pentest gforge loom ai-gateway genai appsec

GForge — Evidence Log

Chronological working notebook for the GForge / Loom engagement. Record observations here during testing; promote validated issues to GForge - Findings.

Important

Always record the exact model, build, environment, and identity context. AI behavior varies across models and builds, so an observation without that context is not reproducible.


Entry Format

## YYYY-MM-DD
 
### Observation Title
- **Category:** AuthN / AuthZ / Gateway routing / GenAI / Secrets / Output handling / Resource / Environment
- **Environment / build:**
- **Identity / role:**
- **Endpoint / function:**
- **Model / provider:**
- **Action:**
- **Result:**
- **Expected (if known):**
- **Evidence:** (Burp item, sanitized request/response, screenshot, log reference)
- **Related test case:** [[GForge - Test Cases#...]]
- **Related finding:** [[GForge - Findings#...]]
- **Status:** Observation / Needs retest / Promoted to candidate finding

Observation Categories

Use these to keep the log skimmable during testing.

CategoryRecords
BaselineNormal flows captured for comparison
AuthNOkta / PKCE / token behavior
AuthZObject and function access across identities
Gateway routingModel / provider / route policy behavior
GenAIPrompt interaction, system-context handling
Output handlingRendering of model output in Loom
SecretsSecret / token exposure checks
ResourceVolume, size, concurrency, cost behavior
EnvironmentStaging vs production parity observations

Baseline Records

Capture before negative testing. Reference: GForge - Endpoint Inventory > Baseline Flows to Capture.

FlowCapturedEnvironmentIdentityNotes
Okta / PKCE login[ ]
Chat creation[ ]
Model request / response[ ]
Streaming behavior[ ]
Chat history[ ]
Projects[ ]
Logout[ ]
Error flow[ ]

Log

No entries yet. Testing targeted to begin week of Sep. 14 — see GForge - Overview > Engagement Timeline.