Cybersecurity
AvailabilityComing soonPut evidence behind the finding.
A product for defensive security review, triage, and remediation planning with human judgment in charge. Not yet available.
Work
From concern to reviewable finding.
Repository intake
- Repository
- example/web-app
- Scope
- apps/web, packages/auth
- Profile
- Defensive review
- Excluded
- Live targets, credentials
Unvalidated redirect target in login callback
MediumSummary
The callback forwards the `next` parameter without checking it against an allow-list.
Code evidence
42 const next = url.searchParams.get("next"); 43 return redirect(next);
Route context
GET /auth/callback
Review actions
- Reason
- Reachable from the public login flow
- Risk owner
- Platform team
- Review by
- Next release
Ask Ethen
Recommended fix
ProposalResolve `next` against an allow-list of relative paths before redirecting.
- return redirect(next); + return redirect(safeNext(next, ALLOWED_PATHS));
Safe validation status
Unit test proposed · not applied · awaiting human review
Console views recreated from the Sentinel workspace components with an example finding — not a capture of a real repository or vulnerability.
Defensive workflow
Six lanes, each with its record.
Defensive security engineering only: intake, scanning, triage, evidence and patch proposals. Sentinel is not yet available; the lanes show the designed workflow.
- 01
Intake
A repository enters review with its scope attached.
/sentinel/intake
- 02
Scans
Scan plans run as attempts that can be retried or cancelled.
/sentinel/scans
- 03
Findings
Each finding keeps its scope, severity notes and uncertainty.
/sentinel/findings
- 04
Evidence
The record behind the finding, per finding — never a bare verdict.
/sentinel/findings/[id]/evidence
- 05
Patch proposals
Proposed fixes stay proposals until people validate them.
/sentinel/patches
- 06
Reports
What was reviewed, what supports it, what remains open.
/sentinel/reports
Purpose
Make defensive review easier to inspect.
For security reviewers, engineers, and maintainers who need to connect a possible issue to its context and decide what to verify next.
Availability · not yet available
Review
Keep uncertainty visible.
Record what was reviewed, what supports each finding, and what remains unresolved where supported. Security-sensitive changes require human review. Sentinel does not guarantee vulnerability discovery or replace a security team.
Limitations, as the console states them
- No exploit execution
- No credential testing
- No live target scanning
- No patch application
Models
Handle sensitive context deliberately.
Model availability depends on configuration. Local review requires a supported runtime and an appropriate data path.
FAQ
What kind of security work is Sentinel for?
Defensive analysis, evidence organization, triage, and remediation planning. Offensive exploitation is outside this product positioning.
Does a review establish compliance?
Findings and review records support your team's decisions. They do not establish certification or compliance.
Explore the record behind the review.
Learn how evidence fits into Ethen. Sentinel is not yet available.