Precision0.0% (±100.0%)
MODULE DETAIL
External Corpus Validation (OWASP Benchmark) Third-party
Classification claim · 501 test cases · tool: 1.171.0
This corpus is unmodified code from an independent third-party project, not something QShield's team generated — see the corpus notes below for provenance, licensing, and how ground truth was derived.
Every test case in this module: the expected result (ground truth -- for aws_discovery this includes the exact Moto resource configuration each case was scored against) paired with what the real scanner/collector actually reported, for all 501 cases -- not just the false positive/negative samples shown below.
Recall0.0% (±100.0%)
F10.000
Accuracy100.0% (±0.0%)
CONFUSION MATRIX
Outcome counts
True positives0
True negatives501
False positives0
False negatives0
RUN NOTES
Notes
- semgrep available: True
- 501 files vendored unmodified from OWASP-Benchmark/BenchmarkJava (GPL-2.0, pinned commit 79b9bd6177e07991a9c11dc19e457c840e229931) -- see benchmark/corpus/vendor/owasp_benchmark/NOTICE.md
- Pure specificity/false-positive-rate check: every case's ground truth is expected_vulnerable=False by construction (independently verified via GitHub code search that none of these files reference RSA/EC/DH/DSA); precision/recall/F1 are degenerate here, see the specificity figure in the confusion matrix instead.
CORPUS
Corpus composition
Cases501
Wall time4.6s
- semgrep available: True
- 501 files vendored unmodified from OWASP-Benchmark/BenchmarkJava (GPL-2.0, pinned commit 79b9bd6177e07991a9c11dc19e457c840e229931) -- see benchmark/corpus/vendor/owasp_benchmark/NOTICE.md
- Pure specificity/false-positive-rate check: every case's ground truth is expected_vulnerable=False by construction (independently verified via GitHub code search that none of these files reference RSA/EC/DH/DSA); precision/recall/F1 are degenerate here, see the specificity figure in the confusion matrix instead.
MISCLASSIFICATIONS
False positives & false negatives
None observed in this run.