The red team, reasoning from the source
.
Vulkro Red is the red team on the same engine as the reviews. It takes what Vulkro and Vulkro for Salesforce found and works out which problems chain into a break-in, stage by stage, reading only the code on the disk. It never sends a request, never touches a live system, and every stage cites a file and a line.
- 01reconsrc/routes/index.ts:31
- 02initial accesssrc/routes/invoice.ts:47
- 03protection bypasssrc/app.ts:88
- 04injectionsrc/db/invoice.repo.ts:126
- 05broken accesssrc/services/invoice.service.ts:212
- 06exfiltrationsrc/serializers/invoice.ts:64lands the damage
Reasoned from the code on the disk. No request is sent, no live system is touched, and no stage is ever marked confirmed.
The stages_
The chain in the hero, written out. Every stage names the file and the line the review read it from, and nothing on this path was executed.
Recon
214 routes inventoried from the router table, 18 with no guardsrc/routes/index.ts:31
Initial access
Invoice read route is reachable without a sessionsrc/routes/invoice.ts:47
Protection bypass
requireAuth is mounted after the invoice router, so it never runssrc/app.ts:88
Injection
Path parameter reaches the query builder without a bound parametersrc/db/invoice.repo.ts:126
Broken access
Lookup carries no owner or tenant predicate, so any id resolvessrc/services/invoice.service.ts:212
Exfiltration
Serializer returns 12 customer fields, including billing addresssrc/serializers/invoice.ts:64
The gap_
A list of problems tells you what is wrong. An ordered chain tells you what happens next.
Severity is per problem
A review ranks each problem on its own: how bad it would be if it is real. That is the right question for fixing, and the wrong one for deciding what an attacker does next.
Risk is per path
A medium problem that opens the door for a high one is worse than either alone. Vulkro Red orders what the reviews found into the route an attacker would take, stage by stage.
Every stage is cited
Each stage names the file and the line the engine actually read, or it is not printed. There is no stage that exists only in a model's imagination.
The scope_
The same reading covers the code you wrote, the code you installed, and the org you deployed into.
Supply chain
Code you never read runs on every machine that installs your product. Hostile package families, hijacked releases and install-time scripts are placed on the chain where they actually enter.
Salesforce
Two half-problems make one path: an Apex query that trusts its caller, and an org setting that lets a guest be that caller. Vulkro Red joins the source review to the live-org posture.
Nothing to authorise
Nothing is attacked. No request is sent, no server is touched, no exploit is run. There is no engagement letter to sign because there is no engagement, only a reading of the code on disk.
How a chain is built_
Corroboration, not labels. A chain is printed only when the review's own map backs every stage, and it is never called confirmed, because nothing was run.
One signal is not a chain
A high severity is one signal. A chain needs corroboration: an entry point that reaches the code, a path the data can travel, and a place it does damage, each backed by the map the review built.
There is no proven-exploit tier
Nothing is executed, so nothing can be confirmed. The ceiling is a strongly grounded static path, and the report says so on every chain rather than dressing a guess as a result.
The model narrates, the engine decides
A local model on your machine writes the story of a chain at temperature zero. Every claim it makes is checked against the call graph, the endpoint inventory and reachability before it can appear.
- 01recon214 routes inventoried from the router table, 18 with no guard
src/routes/index.ts:31VULK-0311 - 02initial accessInvoice read route is reachable without a session
src/routes/invoice.ts:47VULK-1042CWE-306 - 03protection bypassrequireAuth is mounted after the invoice router, so it never runs
src/app.ts:88VULK-1180CWE-284
- +30route resolved from the framework router table
- +24guard absent on this path (checked at src/app.ts:88)
- +18sink reaches a column set tagged as customer data
- +12every stage cites a parsed file and line
- -6no runtime evidence: nothing was executed
noteStatic analysis. No request was sent and no exploit was executed.
The constraints get the same treatment as the results: named, with the reason, before you find them.
what the review reads
- source
- configuration
- lockfiles
- Runtime behaviournothing is executed
- Business logicno specification to compare the code against
- Dynamic dispatchno value to follow when a call is built at runtime
- Exploitability as deployednetwork position is not in the code
- Unsupported languagesno grammar loaded, so no parse tree to walk
- 01recon214 routes inventoried from the router table, 18 with no guard
src/routes/index.ts:31VULK-0311 - 02initial accessInvoice read route is reachable without a session
src/routes/invoice.ts:47VULK-1042CWE-306 - 03protection bypassrequireAuth is mounted after the invoice router, so it never runs
src/app.ts:88VULK-1180CWE-284
- +30route resolved from the framework router table
- +24guard absent on this path (checked at src/app.ts:88)
- +18sink reaches a column set tagged as customer data
- +12every stage cites a parsed file and line
- -6no runtime evidence: nothing was executed
noteStatic analysis. No request was sent and no exploit was executed.
Start with the review.
Run the review on your own code today: it runs on your machine, nothing is uploaded, and your first sign-in starts a 14-day trial of the full product.
Vulkro Red works from what Vulkro and Vulkro for Salesforce found.
