Describe the target in a conversation andAI will help run scans and vulnerability analysis
Select project
Select role
Conversation mode
Human-machine collaboration approval
Current approver
Applies to the currently selected conversation; saved locally when none is selected and reused for new conversations. Takes effect immediately after switching.
Selected 0 items
Loading...
Audit policy
Whitelisted tools skip approval; in approval mode the audit Agent only decides pass//reject.
In review-edit mode, the audit Agent can editedArguments narrow parameters before allowing; it should reject when parameters cannot be changed safely.
No-approval tool whitelist
One per line or comma-separated; saved to config.yaml global whitelist and effective immediately (shown in sync with the chat sidebar).
Audit log details
ID
—
Tools
—
Sessions
—
Decision
—
Approver
—
Time
—
Notes
—
Payload
MCP Status monitoring
Loading...
Latest execution records
Selected 0 items
Loading...
MCP Management
MCP Tool configuration
External MCP Configuration
Knowledge management
Total knowledge items-
Category count-
Total content-
Loading...
Retrieval history
Total retrievals-
Successful retrievals-
Success rate-
Knowledge items retrieved-
Loading...
Asset overview
Total assets
Assets currently under continuous monitoring
0
IP Count0
Domain count0
Port count0
Protocol distribution
View asset exposure composition by recognized service
—
ProtocolAsset shareCountShare
No data
7 DAYS
last 7 days discovered0
—
Trend changes
Observe asset and risk changes over the selected period
Asset growth/decline trend
New discoveries and currently disabled assets
New assetsDisabled assets
Loading...
Risk discovery trend
New vulnerabilities and the high-risk & critical risks among them
New vulnerabilitiesHigh and critical
Loading...
Scan coverage
Identify asset gaps that are unscanned or not rechecked for a long time
—
0%Overall coverage
Scanned assets0Completed at least one scan
last 30 day coverage00%
Never scanned0Recommended for scanning
over 30 days without a scan0Scan results may be outdated
Asset library
More
Export
Target
Service
Project
Ownership
Last scan
Related vulnerabilities
Risk level
Status
Actions
No data
Batch import assets
Download the template, fill it in and upload; data is validated and previewed before submission
1
Download templateRecommended XLSX;CSV good for quick exports from other systems
2
Upload fileSupport .xlsx and .csv; up to 100000 rows,100 MB
3
Data preview
Row number
Target
Project
Status
Validation results
Scan assets
×
Supports {{asset_id}}、{{target}}、{{host}}、{{ip}}、{{domain}}、{{port}} placeholders; a task is generated for each asset when creating the task.
Asset details
×
Info collection
01
Support FOFA、ZoomEye、Quake、Shodan;API Key can be configured in System Settings or environment variables.
02
Query method
After parsing, a popup shows the corresponding data source syntax (editable); once confirmed, it is filled into the query box and executed.
After selecting a data source, the corresponding query syntax hint is shown.
03
Return configuration
Different data sources may have different per-request return limits.
04
Query results
-
Selected 0 items
Show fields
No data
Project management
Select or create a project
Projects share a "fact blackboard" across conversations: target, environment, authentication and other info is auto-injected into conversations bound to the project.
Projects
In progress
0 facts0 vulnerabilities0 conversations0 pending
Key
Category
Summary
Relationships
Body
Confidence
Update
Actions
Target
Service
Title/Fingerprint
Source
Recent discoveries
Status
Actions
Title
Update
Actions
Title
Severity
Status
Actions
Project settings
Configure project metadata and Agent authorization boundaries; takes effect immediately on bound conversations after saving.
Basic info
Name and description are shown in the project details
For team members only;Agent will not read it. Keep it brief (up to 4000 characters). Anything the Agent must know goes into the fact blackboard
Test scope
JSON format for the Agent to understand authorization boundaries and target assets
Support targets、exclude、notes fields; leave empty to set no scope restrictions.
Dangerous actions
After archiving, tick "Show archived" in the list to view it; deleting clears all facts and is irreversible.
Vulnerability management
Total vulnerabilities
-
Critical
-
—
High
-
—
Medium
-
—
Low
-
—
Info
-
—
More filters
Selected filters
Loading...
WebShell Management
Connection list
No connections yet. Click "Add connection"
Select a connection from the left, or add a new WebShell Connection
File management
Manage files uploaded in conversations. Drag files into the list area below, or click "Upload file" to select files (multiple selection supported). To have AI reference a file, click "Copy path" in the list and paste it into the conversation.
Loading…
Task management
Listener management
Conversation management
Task management
Current filters0Success0Failed0Pending0
Quick
Payload Generate
One-line Payload
Quickly generate a reverse-shell command executable on the target, supporting Bash / Python / PowerShell / Curl
Compile Beacon binary
Cross-compile a complete multi-platform Beacon executable, supporting Linux / Windows / macOS
Event audit
Current filters0Info0Warning0Critical0
Quick
Traffic masking
Workflows
Untitled workflow
More
Drag nodes from the left onto the canvas, or generate a workflow in natural language
AI Arranging the canvas…
Role management
Loading...
SkillsStatus monitoring
Call statistics
Loading...
SkillsCall statistics
Loading...
Skills Management
Skills0
Current page0
Files0
Scripts0
Loading...
Agent Management
sub- Agent maintained only under the agents directory as .md files.
Loading...
Edit Agent
×
The main agent can also use the fixed filename orchestrator.md; only one main agent is allowed per directory.
System settings
Basic settings
AI Channel configuration
Switch saved channels via the dropdown; on save it is written to ai.channels. The default channel is used for new conversations and tasks without a specified channel.
Edit the currently selected channel
-
Connection info
Confirm the provider, address, key and model first; the connection test uses this information.
Agent Per-round limit for waiting on a tool; when it expires, an execution_id,worker is returned and the worker keeps running in the background. Use wait_tool_execution to keep waiting.0 waits until completion.
Tools running simultaneously per external MCP server ;0 Use default 2,-1 unlimited.
Total concurrency across all external MCP tools;0 Use default 16,-1 unlimited.
The same MCP server temporarily breaks the circuit after consecutive failures past the threshold;0 Use default 3,-1 disables the circuit breaker.
server cooldown wait time after a circuit break;0 Use default 60 seconds.
When enabled, the chat page offers "multi-agent" mode; sub-agents are configured under config.yaml’s multi_agent.sub_agents or in the agents directory.
only orchestration=plan_execute takes effect;execute and replan maximum rounds between
WeCom (WeChat Work) / DingTalk / robots use this execution mode for every message;Deep / Plan-Execute / Supervisor requires multi-agent mode enabled.
Advanced settings
Total limit of the raw user-input ledger injected into the model context after compression;0 uses the backend default.DB raw messages are never trimmed.
Model-visible limit for a single user message in the ledger;0 uses the backend default and does not affect the raw DB text.
The latest user entering the model context this round; when exceeded, the full text is persisted and only a preview is injected.0 uses the backend default.
overlong latest user Head characters kept for the model.
overlong latest user Tail characters kept for the model.
Human-machine collaboration
Approval configuration
Unselected conversations and new conversations use this approver by default; the conversation sidebar can still override it temporarily.
Maximum chunks per knowledge item (0 = unlimited), preventing a single file from consuming too much API quota
Max requests per minute (default 0 = unlimited), e.g. OpenAI Default 200 RPM
Request interval in milliseconds (default 300) to avoid API rate limits; set to 0 unlimited
Max retries (default 3); retries automatically on rate limits or server errors
Retry interval in milliseconds (default 1000); the delay increases with each retry
C2 Settings
built-in C2
When disabled, listeners are not started and C2 -related MCP tools are not registered; the sidebar C2 entry is hidden. Turn it off to save resources when you only use chat and the knowledge base locally.
Robot settings
Configure WeCom, DingTalk, Feishu and other robots to chat with Yoseph's Tools directly on your phone, without opening a web page on the server.
Robot management
Choose a robot type first, then enter the corresponding configuration; configured platforms show their connection status.
Robot vulnerability alertsPush newly discovered vulnerabilities by severity level to the robot bound to the current account.
Push newly discovered vulnerabilities matching the level through the bound robot account.
Select a robot to start configuring
Click an existing platform in the list above, or click“New robot”to create by type.
Business auth policy
The platform signature verifies the message origin; this decides which RBAC identity the message ultimately uses.
Currently using admin: whitelisted senders get full platform permissions, so only add accounts you fully trust.
is not supported. * The * wildcard. Only the real senders listed here can execute in service-account mode.
WeChat / iLink
Scan to bind personal WeChat and chat with Yoseph's Tools
Unbound
After confirming with a WeChat scan, it is saved and enabled automatically.
Projectsprojects — List all projects | List projects
New project <name>new project <name> — Create a project and bind the current conversation | Create & bind project
Bind project <IDor name>bind project <ID|name> — Bind the current conversation to a project | Bind conversation
Unbind projectunbind project — Remove the project binding of the current conversation | Unbind project
Diagnostics & security
Permissionspermissions — View current business permissions | Show effective permissions
Diagnosticsdoctor — Check critical configuration status | Check configuration status
Confirmconfirm / Cancelcancel — Confirm or cancel high-risk actions | Confirm or cancel risky action
Apart from the commands above, text typed directly is sent under the real-time RBAC permissions of the bound user or service account to AI。Otherwise, text is sent to AI under the effective RBAC identity.
Robot command reference
View the Chinese/English commands available in robot conversations, including identity auth, conversations, roles, modes, projects and security diagnostics.
Terminal
Execute commands on the server for operations and debugging. Commands run server-side; do not run sensitive or destructive operations.
Terminal 1
Log audit
Current filters0Success0Failed0Last 7 days0
Quick
Event type
→
Security settings
Change password
After changing the login password, you must sign in again with the new password.
Platform permissions
0accounts
0enabled accounts
0roles
0grants
User
Manage roles and resource scopes after selecting an account.
0
Loading...
Select user
After selecting a platform user, edit roles, status and resource authorizations.
Role-member relationships
Roles determine what one can do; resource scopes determine which data one can see.
Unsaved changes
only“Specified resources”scope roles need separate authorization. Project authorization covers the conversations and vulnerabilities under that project.
Pending authorization0
Authorizable resourcesSelect resources on the current page; selections accumulate across pages
Page 1
Currently individually authorized0items
Permission change history
Shows the platform permission operation audit for this member.
Select a user first
Showing 0-0 / of 0 records
Page 1 / 1
Role catalog
First define a role's operation permissions and resource scope, then assign it to members.
Tool call details
×
Execution info
Tools
Status
Time
Run ID
Run controls
Only interrupts the current tool call; the conversation and multi-step tasks continue.
Request parameters
Response result
Error info
Interrupt current step
×
After filling in the note, it is written into the conversation and the agent continues iterating.
Terminate the tool and add a note
×
Optional note.
Add externalMCP
×
Configuration format:JSONobject:keyis the configuration name,valueis the configuration content. State is controlled by the"Start/Stop"button; it does not need to be configured inJSON. Configuration example: stdioMode: {
"hexstrike-ai": {
"command": "python3",
"args": ["/path/to/script.py", "--server", "http://example.com"],
"description": "Description",
"timeout": 300
}
}HTTPMode: {
"cicada-agi-http": {
"transport": "http",
"url": "http://127.0.0.1:8081/mcp"
}
}SSEMode: {
"cicada-agi-sse": {
"transport": "sse",
"url": "http://127.0.0.1:8081/mcp/sse"
}
}
Attack chain visualization
×
Nodes: 0 | Edges: 0
Loading...
Risk level
High risk (80-100)
Medium-high risk (60-79)
Medium risk (40-59)
Low risk (0-39)
Edge legend
Blue line: an action discovered the vulnerability
Red line: enables//facilitates relationship
Gray line: logical order
Node details
Edit file
×
Rename
×
Current file
New folder
×
Location
chat_uploads
Workflow info
×
Cannot be modified after creation; used for API and role binding
Enable
Import local package
Security precheck
First checks the package contents and conflicts, then you confirm whether to import
×
1Upload & precheckValidate format, content and version2Resolve conflicts & importConfirm the handling method and finish the import
Local workflow package
Select the file to import
.CSAPKG.ZIP
Drag the local package hereorBrowse files
ZIP
Only a single .csapkg.zipis supported; the file must not exceed 10 MiB。
Import policy
Handling method
Pending precheck
Confirm overwriting the local workflow?
×
Overwriting replaces the name, description, graph definition and enabled state. No rollback is provided in this release.
AddSkill
×
Lowercase letters, digits and hyphens (matching the Agent Skills name)
Written to the YAML front matter of SKILL.md (description field)
Click a file to edit it; folders are for grouping only and are not clickable
EditingSKILL.md
Selecting SKILL.md here the body is used (without YAML header); on save it is written back to the standard SKILL.md。
Only the body is needed at creation; saving generates a standard SKILL.md(with YAML header). Open-source skill packages can be dropped into skills/<name>/ directly.
Add knowledge
×
Manage conversation records·of0items
×
Conversation name
Projects
Conversation groups
Last conversation time
Actions
Create group
×
Grouping keeps conversations organized and easy to manage.
Select icon
📁🔒🛡️⚔️🎯🔍💻🐛🚀⚡🔥💡🎮🏴☠️🕵️🔑📡🌐📊📝🗂️📌⭐💎
Penetration testing
CTF
Red team
Vulnerability research
View attack chain
Download Markdown
Simple
Full version
View vulnerability
Rename
Pin this conversation
Batch management
Move to group
Delete this conversation
Rename
Pin this group
Delete this group
New task
×
Set a title for the batch task queue for easier lookup and management later.
Select a role; all tasks will run with that role's configuration (prompts and tools).
Can bind a project to the queue; leave empty to skip project context.
Same as the chat page:Eino Single agent (ADK), or Deep / Plan-Execute / Supervisor(the last three require multi-agent mode to be enabled).
Number of subtasks running at once (1-8). The default of 1 is serial; recommended when scan-type tools are involved: 1-2。
Manual execution is for one-off tasks;Cron is for scheduled tasks. It is recommended to manually verify task correctness first.
Uses the standard 5 field Cron: minute hour day month weekday, e.g. `0 2 * * *` runs daily at 02:00 .
Not executed immediately by default; when off, the queue stays pending and can be started manually when needed.
Tip: enter one task instruction per line; the system executes them in order. Empty lines are ignored automatically.
Batch task queue details
×
Add task
×
Add vulnerability
×
After binding, Agent the Agent can see this record within the project scope via list_vulnerabilities ; leave empty to try auto-linking from the conversation.
Add connection
×
Determines whether file management//upload uses Linux or Windows commands;PHP/JSP running on Windows should choose Windows
Chinese Windows targets showing garbled text, switch to GBK or GB18030
Select role
×
Add role
×
Enter anemojias the role icon; it will be shown in the role selector.
This prompt is prepended to the user message to guide theAIbehavior. Note: it does not modify the system prompt.
Once a workflow is selected, using this role in the chat page triggers it automatically; the workflow fields are freely configured by the graph definition JSON .
ℹ️
Default role uses all tools
Default roles automatically use all tools enabled inMCPmanagement; no separate configuration needed.
Loading tool list...
Check the tools to associate; when empty, all tool configurations fromMCPmanagement are used.
Platform users
×
Roles are managed uniformly in the "Role permissions" tab of the member details page.
Platform roles
×
Resource scope and operation permissions together determine the final access capability.
New project
Can be bound to conversations after creation to share the fact blackboard across sessions
For team members only;Agent will not read it. Keep it brief (up to 4000 characters). Anything the Agent must know goes into the fact blackboard
Add fact
The summary feeds the blackboard index;body stores attack chains and POCfor audit reproduction (complementing vulnerability records)
One per line:type: source_fact_key(source → current fact). Common type:discovered_on、depends_on、leads_to、enables、exploits. All relationship edges are replaced on save.
Fact details
Bind robot account
Securely link IM platform identity to the current RBAC User
1Generate one-time bind code→2Send the bind command in the robot chat→3Immediately inherits the current user's permissions
One-time security codeWaiting to generate
••••-••••
Send the bind command in the robot chat05:00
Only the hash of the bind code is stored; it is single-use and a new code immediately invalidates the old one
Bound platform account
These platform identities use the current user's real-time RBAC Permissions