Finding
A vulnerability the autonomous pentest already proved with a working exploit is mapped back to the exact source file(s) that govern it.
Most autonomous pentesters stop at the finding. Darkmoon's Pro remediation engine turns each one into an AI remediation pull request, and we published the honest score: 42 of 57 findings fixed and retested end-to-end on OWASP Juice Shop.
The same four steps run on every finding. A fix only counts toward the 42 when the original exploit is re-run against a live instance and confirmed closed.
A vulnerability the autonomous pentest already proved with a working exploit is mapped back to the exact source file(s) that govern it.
The remediation agent generates a minimal, root-cause patch against the real Juice Shop code, not a suppression or a config toggle.
The branch is type-checked with tsc, then the original exploit is re-run against a live instance. The finding must be confirmed closed.
A pull request is opened for a human to review. It is AI-generated code, disclosed as such, and never auto-merged.
42 is the number that survives a clean runtime retest. The other 15 are disclosed here rather than folded into a bigger headline.
Close a narrower exploit at runtime but are partial or architectural relative to the full finding.
Did not close the exploit on retest. The fix is ineffective and is flagged honestly.
Verbose errors: changes behaviour only under NODE_ENV=production, so it was not runtime-retested.
#44, #46, #18/#39, frontend or static-asset changes not exercised by the API-level retest harness.
57 findings − 42 demonstrated = 15 disclosed above.
Five checks, in order, on every one of the 57 pull requests. Everything needed to repeat them is published.
tsc (24 distinct backend branches, all exit 0).main then re-run against the fix branch on a live v19.2.1 instance.The retest harness, the per-PR verdict matrix and the exact reproduction environment are all published.
These PRs are an internal demonstration of the remediation engine on our own fork, not upstream contributions.
The target is a standalone MIT copy of OWASP Juice Shop v19.2.1.
One finding walked from exploit to green retest, on the interactive walkthrough.
It is not a third-party certification or an analyst endorsement. Every number above is drawn from the published dossier and can be reproduced or contested.
Darkmoon is open source (GPL-3.0) and self hosted. The offensive engine is free; the remediation engine is a Pro capability.