07-redteam-leger · 1–3 days · 6 min

Light red team: active, authorized, no weapon.

This is not an offensive pentest. The ZIP contains no exploit; you write none. It is an adversarial exercise bounded by a written mandate. Without the signed file, no GET is sent.

When to open it
  • Adversarial-exercise mandate, hunting blind spots
  • Dated host scope, equal or narrower than the brief
  • You accept that an oral ok or a Slack message is insufficient
Agents
00–11 — stop without AUTHORIZED=yes + authorization.md
Outside this mode
  • No exploit, no payload, no attack PoC
  • Anything outside the dated mandate = stop
  • Expired authorization = stop on resume

The gate

Two conditions, or stop: AUTHORIZED=yes, and authorization.md present. Four minimum clauses: signer identity, host scope, explicit sentence (non-destructive tests between two dates), client forbids. “It’s my site” in chat does not count.

Only a system you have written authorization for. No exploit, no payload, no attack PoC.

Launch phrase

Light red team. Signed authorization.md in the project folder. AUTHORIZED=yes only after reading the four clauses.

Before you launch

I am the founder — is that not enough?
The file must exist in the project folder, with the four clauses. The kit does not take your word. That is intentional.

The kit, not the guide.

Open source, MIT. Clone it, open it in Claude, Codex, Cursor or Hermes. A held report — or QA’s silence.

Open sourceMIT0 stars0 forks

github.com/cryptulien/security-kit