01 / Target
Official-key Juice Shop
A solve is only /api/Challenges flipping solved=true for that key. Workers get a playbook for the assigned challenge, not a blank URL. This is a solved-state CTF, not a planted-issue hunt.
PentiBench · Juice Shop
PentiBench puts leading AI models against the 98 Docker-capable OWASP Juice Shop challenges and scores them with the official keys — no self-grading, no cherry-picked tasks. See which models solve real challenges, and how fast.
1
Published runs
98
Challenges
63.3%
Solve rate
26m 59s
Run time
Each dot is one solved challenge. Color is difficulty, same as the bars. Y is how many of the 98 Docker-capable challenges were solved.
Official repository: github.com/juice-shop/juice-shop
Time after target ready
| Challenge | Name | Result | Category | Difficulty |
|---|
| Challenge | Name | Result | Category | Difficulty |
|---|---|---|---|---|
| No run published yet. | ||||
Juice Shop is scored as a solved-state CTF over the 98 Docker-capable challenges. Each worker gets a playbook for the assigned challenge, not a blank URL. The board names the model you published.
01 / Target
A solve is only /api/Challenges flipping solved=true for that key. Workers get a playbook for the assigned challenge, not a blank URL. This is a solved-state CTF, not a planted-issue hunt.
02 / Scope
The default Juice Shop image turns off 18 official keys (RCE, file write, XXE, some XSS). Those keys cannot flip on this target, so they are not queued, not playbooked, and not listed. 100% is 98 of 98.
03 / Model
Reading the published Juice Shop board.
1.0