07-redteam-leger · 1–3 days · 6 min
Light red team: active, authorized, no weapon.
This is not an offensive pentest. The ZIP contains no exploit; you write none. It is an adversarial exercise bounded by a written mandate. Without the signed file, no GET is sent.
- When to open it
- Adversarial-exercise mandate, hunting blind spots
- Dated host scope, equal or narrower than the brief
- You accept that an oral ok or a Slack message is insufficient
- Agents
- 00–11 — stop without AUTHORIZED=yes + authorization.md
- Outside this mode
- No exploit, no payload, no attack PoC
- Anything outside the dated mandate = stop
- Expired authorization = stop on resume
The gate
Two conditions, or stop: AUTHORIZED=yes, and authorization.md present. Four minimum clauses: signer identity, host scope, explicit sentence (non-destructive tests between two dates), client forbids. “It’s my site” in chat does not count.
Only a system you have written authorization for. No exploit, no payload, no attack PoC.
Launch phrase
Light red team. Signed authorization.md in the project folder. AUTHORIZED=yes only after reading the four clauses.
Before you launch
- I am the founder — is that not enough?
- The file must exist in the project folder, with the four clauses. The kit does not take your word. That is intentional.
The kit, not the guide.
Open source, MIT. Clone it, open it in Claude, Codex, Cursor or Hermes. A held report — or QA’s silence.