pentest gforge loom ai-gateway genai appsec
GForge — Evidence Log
Chronological working notebook for the GForge / Loom engagement. Record observations here during testing; promote validated issues to GForge - Findings.
Important
Always record the exact model, build, environment, and identity context. AI behavior varies across models and builds, so an observation without that context is not reproducible.
Entry Format
## YYYY-MM-DD
### Observation Title
- **Category:** AuthN / AuthZ / Gateway routing / GenAI / Secrets / Output handling / Resource / Environment
- **Environment / build:**
- **Identity / role:**
- **Endpoint / function:**
- **Model / provider:**
- **Action:**
- **Result:**
- **Expected (if known):**
- **Evidence:** (Burp item, sanitized request/response, screenshot, log reference)
- **Related test case:** [[GForge - Test Cases#...]]
- **Related finding:** [[GForge - Findings#...]]
- **Status:** Observation / Needs retest / Promoted to candidate findingObservation Categories
Use these to keep the log skimmable during testing.
| Category | Records |
|---|---|
| Baseline | Normal flows captured for comparison |
| AuthN | Okta / PKCE / token behavior |
| AuthZ | Object and function access across identities |
| Gateway routing | Model / provider / route policy behavior |
| GenAI | Prompt interaction, system-context handling |
| Output handling | Rendering of model output in Loom |
| Secrets | Secret / token exposure checks |
| Resource | Volume, size, concurrency, cost behavior |
| Environment | Staging vs production parity observations |
Baseline Records
Capture before negative testing. Reference: GForge - Endpoint Inventory > Baseline Flows to Capture.
| Flow | Captured | Environment | Identity | Notes |
|---|---|---|---|---|
| Okta / PKCE login | [ ] | |||
| Chat creation | [ ] | |||
| Model request / response | [ ] | |||
| Streaming behavior | [ ] | |||
| Chat history | [ ] | |||
| Projects | [ ] | |||
| Logout | [ ] | |||
| Error flow | [ ] |
Log
No entries yet. Testing targeted to begin week of Sep. 14 — see GForge - Overview > Engagement Timeline.