Most scanners flag anything suspicious and leave you to sort out what's real. Mugiwara proves it instead. It generates a proof-of-concept exploit, runs it in an isolated container, and only marks a finding verified if the attack actually works. For verified issues, an AI patches a disposable copy and we re-run the same exploit to confirm it's blocked. Everything runs locally-your code never leaves your machine. V0: injection classes in Python. Feedback welcome, especially on false positives.