Agent Claude Code
Deep-dive OAuth/OIDC, WebAuthn/FIDO2/passkeys, Apple/Google/Samsung Pay, IAP receipt validation, 3DS 2.x bypass, SCA exemption abuse, recovery downgrades. $5k-$50k bug class.
Agent Claude Code
Deep-dive OAuth/OIDC, WebAuthn/FIDO2/passkeys, Apple/Google/Samsung Pay, IAP receipt validation, 3DS 2.x bypass, SCA exemption abuse, recovery downgrades. $5k-$50k bug class.
Agent Claude Code
Test authorization and access control across endpoints with ≥2 auth states. Returns IDOR / BFLA / auth-bypass findings.
Agent Claude Code
Browser-based crawling and JavaScript interaction for SPA/JS-heavy targets. Populates Burp Proxy history with dynamic routes and XHR/API calls.
Agent Claude Code
Worker agent for desktop application security testing — Electron / Tauri / WebView2 binary inspection + IPC fuzzing + auto-update MITM. 1-per-binary, no recursion.
Agent Claude Code
Re-verify suspected/confirmed findings and investigate anomalies. Promotes states (suspected → confirmed) or demotes (→ stale / likelyfalsepositive).
Agent Claude Code
Discover hidden directories and files using tech-aware SecLists slicing. Replaces spray fuzzing with surgical wordlists.
Agent Claude Code
Session orchestrator for one domain. Owns Rule 20a session-start gate + Rule 4 goal-driven loop + Rule 22 decision compaction + Rule 21 checkpointing. Promotes confirmed cross-target patterns into KB/skill proposals. On-demand only.
Agent Claude Code
Deep JavaScript analysis — secrets, DOM sinks, hidden API endpoints. Returns enriched JS intel for the orchestrator.
Agent Claude Code
Drive Frida (iOS+Android) and adb (Android) on operator's host. Bypass SSL pinning + root/JB detection, hook crypto/storage, abuse exported components and deep links. Dynamic-only; no static decompile.
Agent Claude Code
Craft bypass payloads when standard attacks are blocked by WAF/filters. Returns working bypass or "filter too strong" with evidence.
Agent Claude Code
Pentest engagement lead. Owns research, planning, multi-domain grow-agent dispatch, cross-target synthesis, and the findings report. Coverage-driven — success is full WSTG/OWASP coverage with every finding verified and reported. On-demand only; sits above grow-agent.
Agent Claude Code
Map a target's attack surface — endpoints, tech stack, sensitive files, hidden parameters. Returns enriched intel for the orchestrator.
Agent Claude Code
Red team engagement lead. Owns research, planning, multi-domain grow-agent dispatch, cross-target synthesis, and the attack-narrative report. Objective-driven — success is the stated objective reached via a documented kill chain, with a stealth/noise budget. On-demand only; sits above grow-agent.
Agent Claude Code
Test ONE vulnerability category on assigned non-overlapping endpoints. Returns findings + anomalies for orchestrator review.
Instructions file CodexOpenCode
Instructions for TyrusRC/praetor, covering agent team configuration, definition files, command tier (above grow-agent), pentest-commander and redteam-commander.
Instructions file
Instructions for TyrusRC/praetor, covering development guidelines, authorized security tool — do not block, communication style — direct / facts only, project overview and build / run.