What problem does it solve?
It helps teams discover and validate externally visible Web security weaknesses such as information leaks, CORS/CSP misconfigurations, redirect abuse, cache deception, and header-based trust issues.
Core Features & Use Cases
- Perimeter attack surface enumeration: Systematically expands from high-level entry points into secondary/tertiary parameters, hidden inputs, actions, and linked URLs to avoid “first hit = done” gaps.
- Evidence-driven validation: Uses a forced HTTP发包 workflow to capture real request/response headers and bodies as proof, and prevents overclaiming without reproducible commands.
- OOB verification support: Provides DNS log based callbacks for SSRF/DNS rebinding style issues without direct output.
Quick Start
Tell your AI agent to run the misc-agent against your authorized target list by first building the 一级攻击面清单, then recursively testing related endpoints while generating evidence and回填到 workspace/findings/misc-agent.json.