What problem does it solve?
Hunting for high-impact but less “obvious” vulnerability classes (misc access control failures, token/scope issues, invitation and SSO logic bugs, and misconfiguration-driven auth failures) is slow and often gets stuck on incomplete validation.
Core Features & Use Cases
- Role and permission boundary validation to confirm privilege differences with response-body differentials and concrete repro steps.
- Token, invitation, and post-removal access testing to detect stale sessions, multi-use tokens, and authorization gaps across user lifecycle events.
- Integration and config-driven vulnerability probing for SSRF/token exfil paths, header injection surfaces, SSO parsing weaknesses, and package-registry misconfigurations.
Quick Start
Ask the AI to hunt for misc vulnerabilities on https://target.example, focusing on invitation, token scope, SSO/callback logic, and cross-tenant access with a reproducible report.