An extension never chooses binaries, arguments or images. It requests a typed capability and the CatBridge supervisor builds the command, reserves the budget and returns only verified JSON. Each capability has an executor pinned by version and hash; modifying the executable invalidates approved capabilities.
Initial capabilities (SDK 1.3) #
| Capability | Pinned executor | Result |
|---|---|---|
http.probe | httpx 1.12.0 | HTTP services, status, title, selected headers and observed technologies |
web.crawl | Katana 1.7.0 | Pages, forms, parameters and static JavaScript candidates |
api.schema.test | Schemathesis 4.29.1 | Coverage, checks, observed failures, seed and reduced case |
nuclei.scan | Admin's reviewed install | Results from approved HTTP templates |
Ecosystem capabilities (SDK 1.4) #
The stage 2 to 5 adapters require contract 2 and .catflow 5. API v1 and the signed Protocol 2 stay compatible.
| Capability | Pinned executor |
|---|---|
assets.subdomains.discover | subfinder 2.16.0, Amass 5.1.1 |
dns.resolve / dns.enumerate | dnsx 1.3.1 |
dns.permute | AlterX 0.1.0 |
urls.history | gau 2.2.4, waybackurls 0.1.0 |
assets.search | Uncover 1.2.1 |
net.ports.discover | naabu 2.6.1, Nmap 7.991 |
net.services.fingerprint | Nmap 7.991 |
web.paths.fuzz / http.parameters.fuzz / web.vhosts.fuzz | ffuf 2.3.0 |
http.parameters.discover | Arjun 2.2.7 |
web.xss.analyze | Dalfox 3.2.3 |
api.sqli.validate | SQLmap 1.10 |
jwt.analyze | JWT Tool 2.3.0 |
tls.assess | testssl.sh 3.2.4 |
web.server.assess | Nikto 2.6.1 |
code.secrets.scan | Gitleaks 8.30.1, Trufflehog 3.97.9 |
code.sast.scan | Semgrep 1.179.0 |
Some profiles query selected public sources: subfinder uses crt.sh and CertSpotter; Uncover uses Shodan InternetDB by IP, with no credentials; gau and waybackurls use the Wayback Machine — historical URLs do not prove active services. DNS accepts A, AAAA, CNAME, MX, NS and TXT; TTL and DNSSEC are not considered verified.
Execution profiles #
read-only— offline operations and DNS lookups.external-approved— queries to approved external sources.active-approved— active tests against approved destinations.mutation-approved— Schemathesis only, after you explicitly select the operations and obtain a new approval.
In the ecosystem, HTTP is limited to GET. Discoveries and redirects do not widen the scope.
Budgets and limits #
Limits apply to the whole task and are reserved before each batch:
| Limit | Value |
|---|---|
| Targets per task | up to 25 (httpx accepts 50; Schemathesis uses one base URL) |
| Network operations | up to 500 |
| Rate | 5 requests/s, 2 connections |
| Time | 120 s (httpx/Katana) · 300 s (Schemathesis) · 10 min (Nuclei) |
| Results | 1,000 per task |
| Katana | depth up to 2 and pages up to 25, no browser or JavaScript execution |
| Schemathesis | operations/paths up to 20; examples up to 25; integer seed |
| TCP ports | up to 32 per task, one target per task |
| TLS | one port per step |
Cancellation does not return a reservation whose consumption is unknown. Completed batches (up to five destinations and five templates) are reused; repeating a batch with an unknown result requires an explicit choice.
Reviewed templates (Nuclei) #
The manifest is a list of id, path, sha256 and name in pt-BR/en. Update the hash only after you review the YAML.
{
"templates": [
{
"id": "aurora-cache",
"path": "examples/aurora-cache.yaml",
"sha256": "…",
"name": {"pt-BR": "Cache do Aurora", "en": "Aurora cache"}
}
]
}Only HTTP GET/HEAD, {{BaseURL}}-based targets, matchers and extractors are accepted. Code, executable JavaScript, headless, DNS, OAST, external workflows, raw requests and configured redirects are not accepted. Headers that change host or framing are refused. Hashes are verified before each run.
Data the tool receives #
- The default
endpoints-onlyprofile does not forward cookies, tokens or bodies. selected-headersshares up to 16 headers / 16 KiB explicitly chosen in the step and included in the approval.CookieandAuthorizationrequire explicit selection and SECRET classification; host/framing headers are refused.- Selected values live in a private temporary file removed when the task ends. Bodies are never sent to Nuclei.
Resources sent to the workflow #
Some adapters use resources you upload in signed chunks of up to 64 KiB, bound to device, flow, revision and classification; the hash is part of the immutable approval.
| Resource | Limit |
|---|---|
| Dictionary (wordlist) | 2 to 500 unique entries up to 128 characters |
| File snapshot | 100 files, 256 KiB per file, 1 MiB total |
| JWT | SECRET resource up to 16 KiB |
Absolute paths, directory traversal and symbolic links are refused.
Results and evidence #
Results arrive in signed pages of up to 50 records or 512 KiB, with verifiable receipts, versions and hashes of the executable and templates. Credential values and parameters recognized as secret are hidden.