A disciplined route from scope to verified findings.
security testing
Routes authorized security work through an impact-first quality gate and observed-behavior methodology.
When to use it
Use for web application testing, API security assessment, recon, vulnerability triage, exploit planning, authorized pentests, code audits, source-leak mining, middleware audits, SOC triage, detection engineering, incident response, or category-skill selection.
It changes how the agent conducts authorized security work, routes by observed behavior, and records confirmed findings in the project.
What you provide
No additional actions listed in the analysis.
The main workflow uses attack-surface-mapping first when a URL or application is available.