It found a 0day exploit in the sandbox's package proxy (almost certainly Artifactory). Without source code access which is very impressive.