Plan and use user-consented local camera and microphone observations for an explicitly authorized physical target. Use when a capture can establish a bounded physical-state observation such as whether a test fixture changed state, an instrument reading changed, or equipment noise changed relatively.
Use when a network probe, DNS lookup, HTTP fetch, or nmap scan reports the target host or the internet is unreachable. Stops further probing and reports a target-readiness blocker with useful diagnostics.
Safely develop, verify, and document proof-of-concept exploits and payloads for authorized targets inside isolated Workspace Containers. Use when a Hypothesis is well-founded and the user has explicit authorization to test it, needs a minimal PoC, wants to verify impact, or needs to produce reproducible exploit Evidence for a report.
Turn a specific vulnerability, patch, CVE, Version Diff, or Changelog Claim into a proactive security exploration plan. Use when the user wants research angles, lateral target discovery, patch/CVE strategy, new surface discovery, or hypothesis generation from vulnerability intelligence.
Use when explicitly authorized lab traffic must be captured, searched, or exported from the project's mitmproxy-backed Docker lab recorder.
Passive, citation-grounded review of security-relevant specifications, protocols, standards, APIs, and implementations. Use when a reviewer must trace external preconditions and invariants into source code without treating a cited claim as proof of a vulnerability.
Scientific model and eval tuning loop for prompt/skill/system-prompt changes, model configuration, runtime options, and local/Ollama model sizing or environment variables. Use when tuning eval performance, comparing local or remote models, improving tool-use behavior, reducing timeouts/loops, or deciding whether an eval optimization is worth keeping.
Plan vulnerability research using conventional bug-hunting and pentest stage names, specialty playbooks, and a research-hypothesis-experiment loop. Use when designing a bug bounty workflow, selecting tools and strategies, building a decision tree, or turning a target/scope into a staged hunting plan.