What problem does it solve? Security teams and developers need a disciplined, evidence-based way to test web applications they own for vulnerabilities, without producing unverified findings or accidentally attacking out-of-scope systems. ## Core Features & Use Cases - Phased Testing Workflow: Runs engagement setup, source pre-recon, live recon, vulnerability analysis, proof-based exploitation, and professional reporting in sequence. - Hard Guardrails: Enforces written authorization, scope allowlists, rate limiting, destructive-payload approval, and credential redaction before any active request is sent. - Proof-Based Findings: Requires reproducible witness payloads and bypass-set exhaustion before confirming or dismissing any vulnerability, with CVSS scoring only for verified L3/L4 findings. - Use Case: Point the agent at your staging application, confirm authorization, and receive a structured pentest report with verified SQLi, XSS, IDOR, or SSRF findings including reproduction curl commands and remediation guidance. ## Quick Start Ask the agent to pentest your staging web application at a given URL and confirm you own it when prompted for authorization.