Kamet runs the tools, reads the raw output, and chooses what to do next: an autonomous pentesting agent operating on a real Kali box, Burp Suite, and a live browser, no human between steps.
Cloud, APIs, mobile apps, and AI endpoints ship every week, each one new ground to test. A pentest once or twice a year leaves long blind windows between reports, exactly when code changes most. Senior offensive testers are hard to hire and impossible to clone; manual depth doesn't scale to the surface.
Autonomy closes the gap between tests: continuous, deep testing on every asset in scope, on demand, without waiting for the next booking.
A long-running agent in a tool-calling loop. Runs commands on a real Kali box, reads raw output, and chooses the next action, no human between steps.
A headless state machine for the commercial workflow. Automates everything from inbound purchase-order email through scoping, QA, branded reporting, and CRM close-out.
API-first. Operated over a REST / WebSocket API and through Claude skills, no web UI, by design.
Repeats until the model stops, or hits a safety gate.
No human suggested this. The agent read the raw shell output and chose the next move itself.
An experiments.md log, capped at 30, keeps every attempt on the record.
A skeptic checkpoint fires at experiments 5, 15, and 25 to challenge thin evidence.
A stalled goal triggers a reset: re-read everything, research, retry.
Roles: Coordinator, Explore-executor, Exploit-executor, Skeptic, Finding-validator, Engagement-validator, each with an explicit context contract.
Finding-validator. Every candidate is actively refuted for false positives before it can reach a report.
CVSS · CWE · MITRE. Confirmed findings are scored with CVSS 3.1, mapped to CWE and MITRE ATT&CK.
Branded PDF. An executive and technical report, prioritized by exploitability.
A deterministic scoring formula, with confirmed-vs-inferred separation and remediation-SLA bucketing.
Seven edge detectors stitch findings into attack paths, emitted as JSON, DOT, and Markdown.
Recursive deletes, device writes, and fork bombs raise an explicit consent-required gate, even in auto-run mode.
Engagements exist only from inbound customer POs. Testing stays inside scope, nothing outside it.
Per-user toggles gate every tool, with live pause, resume, and clear-context controls throughout.
The full delivery pipeline runs with no live credentials; every outbound call previews what it would do first.
Point it at external web, API, and network targets, it recons, exploits, validates, and reports without babysitting.
Built for and benchmarked on CTF-style challenges, with HackTheBox integration.
Drop in an APK or IPA, get MASVS-mapped, CVSS-scored findings with working PoCs.
A HackerOne skill for report generation and platform-ready submissions.
OWASP LLM Top 10 coverage via the ai-threat-testing skill.
Lifecycle automation lets a small team deliver many engagements end to end.
Point the harness at one authorized target and set the rules of engagement.
Recon, exploit, validate, report, the harness runs the assessment end to end, unattended.
Come back to scored findings, working PoCs, and a remediation roadmap.
See Kamet run against an authorized test target. We'll follow up within one business day.
Your information stays confidential and is never shared with third parties.