Jane fights the engagement — she doesn't run a fixed scan
A bounded ReAct loop drives every mission: she reasons a move, picks one scope-gated weapon, observes what it hit, and presses the advantage — forming hypotheses, testing them under fire, and promoting only the proven ones to findings. A miss is kept as intel, never discarded.
Reason
Calls the shot — states a hypothesis and why the next strike is in-scope and safe.
Strike — gated
Fires one tool through the policy gate. Out-of-scope shots are refused, not sent.
Observe
Reads the captured exchange; the request/response is logged as evidence.
Hypothesize
Opens, confirms, or rules out a lead — dead-ends kept as intel.
Confirm the kill
Promotes a proven breach to a finding with a PoC, CVSS and counterevidence.
The offensive advances phase by phase — and only when the gate falls
Jane wages a real campaign, not a checklist. Each phase pulls its own framework playbooks and must breach a validation gate before the next front opens. Escalation into post-exploitation is authorized separately — a surface-only mission documents and holds the line.
Scout the ground
Enumerate endpoints, params and tech.
Find the weak point
Probe authn/z, injection, IDOR, SSRF.
Take the ground
Confirm the breach with reproducible evidence.
Press deeper — if authorized
Escalate within the granted depth.
The after-action
Findings + kill-chain coverage.
Watch the assault unfold, in real time
Operators command missions from a board and follow Jane live on the front: her reasoning trace, the hypothesis timeline, kills as they’re confirmed, and a coverage map of every position taken.
- severity
- Critical · CVSS 9.1
- endpoint
- /rest/products/search
- att&ck
- T1190 · Initial Access
- owasp
- A03:2021 — Injection
- status
- proposed → validated
exchange ex_7f21, ex_7f2a · poc.sh · counterevidence recorded
A signed armory of expert playbooks, drawn for the phase and the target
Jane never fights from nothing. She draws the right playbook for the active phase and the target in front of her — from an armory built independently from public sources and Ed25519-signed, so a tampered pack never makes it to the field.
Jane plugs into the stack you already fight with
She doesn’t just report — she acts through your tools: reading your source for white-box analysis, shipping the fix, sounding the alarm, and commanding the scanners you already trust. Every integration stays inside the same scope and audit log as the rest of the engagement.
Reads the source, ships the fix
Connect a repo and Jane can pull the code to run white-box analysis alongside the live attack (optional) — then open an auto-fix pull or merge request for a confirmed finding, patch and evidence attached, scoped to the repos you install her on.
Sounds the alarm in Slack
Point Jane at a channel and every confirmed kill, mission milestone and escalation lands where your team already lives — with the evidence attached and a jump straight into the war room. No dashboard-watching required.

Commands Burp — not just scans
Connect over Burp's MCP server and Jane drives the whole toolkit — Intruder, Repeater, the Proxy history and the sitemap, not only the REST scanner. Works with Burp Pro on your machine (via a no-ports connector) or a cloud/Enterprise deployment. Every target-touching call is scope-gated, and she replays and re-proves each lead with her own reproducible evidence before it ever counts as a finding.
GET /rest/products/search?q='+OR+1=1--
Host: app.acme.ioHTTP/1.1 500 Internal Server Error ↳ differential confirms injection
Built so an autonomous attacker can be trusted on a real target
A weapon this capable is only safe when it’s bounded and accountable. Jane is built around the scope you grant, the evidence she captures, and the identity of who gave the order.
Deny-by-default scope
Allowed hosts, ports, paths and methods are the front line. Every target-touching call is gated twice; an out-of-scope shot is refused before it leaves.
Proof of every kill
Findings carry replayable exchanges, a runnable PoC, a CVSS breakdown and counterevidence — cleared through a multi-gate validator before they confirm.
Chain of command
Authenticator MFA and passkeys, scoped API keys, and mission-scoped users — with an audit log of who gave the order, changed it, and read the results.
Give the order
Set a scope, authorize the campaign, and watch Jane go to war on it — live, evidence-backed, and inside the lines you drew.