Back to Services
AI Security Toolkit V4

19 checks we wrote,
plus 15 open-source scanners

Semgrep, Trivy, Nuclei, sqlmap and gitleaks are among the sensors, alongside 19 checks we wrote ourselves for what off-the-shelf tools skip. 17 specialist agents coordinate them in an 8-phase pipeline, then cross-pollinate findings to build attack chains no single tool would catch. Against a public vulnerable-by-design benchmark it built six working attack chains, where Burp Pro built none.

Request Security Assessment
17 AI Agents
15 Open-source scanners
8 Phase Pipeline
8 Security Pillars
ai-security-scan-v4
$ /ai-security-scan-v4 --repo github.com/client/webapp
[V4] Initializing 17 specialist agents...
[SURFACE] 23 endpoints, 4 auth flows, 2 file uploads
[SAST] Semgrep + Bearer: 3 findings in 847 files
[SCA] CVE-2024-3241 (jsonwebtoken 8.5.1) HIGH
[DAST] Nuclei + sqlmap probing 23 endpoints...
[AGENT:auth-bypass] Session fixation in /api/oauth/call
[CHAIN] SCA CVE + DAST endpoint = token forge → admin
[AUDIT] Coverage map: 12 WSTG categories, 3 gaps flagged
[REPORT] 8 phases complete → 14 findings, 2 attack chains
Section 01

Specialist agents

Each agent focuses on a specific attack class. They run in parallel, share findings, and build multi-step attack chains that individual tools would never detect.

CLAUDE
AuthZ
SAST
BaaS Posture
SCA
Chains
Secrets
Coverage
Protocol
Cross-Poll
Auth Bypass
DAST
Client DOM
Exploit
Injection
Gap Filler
Prompt Inj
Silent Fail
AuthZ Specialist
IDOR, privilege escalation, multi-tenancy, and broken object-level authorization.
SAST
Static analysis of source with Semgrep, Bandit, gosec and njsscan.
BaaS Posture
Read-only Supabase and PostgREST checks: anon-readable tables and exposed policies.
SCA
Dependency and container scanning with Trivy, Syft and pip-audit.
Chain Constructor
Correlates single findings into multi-step exploitation chains.
Secrets
Credential detection across the tree and its history with Gitleaks and TruffleHog.
Coverage Auditor
Audits the enumerated attack surface for untested endpoints.
Protocol Analyst
Inspects headers, cookies, CORS and TLS configuration for weak transport rules.
Cross-Pollinator
Feeds one agent's findings to another so a single signal reaches every specialist.
Auth Bypass
Attempts authentication bypass: session handling, token forgery and forced browsing.
DAST Orchestrator
Drives Nuclei, sqlmap, ffuf and Wapiti against the running target.
Client-Side DOM
Finds DOM XSS, unsafe sinks and client-side routing flaws in shipped JavaScript.
Exploit Confirmer
Reproduces findings with concrete proof to eliminate false positives.
Injection Chains
Chains injection primitives across parameters to reach a working payload.
Gap Filler
Runs focused probes against the coverage gaps the auditor reported.
Prompt Injection
Tests LLM endpoints for jailbreaks, injection, and data disclosure.
Silent Failure
Finds 200-OK-with-degraded-status responses and swallowed errors.

Two more run only when they apply: Mobile Security on an APK or IPA target, and SOC2 Compliance when a SOC2 report is requested. That is 19 agents on a scan that needs both.

Section 02

What Makes This Different

Capability Description Example
SPEC-01
Cross-Pollination
When one agent finds something, it tells related agents to focus there. SCA finds vulnerable JWT library → DAST agent targets auth endpoints using that library. SCA CVE → DAST focus
SPEC-02
Attack Chains
Individual findings are medium severity. Combined, they're critical. The toolkit links SCA + DAST + Auth findings into full exploitation paths. On the public benchmark it found 6 attack chains; Burp Pro found 0. JWT vuln + /api/refresh → admin
SPEC-03
Coverage Audit
Every scan maps findings to OWASP Top 10 categories. If any category has zero coverage, gap-fill scans run before the final report. Gap: SSRF → run nuclei ssrf
SPEC-04
Human Review
AI finds and correlates. Humans verify and prioritize. Every critical finding is manually validated before it appears in your report. AI: 14 findings → Human: 9 valid
Section 03

How a scan runs

1
Surface
Map attack surface: endpoints, auth, uploads
2
Parallel
Agents run concurrently
3
Cross-Pollinate
Share findings between agents
4
Chain
Build multi-step attack paths
5
Coverage
Check OWASP Top 10 coverage
6
Gap-Fill
Target zero-coverage areas
7
Verify
Confirm evidence before it reaches the report
8
Report
Human-reviewed findings
Section 04

15 open-source scanners

SAST
Semgrep Bandit njsscan Bearer gosec
SCA
Trivy Syft pip-audit Safety npm-audit
DAST
testssl Nuclei sqlmap Wapiti ffuf XSStrike Dalfox
Secrets
gitleaks trufflehog detect-secrets
IaC
Checkov tfsec kics
Cloud
Prowler Kubescape ScoutSuite
Custom
dom-scanner.js oob-detector.sh param-fuzzer.sh chain-builder.py
Proof

See it in action

We ran BetterQA against a public vulnerable-by-design benchmark application, the same target Escape used to compare DAST scanners. We came away with 27 findings, 6 attack chains, and credentials the other scanners missed.

Read the benchmark

Ready for a security assessment?

Get a comprehensive security scan with attack chain analysis and OWASP coverage audit.

Request Assessment