Pipeline
MCP exposes the same stages as tools (see MCP):
Core pieces
Runtime behavior
- Missing external tools are skipped, not treated as fatal errors
- Auth headers set once can carry through httpx, katana, ffuf, nuclei, dalfox when configured
- Active MCP tools require an allowlisted scope and approval
- Discovered hosts are not automatically authorized
- Report tools draft locally — they do not auto-submit