What problem does it solve? Security testers and developers need a disciplined, evidence-based workflow for actively testing web applications they own or are authorized to assess, without drifting out of scope or reporting unverified findings. ## Core Features & Use Cases - Phased engagement workflow: Moves through engagement setup, source pre-recon, live recon, vulnerability analysis, proof-based exploitation, and reporting, with an authorization gate before any active scanning. - Scope and safety guardrails: Enforces a scope.txt allowlist, rate limiting, destructive-payload approval, and credential redaction so testing stays bounded and auditable. - Proof-based findings: Promotes candidates through L1-L4 verification levels with bypass exhaustion before false-positive dismissal, and generates a CVSS-scored report from templates. - Use Case: Point the agent at your staging application, confirm authorization, and receive a structured pentest report with reproducible request/response evidence for each confirmed vulnerability. ## Quick Start Ask the agent to pentest your staging application URL and reply 'authorized' when it presents the engagement confirmation prompt.