New --research mode for whitebox/greybox (REPL /research, web 🔬 checkbox, or
auto-detected from natural-language focus/objective in PT/EN). Steers the source
review to find a NOVEL, CVE-reportable issue instead of a known one:
- WHITEBOX_RESEARCH_DOCTRINE: pin version/commit; research known CVEs/advisories
(SECURITY.md, CHANGELOG, GHSA, NVD, git history) to de-duplicate; patch-diff /
n-day->0-day variant analysis (incomplete fixes, bypasses of a new check,
sibling sinks, reintroductions); strict novelty gate (each finding states
novel-why + checked-against); benign PoC + dynamic confirm on greybox.
- RunConfig.research + is_research_intent(); injected in run_whitebox and the
greybox code-review half.
- 6 research skills (code/): known_cve_dedup, patch_diff_variant,
attack_surface_map, source_to_sink_taint, logic_authz_flaw,
dependency_nday_reachability.
- Methodology modeled on a real AppSec-research workflow (no specifics copied).
479 agents, 421 tests.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Task-based model ROUTER (recon/select prefer a fast model; exploit prefers primary; validate uses a different model than the finder)
- ReAct doctrine injected into exploit prompts (Thought→Action→Observation, token-efficient)
- Dedup: unique agents per run + findings deduped by CWE/endpoint/title (highest confidence kept)
- Token economy: recon blob capped for selector + per-agent context
- Configurable MCP: merge user mcp.servers.json into the pipeline's .mcp.json
- +54 white-box/code-analysis agents (NoSQLi, LDAP/XPath, JWT-none, Java/.NET/PHP/Go/Node/Python
specifics, SSTI, ReDoS, deserialization, etc.) → 303 agents total (78 code)
- Credits: Joas A Santos & Red Team Leaders (CLI banner, interactive header, HTML+Typst report)
- README: GitHub stars/forks badges, 60-second quick start, full API config steps, intuitive layout
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>