Pallos Proof Lab

Proof Lab.

Controlled tests showing what Pallos catches, flags for review, and cannot establish. These two reproducible cases use a pinned commit of OWASP Juice Shop, an intentionally insecure training app. They are not customer results or a full-repository benchmark.

Source commit 1618a611b173·Scanner rule-level reproduction

Controlled two-case sample

Scroll sideways for all columns →
BenchmarkCommitTestsCorrectPartialMissedCould not verify
Dynamic execution · Juice Shop1618a6112110 in sampleRuntime impact

This is a selected rule demonstration, not a measured detection rate. Missed findings elsewhere and false-positive rate have not been measured. Source evidence cannot verify deployed exploitability.

EXAMPLE 01 · Lower-confidence review

Dynamic code execution needs review

Review · Needs review

routes/captcha.ts:22View pinned source

Known issue / expected behavior: Avoid a high-priority injection finding because the expression is generated from fixed operators; a low-priority review note would be enough.

Pallos result: Dynamic code execution needs review. Classification: Partial within this two-case sample.

The expression is assembled from generated numbers and a fixed list of arithmetic operators. Pallos did not see an obvious user-controlled source in this file, so it does not label this as a confirmed injection.

Limit: This is a source-level observation, not a runtime test. Other files or configuration could change the trust boundary.

EXAMPLE 02 · Higher-confidence data flow

User-derived value reaches dynamic code execution

High · High confidence

routes/userProfile.ts:65View pinned source

Known issue / expected behavior: Identify the visible user-data flow into eval and give a concrete fix direction.

Pallos result: User-derived value reaches dynamic code execution. Classification: Correct within this two-case sample.

The code assigns `user.username` to `username`, derives `code` from that value, then passes `code` to `eval`. The route only takes this branch when the named training challenge is enabled.

Limit: Static analysis shows the source-level flow; Pallos did not run the app or verify the challenge's deployed configuration.

What this demonstrates

Confidence follows the evidence.

The same broad rule can produce a review signal or a higher-confidence finding depending on visible source context. Severity describes potential impact; confidence describes the evidence found. Neither establishes runtime exploitability.

Read the checks and limits

Want to inspect a whole public repository?

Run the current scan yourself.

It reviews one current commit, never executes repository code, and lists checks Pallos could not verify.

Scan this repository