Example: Blackbox scan, one domain
User: "Scan https://example.com for vulnerabilities."
Tool-call blueprint
- Ask operator for scope confirmation and out-of-scope paths (if ambiguous).
Bash→ parallel recon (seeworkflows/blackbox_single_domain.mdstep 2).- Playwright MCP → launch context, navigate, BFS-crawl, emit
crawl/endpoints.jsonl. - For each injection class (XSS, SQLi, SSRF, path traversal, CRLF), iterate
payloads/*.txtagainst discovered inputs. Bash→nuclei -l endpoints.txt ...for CVE/misconfig overlay.- Manually re-verify Critical/High.
Write→results/example.com/output.jsonconforming toschemas/finding.json.
Minimal state-tracking
results/example.com/
crawl/endpoints.jsonl # from Playwright
crawl/forms.jsonl
recon/nmap.txt
recon/nuclei-root.jsonl
output.json # finalReport back to operator
- Count by severity.
- Top 3 risks with one-line description each.
- Path to
output.html.
Do not paste every finding inline; link to the structured output.