Use ProjectDiscovery dnsx for authorized, small-batch DNS resolution, record lookup, and hostname validation at conservative rates.
Use ProjectDiscovery httpx for authorized, low-rate HTTP availability checks, response triage, and lightweight technology signals.
Use jadx for authorized Android APK, DEX, AAR, and JAR decompilation, app logic review, endpoint discovery, embedded-secret review, and mobile reverse engineering.
Use nmap for authorized, targeted port checks, lightweight service detection, and local network diagnostics at conservative rates.
Use when a task requires shell-level work inside the sandbox, including environment setup, script writing, code execution, preinstalled programs, bounded network diagnostics, or browser/tool CLIs.
Use uv for missing Python dependencies, task-scoped virtual environments, temporary execution, and non-preinstalled Python tools.
Use agent-browser-cli to perceive and control the supervised Chrome browser inside the sandbox, interact with pages, capture screenshots/PDFs, inspect cookies/CDP/network/console state, and troubleshoot only when needed.
Use apktool for authorized Android APK resource decoding, manifest review, smali inspection, rebuild checks, and static mobile artifact triage.