06-continuous · 30–90 min / run · 5 min

Periodic guardrail: Continuous mode.

Same folder, same journal. A cron, a release hook, or a manual rerun. Each run looks at probes already placed. If nothing moved, we write that. We do not invent a finding to justify the pass.

When to open it
  • A Full audit (or a Delta) already set the baseline
  • You want a pass on every release or every week
  • You accept a narrow collection — not a new audit
Agents
00, 01 + tracker-continuous specialist
Outside this mode
  • Does not open a new class outside existing probes
  • No baseline: Express or Full first
  • A sterile run does not authorize a board report

What each run does

  • Open entry with the trigger.
  • Narrow collection: policies, known headers, 404 probe, script list. Cap 80 URLs.
  • Compare to recent evidence, like an automatic delta.
  • A security header disappears, a 500 becomes talkative, an in-scope host appears: finding or regression.
  • Nothing moved: “sterile run” note, no fake finding.

Launch phrase

Continuous on the already-open project. Trigger: release / cron / manual.

Before you launch

Is this a managed SOC?
No. It is a guardrail YOU run, on your machine, on the same journal. Karukera never sees the target.

The kit, not the guide.

Open source, MIT. Clone it, open it in Claude, Codex, Cursor or Hermes. A held report — or QA’s silence.

Open sourceMIT0 stars0 forks

github.com/cryptulien/security-kit