Assessment Result
Fixture-driven ACME repoShow the VS Code extension as a live scorecard, not a static screenshot.
This route uses the ACME Corp fixture to present the repository tree, the security exposure mix, the redaction and injection findings, and the Chrome side panel with the same confidence and hierarchy you’d expect from a polished benchmark result.
AI detected
Yes
Security score
62/100
Signals
112
Top strengths
- 4 AI stacks surfaced
- 14 signals normalized
- 15 repo paths mapped
Priority gaps
- Prompt injection through support inbox transcripts
- Tool authority exceeds the approval boundary
- RAG responses are not yet tenant-isolated by policy
Trace Coverage
AIPSA-style scorecard view
Coverage
173/199
Risk count
6
Maturity
Managed AI Engineering
Fetch budget
87%
Signal trend
Key context
- Signals captured14
- Repo paths15
- Latest scan5/21/2026
VS Code Extension
Repo AI Forensics Dashboard
Full workspace view — AI surface explorer, live signals, risk analysis, and controls coverage.
SecEng RAG Test Harness
RAG Boundary Lens
Boundary planning, testcase generation, and evidence classification rendered from the same public-safe trace fixture.
classifyRagEvidence
Evidence scorecard
AuthZ pass
Retrieval gates are mostly aligned.
Context leaks
No leak-shaped signals surfaced.
Policy violations
Policy language needs stronger enforcement.
Poisoned chunks
No poisoned chunk patterns detected.
PII / secret hits
Redaction surfaced one or more hits.
Source provenance
Source attribution and retrieval lineage need follow-up.
Missing boundaries
What still needs to be enforced
Top 3 tests
Highest-priority harness checks
Pipeline map
planRagBoundaries → generateRagTestcases → classifyRagEvidence
Suggested tests
Controls found
Affected paths
The lens is public-safe and directional. It uses job-description intelligence and trace fixture signals to show where RAG boundaries need reinforcement, without exposing raw documents or private payloads.
Chrome Extension
AI Goggles — GitHub Side Panel
Browser-native AI intelligence. Surfaces security signals directly in the GitHub repository view.
ACME Corp Assistant Platform — AI-powered support and workflow automation. Built on OpenAI, LangChain, and Qdrant. Includes prompt injection mitigations and RAG safety controls.
SecEng RAG Test Harness
RAG Boundary Lens
Boundary planning, testcase generation, and evidence classification rendered from the same public-safe trace fixture.
AuthZ pass
Retrieval gates are mostly aligned.
Context leaks
No leak-shaped signals surfaced.
Policy violations
Policy language needs stronger enforcement.
Pipeline snapshot
5Suggested tests
3Controls found
3Affected paths
2Missing boundaries
Priority gaps
Top tests
Harness checks
The lens is public-safe and directional. It uses job-description intelligence and trace fixture signals to show where RAG boundaries need reinforcement, without exposing raw documents or private payloads.
SecEng RAG Test Harness
Boundary planning and testcase generation
The same fixture now drives a compact boundary lens in Chrome and a fuller planning view in the editor, so the public demo stays close to the actual product flow.
SecEng RAG Test Harness
RAG Boundary Lens
Boundary planning, testcase generation, and evidence classification rendered from the same public-safe trace fixture.
classifyRagEvidence
Evidence scorecard
AuthZ pass
Retrieval gates are mostly aligned.
Context leaks
No leak-shaped signals surfaced.
Policy violations
Policy language needs stronger enforcement.
Poisoned chunks
No poisoned chunk patterns detected.
PII / secret hits
Redaction surfaced one or more hits.
Source provenance
Source attribution and retrieval lineage need follow-up.
Missing boundaries
What still needs to be enforced
Top 3 tests
Highest-priority harness checks
Pipeline map
planRagBoundaries → generateRagTestcases → classifyRagEvidence
Suggested tests
Controls found
Affected paths
The lens is public-safe and directional. It uses job-description intelligence and trace fixture signals to show where RAG boundaries need reinforcement, without exposing raw documents or private payloads.
Comparison snapshot
What changed in this fixture
New prompts
New tools
Operating controls