Find what breaks before someone else does.
Cyberful guides an AI coding agent through authorized penetration tests, code audits, and bug bounty programs—from a precise scope to findings an independent verifier can reproduce.
Start with the job in front of you
No internal architecture knowledge required.
Check the requirements
Prepare Docker, disk space, and one supported agent provider.
02Install Cyberful
Install the packaged CLI or launch a source checkout for development.
03Run an authorized test
Define exact targets and constraints, then follow the phase-by-phase run.
04Choose the right workflow
Match pentest, bug bounty, or code audit to the evidence you need.
One disciplined path from scope to report
See the execution model →Authorization is part of the system boundary. Use Cyberful only on systems you own or are explicitly authorized to test. Workareas, evidence, reports, browser profiles, and scanner state may contain sensitive data and must not be committed.
Go deeper¶
- Use Cyberful for the terminal, sessions, evidence, reports, and agent providers.
- Understand the system for phases, isolation, handoffs, and safety boundaries.
- Operate the security tools for cyberful-os, the browser, OWASP ZAP, Ghidra, and the EVM lab.
- Build with us for contributor workflows, testing, and releases.