Wild West API

Write a pentest finding and remediation section

The testing is done and the report is due. Each finding needs a title, description, evidence, impact, severity and fix, written clearly enough for both the developer and the manager. Apex Flash can draft that section from your notes. The facts must come from you.

Set it up

  1. Collect your notes for one finding: affected endpoint, steps taken, evidence, and the scope document reference.
  2. Redact credentials, tokens and personal data from the evidence.
  3. Send the notes to apex-flash with the finding template prompt.
  4. Check every factual statement against your evidence.
  5. Assign the severity yourself, using your agreed method.
  6. Paste the cleaned text into the report template and have a colleague review it.

Authorisation boundary

This workflow is for work done under a signed scope of work or rules of engagement, or against your own systems. The report describes what you did inside that scope; it should never be used to describe testing outside it.

Sanitised sample input

Engagement: ACME portal, scope doc SOW-2026-14, test window 5-9 Oct.
Finding: Invoice API returns other customers' invoices.
Request: GET /api/invoices/10042 with customer A session returned an invoice
belonging to customer B. Changing the id returned further records.
Observed: 3 distinct customers' invoices (names redacted).
Not tested: write operations.

The prompt and the call

Give the model a fixed structure and forbid it from adding facts. For ratings, name your scale. CVSS v3.1 bands are Low 0.1 to 3.9, Medium 4.0 to 6.9, High 7.0 to 8.9 and Critical 9.0 to 10.0 (FIRST).

Write one pentest finding from my notes, for a client report.
Sections: Title, Summary (2 sentences), Affected asset, Description, Evidence (list only what is in my notes), Impact (what an attacker could do, based only on the evidence), Likelihood, Remediation (specific steps in priority order), References (OWASP category).
Rules: do not add technical facts that are not in my notes. Use "TODO: confirm" where information is missing. Do not state a CVSS score; I will compute it. Plain, direct language.

<notes>
...your notes...
</notes>
import os
from openai import OpenAI

client = OpenAI(base_url="https://wildwestapi.com/v1",
                api_key=os.environ["WILDWEST_API_KEY"])

resp = client.chat.completions.create(
    model="apex-flash",
    temperature=0.2,
    messages=[
        {"role": "system", "content": "You help pentesters write accurate, clear findings."},
        {"role": "user", "content": open("finding_prompt.txt", encoding="utf-8").read()},
    ],
)
print(resp.choices[0].message.content)

Keys look like sk-ww-...; keep yours in the WILDWEST_API_KEY environment variable, never in the script. Calls to /v1/chat/completions use the OpenAI format, billing is pay-as-you-go, and prompts are not retained on /v1.

What good looks like

For this example, a sound draft names the issue as broken object-level authorisation, an access control failure that fits OWASP A01:2021 Broken Access Control. Remediation should say: check on the server that the invoice belongs to the authenticated customer on every request, use unpredictable identifiers as defence in depth, and add automated tests for cross-account access. Impact should stay inside the evidence: confidential invoice data of other customers was readable.

What to check

  • Every number and name in the draft appears in your notes. Delete anything else.
  • Impact is not inflated. "Full account takeover" is wrong if you only read invoices.
  • Remediation matches the client's stack. Add framework specifics yourself or give them in the prompt.
  • Severity is yours. Ask the model for a rationale if you want a second opinion, then decide.

Both apex-flash and glm-5.3-flash-cyber are security-tuned models with a 1M-token context window, tool calling and vision. They are not uncensored models, and they are meant for defensive and authorised work like this. It writes fluently, which makes errors easy to miss; read as the client's developer would.

Where this fits

Start from deduplicated scanner results and pair with a code review when you have source. See penetration testing use cases and red team tools for testing tools in scope.

FAQ

Can it write the whole report?

It can draft sections, but you own accuracy. Executive summaries and findings need your review against evidence.

Should I send client data to the API?

Redact credentials and personal data. Prompts are not retained on /v1, but your contract may still limit what leaves your environment.

Will it pick the CVSS score?

Leave scoring to you with the official calculator. The model can explain the metrics but should not be the source of the number.

Related

Uncensored AI models on one key

OpenAI and Anthropic compatible, pay as you go. New to it? Start with uncensored AI, explained.