What BrassCoders Catches in OWASP PyGoat
A real scan of OWASP's intentionally-vulnerable PyGoat app: BrassCoders now catches all 11 documented findings, including 4 gaps closed since the May baseline.

Search for a command to run...
A real scan of OWASP's intentionally-vulnerable PyGoat app: BrassCoders now catches all 11 documented findings, including 4 gaps closed since the May baseline.

Catastrophic backtracking turns one crafted input into a denial-of-service attack: real npm advisories and how to catch it before it ships.

OWASP ranks broken access control the top web risk and BOLA the top API risk. Real prevalence and attack data, and what BrassCoders can honestly flag.

PyYAML's yaml.load carried a CVSS 9.8 CVE. PyTorch's torch.load carried one at 9.3, in 2025, in a flag documented as safe. Here is the actual track record.

AI coding assistants can reproduce license-encumbered training data. Here is what the memorization research, GitHub's own data, and an active lawsuit say.

Wire a Claude Code hook to run brasscoders scan on every edit, so .brass/ai_instructions.yaml stays fresh and the assistant reads findings without copy-paste.

A 2025 benchmark puts LLM code-review recall at 0.78 to 0.88, yet the models mislocate findings and vary run to run — the numbers on why it's a weak gate.

BrassCoders closes the loop on AI-written bugs: scan for the finding, hand it to your assistant for a patch, then re-scan to confirm the fix deterministically.

BrassCoders ran a first-party probe: 96 package names a frontier AI model suggested for Python tasks, checked live against PyPI. 95 existed; 1 didn't.
