[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-new-framework-scores-ai-pentest-tools-on-trust-not-just-hacks":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},7322,"new-framework-scores-ai-pentest-tools-on-trust-not-just-hacks","New Framework Scores AI Pentest Tools on Trust, Not Just Hacks","A new paper argues AI pentesting agents need audited trust properties, not just flag captures, and finds a real enforcement gap in one open-source tool.","A new arXiv paper argues AI penetration-testing agents are being graded on the wrong scorecard.\n\nThe researchers propose a framework of five assurance properties: evidence grounding, non-destructive claim reduction, computed severity, enforced authorization, and tamper-evident accountability, meant to determine whether an autonomous pentesting agent can be trusted in an authorized engagement, not just whether it captures a flag. They map existing systems, including PentestGPT, the Cochise reference harness, MAPTA, and the trajectory judge PentestJudge, against the framework and find a consistent assurance gap across all of them. They then study NeuroSploit, one existing open-source pentesting tool distinct from the Cochise harness, pinned to a specific commit, tracing its architecture and the complexity cost of its design. Running the paper's own deterministic authorization and audit acceptance tests against NeuroSploit turns up a real enforcement gap, which the authors score as partial on both properties.\n\nCapture-the-flag success is easy to game and says nothing about whether an autonomous hacking agent stayed inside its authorized scope or left an auditable trail. That distinction matters once these agents move from benchmarks to real client engagements, where a false-positive finding or an out-of-scope action carries legal and safety consequences, not just a lower score.\n\nThe authors call this an existence proof, not a leaderboard result: evidence that trustworthy autonomy is achievable, not proof that any current tool has actually achieved it.","[\"ai-security\",\"penetration-testing\",\"arxiv-research\",\"autonomous-agents\"]","2026-09-23T04:00:00.000Z","2026-09-23T07:28:19.215Z","2026-09-23T07:28:25.323Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"Remove the invented quote fragment 'not a rounding error' (not in the source and misattributed to the researchers), and fix the mischaracterization of NeuroSploit as 'the paper's own reference implementation' — the source describes it as one existing open-source tool the authors studied, distinct from the Cochise reference harness.","resolved","security",[32,33,34,35],"ai-security","penetration-testing","arxiv-research","autonomous-agents",[37],{"name":38,"url":39},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2609.22664",0,{"sections":42},[43,47,50,55,60,65,69,74,79,84,89,94,99,104],{"name":44,"slug":45,"count":46,"latest_published_at":18},"AI","ai",4265,{"name":48,"slug":30,"count":49,"latest_published_at":18},"Security",707,{"name":51,"slug":52,"count":53,"latest_published_at":54},"Policy","policy",369,"2026-09-23T02:13:52.000Z",{"name":56,"slug":57,"count":58,"latest_published_at":59},"Deals","deals",202,"2026-09-22T23:00:04.000Z",{"name":61,"slug":62,"count":63,"latest_published_at":64},"Hardware","hardware",168,"2026-09-22T23:56:03.000Z",{"name":66,"slug":67,"count":68,"latest_published_at":18},"Science","science",133,{"name":70,"slug":71,"count":72,"latest_published_at":73},"Consumer Tech","consumer-tech",110,"2026-09-22T20:00:00.000Z",{"name":75,"slug":76,"count":77,"latest_published_at":78},"Software","software",80,"2026-09-22T23:32:52.000Z",{"name":80,"slug":81,"count":82,"latest_published_at":83},"Dev Tools","dev-tools",79,"2026-09-22T22:21:13.000Z",{"name":85,"slug":86,"count":87,"latest_published_at":88},"Startups","startups",65,"2026-09-22T22:06:48.000Z",{"name":90,"slug":91,"count":92,"latest_published_at":93},"Gaming","gaming",45,"2026-09-22T15:35:06.000Z",{"name":95,"slug":96,"count":97,"latest_published_at":98},"General","general",43,"2026-09-21T23:48:56.000Z",{"name":100,"slug":101,"count":102,"latest_published_at":103},"Reviews","reviews",27,"2026-09-22T13:00:00.000Z",{"name":105,"slug":106,"count":107,"latest_published_at":108},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]