Architecture
One pipeline, fully instrumented
Operator-supervised assessment engine: a policy-gated agent loop over a target-locked MCP tool layer, with evidence-backed verification and reporting. For authorized testing only.
Authorized testing only — every action is allowlist-gated and audited.
Runtime pipeline
- Operatorapproves gated
- PlannerAttackPlan DAG
- AgentFlow A loop
- MCP Tools153 · 33 fam.
- Sandboxallowlist-locked
- EvidenceCONF / REFUTED
- Verificationoracle · score
- Reportmd · html · MITRE
operator → planner → agent → mcp tools → sandbox → evidence → verification → report
Main path — one supervised run
Operator
Starts runs, approves gated actions. The only authority.
Planner
Resolves goals, gates SAFE / GATED / HIGH, builds the AttackPlan DAG.
Agent
Flow A loop: hypothesize → execute → validate. Policy-gated.
MCP Tool Layer
153 tools / 33 families — @audit_tool + @require_allowlist.
Sandbox
Disposable worker, target-IP lock, fail-closed DROP.
Evidence
Execution vs evidential outcome — OutcomeJudge.
Verification
Validation scoring: CONFIRMED / REFUTED / EXHAUSTED.
Report
Markdown/HTML, MITRE export, SHA-256 audit chain.
Alongside — every run
Swarm Orchestrator
Six specialists on a shared blackboard.
Autonomous Orchestrator
Persistent campaigns with resume.
Skills + Memory
139 advisory skills, semantic + experience memory.
Provider layer
Ollama / Ollama Cloud · OpenCode Go · ChatGPT behind one contract.
Go deeper
Engineering depth: architecture · runtime flows · MCP wiring · sandbox