A set of rules for carrying out authorized black-box penetration tests, where the tester examines a system without access to its source code. It defines testing boundaries, safety limits, and the evidence needed to report a vulnerability.
A specialized sub-agent for authorized black-box penetration testing that investigates inputs blocked by a web application firewall, keyword filter, or input validation. It tries groups of bypass approaches and records reproducible evidence when they work.
A reconnaissance sub-agent for authorized black-box security testing that gathers public information about a target and identifies exposed assets and endpoints. OSINT means information collected from publicly available sources such as certificate logs, GitHub, or public API collections.
A delegated agent for black-box penetration testing of up to five assigned URLs, checking endpoints independently and recording results in the project state.
A security-audit guide for Electron desktop applications, which are desktop programs built with web technologies. It focuses on vulnerabilities that ordinary users can trigger through projects, files, links, or other normal actions.