observation": "Exact equality failed; the export is not claimed to preserve untouched pixels byte for byte."
        },
        {
          "name": "Independent artifact and source readback",
          "outcome": "passed",
          "observation": "Input/output bytes and three served source files were independently matched to the receipt."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://everestpipkin.github.io/image-scrubber/",
        "https://github.com/everestpipkin/image-scrubber/tree/390b166cfc61326476ed9d6cb376291f87e35c23"
      ]
    },
    {
      "id": "66c10181774f",
      "name": "LLM Prompt Injection Firewall",
      "status": "partial",
      "kind": "educational",
      "checked_at": "2026-10-10T17:02:34.001966Z",
      "version": "0.1.0; source commit 83666be936f09ebde5a43be01006d37796c1b08e",
      "summary": "Selected original firewall decisions passed offline; complete model/proxy operation is untested.",
      "scope": "Run 88 selected original tests covering firewall decisions, mock-agent cases, tool authorization and egress canary controls with no provider calls.",
      "observed": "All 88 tests passed, including benign input, seeded instruction attacks, disabled-layer controls and encoded-canary rejection. Hypothesis used in-memory storage.",
      "limitations": [
        "Code-level and mock-agent tests are not a complete deployed firewall service test.",
        "No real LLM, provider API, hosted proxy, UI or production resistance evaluation was performed.",
        "An implementation exists at the educational source; passing these cases does not guarantee prevention of arbitrary prompt injection."
      ],
      "checks": [
        {
          "name": "Original firewall and end-to-end mock tests",
          "outcome": "passed",
          "observation": "Selected original suite completed: 88 passed."
        },
        {
          "name": "Positive and negative/control cases",
          "outcome": "passed",
          "observation": "Original tests covered benign allow, seeded attack block, layer controls, tool allowlists and encoded-canary egress."
        },
        {
          "name": "Complete provider/proxy operation",
          "outcome": "not_run",
          "observation": "External model providers and hosted proxy behavior were excluded."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://github.com/CarterPerez-dev/Cybersecurity-Projects/tree/83666be936f09ebde5a43be01006d37796c1b08e/PROJECTS/beginner/prompt-injection-firewall",
        "https://github.com/CarterPerez-dev/Cybersecurity-Projects/tree/83666be936f09ebde5a43be01006d37796c1b08e"
      ]
    },
    {
      "id": "b7105f51351a",
      "name": "MetaOSINT.github.io",
      "status": "reference_review",
      "kind": "directory",
      "checked_at": "2026-10-10T16:44:05.955618Z",
      "version": "Source commit de6490ac2be61117e47d0ba0aab5ea55632cbdf7",
      "summary": "The archived category table supported a bounded source-selection task.",
      "scope": "Use the Domains / DNS category to select three existing research indexes for a synthetic domain.",
      "observed": "The category yielded crt.sh, Censys and urlscan; all 3 sampled references responded.",
      "limitations": [
        "Archived directory; 3 sampled references do not validate all entries or present-day access.",
        "Citation counts describe inclusion frequency, not reliability or data quality.",
        "No index queries, API calls or scan submissions were made."
      ],
      "checks": [
        {
          "name": "Source-selection task",
          "outcome": "passed",
          "observation": "Use the Domains / DNS category to select three passive sources for a synthetic domain."
        },
        {
          "name": "Outbound reference 1",
          "outcome": "passed",
          "observation": "certificate-transparency: HTTP 200; reference page retrieved."
        },
        {
          "name": "Outbound reference 2",
          "outcome": "passed",
          "observation": "internet-index: HTTP 200; reference page retrieved."
        },
        {
          "name": "Outbound reference 3",
          "outcome": "passed",
          "observation": "historical-web-index: HTTP 200; reference page retrieved."
        },
        {
          "name": "Selection control",
          "outcome": "passed",
          "observation": "Selection excludes active scans; topic match is a reading decision, not a tool execution result."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://github.com/MetaOSINT/MetaOSINT.github.io",
        "https://crt.sh",
        "https://censys.io",
        "https://urlscan.io",
        "https://github.com/MetaOSINT/MetaOSINT.github.io/tree/de6490ac2be61117e47d0ba0aab5ea55632cbdf7"
      ]
    },
    {
      "id": "5f261cdbae4a",
      "name": "nadezhda / Security News Scraper",
      "status": "partial",
      "kind": "educational",
      "checked_at": "2026-10-10T17:02:34.001966Z",
      "version": "0.1.0-dev; source commit 83666be936f09ebde5a43be01006d37796c1b08e",
      "summary": "Offline news-ingestion components passed; the complete external-feed CLI was not run.",
      "scope": "Run nine original Go package suites covering parse, CVE extraction, localhost fetch, normalization, clustering, ranking, SQLite, export and ingestion.",
      "observed": "All 9 packages passed, with 100 PASS lines including subtests. Local HTTP and temporary-database cases covered ingestion/deduplication and malformed/not-modified controls.",
      "limitations": [
        "Package and local pipeline tests do not prove live feed coverage or complete interactive CLI operation.",
        "No external feeds, credential setup, AI provider, scheduler or real news dataset was exercised.",
        "Initial build execution was blocked by noexec temporary storage; the corrected executable container scratch passed."
      ],
      "checks": [
        {
          "name": "Nine original offline package suites",
          "outcome": "passed",
          "observation": "All nine selected packages passed; 100 PASS lines include subtests."
        },
        {
          "name": "Local ingestion and failure controls",
          "outcome": "passed",
          "observation": "Original suites exercised synthetic localhost feeds, deduplication, malformed input and not-modified responses."
        },
        {
          "name": "Initial temporary-storage setup",
          "outcome": "blocked",
          "observation": "Go test executables could not run on the initial noexec scratch mount."
        },
        {
          "name": "Complete external-feed CLI",
          "outcome": "not_run",
          "observation": "Live feeds, interactive CLI and provider integrations were excluded."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://github.com/CarterPerez-dev/Cybersecurity-Projects/tree/83666be936f09ebde5a43be01006d37796c1b08e/PROJECTS/intermediate/security-news-scraper",
        "https://github.com/CarterPerez-dev/Cybersecurity-Projects/tree/83666be936f09ebde5a43be01006d37796c1b08e"
      ]
    },
    {
      "id": "d5c16d575cc5",
      "name": "osint_stuff_tool_collection",
      "status": "reference_review",
      "kind": "directory",
      "checked_at": "2026-10-10T16:44:06.973665Z",
      "version": "Source commit f525963974e7b636e5e0d156e3a636171d3ae675",
      "summary": "The collection supported choosing archive and certificate research tools.",
      "scope": "Select tools for existing archive/certificate data for a synthetic domain and exclude active scanning tools.",
      "observed": "Selected waybackpack, GoGetCrawl and Cert4Recon repositories; all 3 sampled references responded.",
      "limitations": [
        "Sample is 3 repository references; none of those programs was installed or executed.",
        "A repository being reachable does not validate its safety, maintenance or results.",
        "Tools requiring active target contact need a separate authorized assessment."
      ],
      "checks": [
        {
          "name": "Source-selection task",
          "outcome": "passed",
          "observation": "Select archive and certificate-research tools for a synthetic domain; exclude tools with active port scanning."
        },
        {
          "name": "Outbound reference 1",
          "outcome": "passed",
          "observation": "archive-download: HTTP 200; reference page retrieved."
        },
        {
          "name": "Outbound reference 2",
          "outcome": "passed",
          "observation": "archive-search: HTTP 200; reference page retrieved."
        },
        {
          "name": "Outbound reference 3",
          "outcome": "passed",
          "observation": "certificate-search: HTTP 200; reference page retrieved."
        },
        {
          "name": "Selection control",
          "outcome": "passed",
          "observation": "Selection excludes active scans; topic match is a reading decision, not a tool execution result."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://github.com/cipher387/osint_stuff_tool_collection",
        "https://github.com/jsvine/waybackpack",
        "https://github.com/karust/gogetcrawl",
        "https://github.com/mathis2001/Cert4Recon",
        "https://github.com/cipher387/osint_stuff_tool_collection/tree/f525963974e7b636e5e0d156e3a636171d3ae675"
      ]
    },
    {
      "id": "2424badde310",
      "name": "OSQuery",
      "status": "passed",
      "kind": "software",
      "checked_at": "2026-10-10T16:46:46.423680Z",
      "version": "5.23.1; official Linux aarch64 release",
      "summary": "Real file/hash instrumentation worked on a harmless container fixture.",
      "scope": "Query the original osquery file and hash virtual tables for one synthetic container file, plus missing-file and invalid-SQL controls.",
      "observed": "The file table returned the correct name and 42-byte size. The hash table matched independently computed SHA256; a missing path returned zero rows. Invalid SQL was rejected.",
      "limitations": [
        "Only a synthetic file in a Linux container was inventoried; no host private data was queried.",
        "Processes, events, services, fleet enrollment and macOS/Windows inventory were not tested.",
        "SQL constants alone were setup evidence; the pass rests on actual file/hash instrumentation."
      ],
      "checks": [
        {
          "name": "Official release identity",
          "outcome": "passed",
          "observation": "Downloaded archive hash matched the official asset digest; binary reported 5.23.1."
        },
        {
          "name": "Synthetic file inventory",
          "outcome": "passed",
          "observation": "Correct fixture filename and size 42 returned from the file table."
        },
        {
          "name": "Independent file hash",
          "outcome": "passed",
          "observation": "Instrumented SHA256 matched the fixture hash."
        },
        {
          "name": "Missing-file control",
          "outcome": "passed",
          "observation": "The absent synthetic path returned an empty row set."
        },
        {
          "name": "Invalid-SQL control",
          "outcome": "passed",
          "observation": "Unknown-column query failed as expected."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://osquery.io/",
        "https://osquery.readthedocs.io/en/stable/introduction/sql/",
        "https://github.com/osquery/osquery/tree/390c347286ec759b630c24d1dd12e6988661900e"
      ]
    },
    {
      "id": "c5bb16ef8a00",
      "name": "OWASP ZAP",
      "status": "passed",
      "kind": "software",
      "checked_at": "2026-10-10T16:58:28.140304Z",
      "version": "2.17.0; official container image digest in evidence",
      "summary": "The localhost passive baseline detected missing headers and distinguished the header control.",
      "scope": "Run official ZAP baseline against synthetic HTTP fixtures only, with updates off, network isolation and a fresh container for the control.",
      "observed": "Bare response produced 4 warning classes. CSP, anti-clickjacking and nosniff warnings disappeared in the strong control; its server-version warning remained. Exit 2 denotes warnings, not startup failure.",
      "limitations": [
        "A passive baseline still performs a short crawl; only localhost fixtures were targeted.",
        "No active attack scan, authentication, HTTPS, real application or complete vulnerability assessment was run.",
        "The strong control retains a server-version warning; it is not an all-clean security result.",
        "Earlier unwritable settings/startup attempts and the reused-settings control timeout are preserved."
      ],
      "checks": [
        {
          "name": "Bare localhost baseline",
          "outcome": "passed",
          "observation": "Detected CSP, anti-clickjacking, nosniff and server-version warning classes."
        },
        {
          "name": "Strong-header control in fresh container",
          "outcome": "passed",
          "observation": "Three intended header warning classes disappeared; server-version warning remained."
        }
      ],
      "earlier_attempts": [
        {
          "name": "Initial settings/startup setup",
          "outcome": "blocked",
          "observation": "Initial baseline attempts could not connect to ZAP within 120 seconds; corrected settings later completed."
        },
        {
          "name": "Reused-settings control setup",
          "outcome": "blocked",
          "observation": "The second case timed out; a fresh disposable container completed the control."
        }
      ],
      "sources": [
        "https://www.zaproxy.org/",
        "https://www.zaproxy.org/docs/docker/baseline-scan/",
        "https://github.com/zaproxy/zaproxy/tree/38ffe34a1b03fd3241e0bb233c2a083df875ee33"
      ]
    },
    {
      "id": "13b7d4576ea6",
      "name": "Personal Security Checklist",
      "status": "reference_review",
      "kind": "checklist",
      "checked_at": "2026-10-10T16:44:07.727159Z",
      "version": "Source commit cc27041690e20a7c6f7ef4ef0202c4f22e2c691a",
      "summary": "The checklist supported a prioritized synthetic security plan.",
      "scope": "Prioritize unique managed passwords, a second factor and encrypted backup/restore; sample 3 relevant outbound references.",
      "observed": "Selected password-manager, second-factor and encrypted-storage reading; 3 of 3 references responded.",
      "limitations": [
        "Advice/checklist review, not executed security software or a completed personal security audit.",
        "Sample links are curated pages; current vendor procedures still need confirmation.",
        "No accounts, devices, passwords, backup encryption or restore were configured or tested."
      ],
      "checks": [
        {
          "name": "Source-selection task",
          "outcome": "passed",
          "observation": "Prioritize a synthetic user plan: unique managed passwords, second factor, then encrypted backup with a restore check."
        },
        {
          "name": "Outbound reference 1",
          "outcome": "passed",
          "observation": "password-manager: HTTP 200; reference page retrieved."
        },
        {
          "name": "Outbound reference 2",
          "outcome": "passed",
          "observation": "second-factor: HTTP 200; reference page retrieved."
        },
        {
          "name": "Outbound reference 3",
          "outcome": "passed",
          "observation": "encrypted-backup: HTTP 200; reference page retrieved."
        },
        {
          "name": "Selection control",
          "outcome": "passed",
          "observation": "Selection excludes active scans; topic match is a reading decision, not a tool execution result."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://github.com/Lissy93/personal-security-checklist",
        "https://awesome-privacy.xyz/essentials/password-managers/bitwarden",
        "https://github.com/Lissy93/awesome-privacy#2-factor-authentication",
        "https://awesome-privacy.xyz/security-tools/mobile-apps/cryptomator",
        "https://github.com/Lissy93/personal-security-checklist/tree/cc27041690e20a7c6f7ef4ef0202c4f22e2c691a"
      ]
    },
    {
      "id": "5eab6ac8e7e7",
      "name": "Prowler",
      "status": "partial",
      "kind": "software",
      "checked_at": "2026-10-10T17:02:34.001966Z",
      "version": "5.44.0 dependency image; tested source commit 61d2cc55c4539a6b48a3cf9f3729d8f2af300882",
      "summary": "One original cloud check passed with offline AWS doubles; account auditing remains untested.",
      "scope": "Run 13 original S3 bucket public-access check tests with Moto mocks in a network-none container using synthetic dummy credentials only.",
      "observed": "All 13 original tests passed across mocked account/bucket public-access states. No real cloud account was enumerated.",
      "limitations": [
        "This evaluates one original check against mocks, not Prowler authentication, full cloud enumeration or compliance posture.",
        "Other services, cloud providers, report completeness and live account permissions were not tested.",
        "Source snapshot and dependency release image are separately bound; source is not asserted byte-identical to the release.",
        "Initial setup failures involved stripped pip and user permissions; corrected uv installation and UID 1000 test execution passed."
      ],
      "checks": [
        {
          "name": "Original offline S3 check tests",
          "outcome": "passed",
          "observation": "All 13 selected original tests passed with mocked AWS responses."
        },
        {
          "name": "Synthetic access-state controls",
          "outcome": "passed",
          "observation": "Original tests compared public-access blocked/allowed account and bucket fixtures; no account calls left the container."
        },
        {
          "name": "Initial dependency/user setup",
          "outcome": "blocked",
          "observation": "Initial dependency installation and root execution failed; exact errors are preserved."
        },
        {
          "name": "Live account audit",
          "outcome": "not_run",
          "observation": "Real cloud accounts and credentials were excluded."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://github.com/prowler-cloud/prowler",
        "https://github.com/prowler-cloud/prowler/tree/61d2cc55c4539a6b48a3cf9f3729d8f2af300882"
      ]
    },
    {
      "id": "74def8b8134e",
      "name": "Quad9",
      "status": "partial",
      "kind": "service",
      "checked_at": "2026-10-10T17:02:35.047974Z",
      "version": "Public resolver 9.9.9.9 UDP/53; client DiG 9.10.6; server build not exposed",
      "summary": "Basic public DNS resolution worked; protective blocking and encrypted transports were not tested.",
      "scope": "Make two benign explicit queries to Quad9 using native dig, without changing host DNS settings.",
      "observed": "example.com returned NOERROR with 2 A answers; the synthetic .invalid name returned NXDOMAIN with no answers.",
      "limitations": [
        "Two UDP DNS requests only; the resolver service has no exposed build version in this test.",
        "Malware blocking, DNSSEC rejection, DoH/DoT, privacy guarantees, regional reliability and router/host configuration were not tested.",
        "An NXDOMAIN control is not evidence of threat blocking."
      ],
      "checks": [
        {
          "name": "Benign positive DNS query",
          "outcome": "passed",
          "observation": "NOERROR with two A answers from 9.9.9.9."
        },
        {
          "name": "Reserved-name negative control",
          "outcome": "passed",
          "observation": "Synthetic .invalid query returned NXDOMAIN and zero answers."
        },
        {
          "name": "Protective blocking and encrypted transport",
          "outcome": "not_run",
          "observation": "Only benign UDP resolution was exercised."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://quad9.net/",
        "https://quad9.net/support/faq/"
      ]
    },
    {
      "id": "a8eb6e6430a9",
      "name": "Semgrep",
      "status": "passed",
      "kind": "software",
      "checked_at": "2026-10-10T16:39:17.715407Z",
      "version": "1.180.0; official container image digest in evidence",
      "summary": "The local Python rule engine found seeded unsafe code and cleared the control.",
      "scope": "Run one explicit custom Semgrep Python rule against synthetic shell=True code and shell=False code, offline with metrics/update checks off.",
      "observed": "Unsafe code produced 1 finding; the safe-form control produced 0. Both JSON reports contained no parser errors.",
      "limitations": [
        "One custom rule in one language; the result is not a complete code security audit.",
        "Registry rule packs, taint analysis, Pro engine, hosted workflows and dependency scanning were not tested.",
        "The fixture code was analyzed, not executed."
      ],
      "checks": [
        {
          "name": "Executable version",
          "outcome": "passed",
          "observation": "Official image reported Semgrep 1.180.0."
        },
        {
          "name": "Seeded unsafe-code detection",
          "outcome": "passed",
          "observation": "One custom-rule finding and no parser errors."
        },
        {
          "name": "Safe-form control",
          "outcome": "passed",
          "observation": "Zero findings and no parser errors."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://semgrep.dev/",
        "https://docs.semgrep.dev/running-rules",
        "https://github.com/semgrep/semgrep/tree/38a67a7eaf724fc266bf96e5705742bff8589775"
      ]
    },
    {
      "id": "c90cc8650405",
      "name": "SimpleLogin",
      "status": "partial",
      "kind": "service",
      "checked_at": "2026-10-10T17:02:34.001966Z",
      "version": "Source commit 070155c702a2bc6b0fdff46594e9cc931f61aa37",
      "summary": "Original alias-validation helpers passed offline; email service operation remains untested.",
      "scope": "Call the original alias suffix and timestamp-signature helpers with synthetic inputs and configuration/logging/model doubles, in an offline container.",
      "observed": "Authorized suffix and valid signature were accepted. Foreign-domain suffix, empty prefix and tampered signature were rejected. Zero service operations occurred.",
      "limitations": [
        "Helper-level tests do not prove alias creation, persistence, forwarding, delivery, account operation or end-to-end service behavior.",
        "Configuration, logging and ORM models were explicit dependency doubles; PostgreSQL and SMTP were not started.",
        "No account, email, live credential or secret store was used."
      ],
      "checks": [
        {
          "name": "Authorized suffix control",
          "outcome": "passed",
          "observation": "The original helper accepted the permitted synthetic suffix."
        },
        {
          "name": "Invalid suffix and signature controls",
          "outcome": "passed",
          "observation": "Foreign domain, empty prefix and tampered signature were rejected; valid signature was accepted."
        },
        {
          "name": "Complete alias/email operation",
          "outcome": "not_run",
          "observation": "Account creation, persistence and email forwarding require further authorized service access."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://github.com/simple-login/app",
        "https://github.com/simple-login/app/tree/070155c702a2bc6b0fdff46594e9cc931f61aa37"
      ]
    },
    {
      "id": "8753db7699be",
      "name": "Trivy",
      "status": "passed",
      "kind": "software",
      "checked_at": "2026-10-10T16:58:23.855281Z",
      "version": "0.75.0; DB schema 2 updated 2026-10-10T12:33:35.352381306Z",
      "summary": "Package-CVE, secret and Dockerfile checks worked on synthetic fixtures with bounded controls.",
      "scope": "Download the official public vulnerability DB during setup, then scan two tiny npm lockfiles offline; also scan synthetic secret and Dockerfile fixtures.",
      "observed": "lodash 4.17.20 produced 5 CVEs including CVE-2021-23337. The 4.17.21 control excluded that CVE but still had 3 other findings. Secret scan found 1 seeded secret and 0 in clean input; unsafe Dockerfile had 3 findings and its control 0.",
      "limitations": [
        "One npm dependency and one selected CVE control; lodash 4.17.21 is not claimed generally vulnerability-free.",
        "No package installation, exploit execution, real repository, OS/container package inventory, Java DB or complete ecosystem coverage was tested.",
        "CVE results reflect the dated DB snapshot, whose SHA256 and metadata are preserved; future DB contents may differ.",
        "Secret validity was never checked.",
        "An initial config invocation used an unsupported offline-scan flag; corrected invocations used the embedded checks in a network-none container."
      ],
      "checks": [
        {
          "name": "Official release identity",
          "outcome": "passed",
          "observation": "Publisher checksum matched the official 0.75.0 release archive."
        },
        {
          "name": "Bounded official DB setup",
          "outcome": "passed",
          "observation": "Public vulnerability DB setup completed within the 210-second bound."
        },
        {
          "name": "Old-package CVE detection",
          "outcome": "passed",
          "observation": "Parsed lodash 4.17.20 and detected CVE-2021-23337 among five findings."
        },
        {
          "name": "Target-CVE patched control",
          "outcome": "passed",
          "observation": "Parsed lodash 4.17.21; CVE-2021-23337 disappeared, while three other findings remained."
        },
        {
          "name": "Seeded secret detection",
          "outcome": "passed",
          "observation": "One synthetic credential-shaped secret was detected."
        },
        {
          "name": "Clean secret control",
          "outcome": "passed",
          "observation": "Clean input produced zero secret findings."
        },
        {
          "name": "Unsafe Dockerfile detection",
          "outcome": "passed",
          "observation": "Unsafe Dockerfile produced three misconfiguration findings."
        },
        {
          "name": "Dockerfile control",
          "outcome": "passed",
          "observation": "The scoped stronger Dockerfile produced zero misconfiguration findings."
        }
      ],
      "earlier_attempts": [
        {
          "name": "Initial unsupported-flag setup",
          "outcome": "failed",
          "observation": "The config command rejected offline-scan; corrected offline-container invocations passed. This was a superseded invocation error."
        }
      ],
      "sources": [
        "https://github.com/aquasecurity/trivy",
        "https://trivy.dev/docs/v0.75/guide/configuration/db/",
        "https://trivy.dev/docs/v0.75/guide/target/filesystem/",
        "https://github.com/advisories/GHSA-35jh-r3h4-6jhm",
        "https://github.com/aquasecurity/trivy/tree/7c1b1fa19f1628132a9e8377fed127682500d87d"
      ]
    },
    {
      "id": "96efd5297fe1",
      "name": "TruffleHog",
      "status": "passed",
      "kind": "software",
      "checked_at": "2026-10-10T16:39:13.262072Z",
      "version": "3.99.2; official Linux ARM64 release",
      "summary": "Filesystem secret detection worked with verification and updates disabled.",
      "scope": "Run TruffleHog filesystem on one synthetic credential-shaped file and a clean control in a network-none container, with no-update and no-verification.",
      "observed": "The seeded file produced one unverified GitHub-pattern finding; the clean control produced no findings. No provider verification occurred.",
      "limitations": [
        "The string is deliberately synthetic; it was never verified or used as a credential.",
        "Git history, cloud sources, alternate detectors and verified-secret operation were not tested.",
        "Finding output is redacted; exit 0 by itself is not a no-secret signal."
      ],
      "checks": [
        {
          "name": "Official release identity",
          "outcome": "passed",
          "observation": "Version and publisher checksum matched the official 3.99.2 release."
        },
        {
          "name": "Synthetic unverified detection",
          "outcome": "passed",
          "observation": "One unverified pattern finding with verification/update flags off."
        },
        {
          "name": "Clean filesystem control",
          "outcome": "passed",
          "observation": "No finding JSON was emitted for clean input."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://github.com/trufflesecurity/trufflehog",
        "https://github.com/trufflesecurity/trufflehog/tree/3bcf19f51e91a9655d84ddb623728c7620be482a"
      ]
    },
    {
      "id": "f58fd4cb2c55",
      "name": "uBlock Origin",
      "status": "blocked",
      "kind": "software",
      "checked_at": "2026-10-10T16:51:34.184473Z",
      "version": "1.75.0 official signed XPI; disposable Firefox 153.0",
      "summary": "The isolated browser installed the extension, but the filtering control could not complete.",
      "scope": "Attempt to install the official signed extension in a new disposable Firefox profile and apply a localhost-only custom script filter in a network-none container.",
      "observed": "Both synthetic scripts loaded before installation and the add-on installed. Extension settings/editor automation hit access, click-interception and timeout errors before a completed post-filter observation.",
      "limitations": [
        "No claim that request blocking passed or failed: the core filtered-page assertion was not reached.",
        "Default lists, remote list updates, ad/tracker effectiveness, popup behavior and other browsers were not tested.",
        "Only disposable container profiles were used; no shared user browser/profile was modified.",
        "Firefox privileged driver access was limited to reading this disposable extension UUID."
      ],
      "checks": [
        {
          "name": "Official extension acquisition",
          "outcome": "passed",
          "observation": "Signed 1.75.0 XPI downloaded from the maintainer release; file SHA256 preserved."
        },
        {
          "name": "Unfiltered localhost baseline",
          "outcome": "passed",
          "observation": "Both seeded scripts loaded in the disposable browser before extension installation."
        },
        {
          "name": "Custom-filter execution",
          "outcome": "blocked",
          "observation": "Settings automation timed out before a post-filter result; earlier access/click errors are preserved."
        }
      ],
      "earlier_attempts": [],
      "sources": [
        "https://ublockorigin.com/",
        "https://github.com/gorhill/uBlock",
        "https://github.com/gorhill/uBlock/wiki/Deploying-uBlock-Origin",
        "https://github.com/gorhill/uBlock/tree/b711687470f72ee0844a843102b0ca61580204be"
      ]
    }
  ]
}
