TECHNICAL REPORT
Benchmarking the FireCompass Web App Pentesting Agent
The FireCompass agent solved 100 of 104 XBEN challenges on the first attempt (96.15%) and all 104 with bounded retries, black-box on the original benchmark, at roughly 19 minutes per challenge. The report discloses the full protocol and benchmarks what others omit: scope enforcement, safe payloads, and audit logging mapped to OWASP APTS
What’s Inside the Report?
- The agent solved 100 of 104 web-exploitation challenges on the first pass, and all 104 when four were retried under a bounded best-of-N policy, black-box on the original benchmark at roughly 19 minutes per challenge.
- The full evaluation protocol most reports leave out: Black-box access, original challenge descriptions, and a single fixed frontier model held identical across all 104 challenges, with first-attempt scoring reported separately from retries so the number can be checked, not just trusted.
- Safety and governance measured, not assumed: Scope enforcement, safe-payload constraints, and append-only audit logging mapped to the OWASP Autonomous Penetration Testing Standard, plus independent HackerOne validation at all-time rank 6 and April to June 2026 rank 2.
.
Trusted by Leading Enterprises Across Banking, Telecom, and Technology