Skip to content
BreachPilot

Architecture

One pipeline, fully instrumented

Operator-supervised assessment engine: a policy-gated agent loop over a target-locked MCP tool layer, with evidence-backed verification and reporting. For authorized testing only.

Authorized testing only — every action is allowlist-gated and audited.

Runtime pipeline

attack plan · dag ready running blocked
  1. Operatorapproves gated
  2. PlannerAttackPlan DAG
  3. AgentFlow A loop
  4. MCP Tools153 · 33 fam.
  5. Sandboxallowlist-locked
  6. EvidenceCONF / REFUTED
  7. Verificationoracle · score
  8. Reportmd · html · MITRE

operator → planner → agent → mcp tools → sandbox → evidence → verification → report

Main path — one supervised run

  1. Operator

    Starts runs, approves gated actions. The only authority.

  2. Planner

    Resolves goals, gates SAFE / GATED / HIGH, builds the AttackPlan DAG.

  3. Agent

    Flow A loop: hypothesize → execute → validate. Policy-gated.

  4. MCP Tool Layer

    153 tools / 33 families — @audit_tool + @require_allowlist.

  5. Sandbox

    Disposable worker, target-IP lock, fail-closed DROP.

  6. Evidence

    Execution vs evidential outcome — OutcomeJudge.

  7. Verification

    Validation scoring: CONFIRMED / REFUTED / EXHAUSTED.

  8. Report

    Markdown/HTML, MITRE export, SHA-256 audit chain.

Alongside — every run

Swarm Orchestrator

Six specialists on a shared blackboard.

Autonomous Orchestrator

Persistent campaigns with resume.

Skills + Memory

139 advisory skills, semantic + experience memory.

Provider layer

Ollama / Ollama Cloud · OpenCode Go · ChatGPT behind one contract.