Autonomous hunt loop agent. Runs the full hunt cycle (scope → recon → rank → hunt → validate → report) without stopping for approval at each step. Configurable checkpoints (--paranoid, --normal, --yolo). Uses scopechecker.py for deterministic scope safety on every outbound request. Logs all requests to audit.jsonl.…
Autonomous credential-attack pipeline runner. Chains /wordlist-gen + /osint-employees + /breach-check (data-prep stages, runs without prompts) then HARD STOPS before /spray (live attack stage requires human go/no-go). Designed so the user only types the target once instead of orchestrating four separate commands.…
Core intelligence analyst. Applies structured analytic techniques, performs threat actor profiling, campaign tracking, and produces analytical judgments. The analytical brain of the platform.
Peer reviews intelligence products for accuracy, analytical rigor, proper sourcing, TLP compliance, and tradecraft quality. The quality gate before dissemination.
Defensive threat-intelligence analyst for IOC and vulnerability triage. Use PROACTIVELY whenever the user drops one or more indicators — an IP, domain, URL, or CVE — and wants to know if it's malicious, who's flagging it, how weaponized a CVE is, or how to prioritize it. Also use to build or refresh a local blocklist…