Ledgerline is a fictional multi-tenant invoicing product: our own demo application, built with deliberate weaknesses so the whole method can be shown end to end without touching anyone's real system. Everything below is real output from an assessment run on 3 October 2026, condensed into the format you would receive. Nothing here is a customer finding.
Each of these was proven with real requests against a deployed copy of the application, using two real accounts where the issue is about who can see what. They lead the report because nothing about them is a guess.
none. The protected endpoint returned 200 for both the genuine and the forged token.s****t). A fresh token signed with it was accepted live: 200.LEDGERLINE-CANARY-SYSTEM-PROMPT-9d41, came back verbatim, along with an internal “admin override phrase”. A plain baseline question returned a normal answer.prompt-injection-verify-6d2bf37cb07cbf39 came back verbatim, twice.In this demo the assistant is a deterministic stand-in for a model, so results are reproducible. Against a real model the same checks run unchanged.
Found by static analysis and flagged independently by two engines from different vendors. Strong signal, but not exercised live, and labelled that way.
SYS_ADMIN (line 33).One engine saw these and nothing else confirmed them. They are reported, ranked last, and never presented as vulnerabilities.
The first assessment is on us: one repository, one report, no obligation.