Authorized targets only. Confirm scope before any active testing.

1. Install

Optional scanners:

2. Choose a provider

Non-interactive example (Ollama, free + local):
Groq free-tier cloud:
Check what is active:

3. Recon → hunt → validate → report

Replace target.com with an in-scope asset you are allowed to test:
Interactive shell:
One-off provider override (option before the subcommand):

Claude Code path

If you use Claude Code instead of the standalone CLI:
Then use slash commands such as /recon, /hunt, /validate, and /report.