# Capability catalog and tools

> CatBridge typed capabilities, pinned executors, the read-only, external-approved and active-approved profiles, budgets, reviewed templates and the data each tool receives.

- Language: en
- Canonical URL: https://netcattest.com/catsuite/en/docs/catbridge/tools
- Section: CatBridge
- Updated: 2026-10-05
- Other language (pt-BR): https://netcattest.com/catsuite/docs/catbridge/ferramentas

An extension never chooses binaries, arguments or images. It requests a **typed capability** and the [CatBridge](https://netcattest.com/catsuite/en/docs/catbridge) supervisor builds the command, reserves the budget and returns only verified JSON. Each capability has an **executor pinned by version and hash**; modifying the executable invalidates approved capabilities.

> [!NOTE]
> The catalog distinguishes **implementation** from **availability**. A capability may exist in the code and show up as `planned`, `not-installed` or `unavailable` until you prepare the matching executor on your computer.

## Initial capabilities (SDK 1.3)

| Capability | Pinned executor | Result |
|---|---|---|
| `http.probe` | httpx 1.12.0 | HTTP services, status, title, selected headers and observed technologies |
| `web.crawl` | Katana 1.7.0 | Pages, forms, parameters and static JavaScript candidates |
| `api.schema.test` | Schemathesis 4.29.1 | Coverage, checks, observed failures, seed and reduced case |
| `nuclei.scan` | Admin's reviewed install | Results from approved HTTP templates |

## Ecosystem capabilities (SDK 1.4)

The stage 2 to 5 adapters require contract 2 and `.catflow` 5. API v1 and the signed Protocol 2 stay compatible.

| Capability | Pinned executor |
|---|---|
| `assets.subdomains.discover` | subfinder 2.16.0, Amass 5.1.1 |
| `dns.resolve` / `dns.enumerate` | dnsx 1.3.1 |
| `dns.permute` | AlterX 0.1.0 |
| `urls.history` | gau 2.2.4, waybackurls 0.1.0 |
| `assets.search` | Uncover 1.2.1 |
| `net.ports.discover` | naabu 2.6.1, Nmap 7.991 |
| `net.services.fingerprint` | Nmap 7.991 |
| `web.paths.fuzz` / `http.parameters.fuzz` / `web.vhosts.fuzz` | ffuf 2.3.0 |
| `http.parameters.discover` | Arjun 2.2.7 |
| `web.xss.analyze` | Dalfox 3.2.3 |
| `api.sqli.validate` | SQLmap 1.10 |
| `jwt.analyze` | JWT Tool 2.3.0 |
| `tls.assess` | testssl.sh 3.2.4 |
| `web.server.assess` | Nikto 2.6.1 |
| `code.secrets.scan` | Gitleaks 8.30.1, Trufflehog 3.97.9 |
| `code.sast.scan` | Semgrep 1.179.0 |

Some profiles query selected public sources: subfinder uses crt.sh and CertSpotter; Uncover uses Shodan InternetDB by IP, with no credentials; gau and waybackurls use the Wayback Machine — historical URLs do **not** prove active services. DNS accepts A, AAAA, CNAME, MX, NS and TXT; TTL and DNSSEC are not considered verified.

## Execution profiles

- `read-only` — offline operations and DNS lookups.
- `external-approved` — queries to approved external sources.
- `active-approved` — active tests against approved destinations.
- `mutation-approved` — Schemathesis only, after you explicitly select the operations and obtain a new approval.

In the ecosystem, HTTP is limited to **GET**. Discoveries and redirects do **not** widen the scope.

## Budgets and limits

Limits apply to the whole task and are reserved before each batch:

| Limit | Value |
|---|---|
| Targets per task | up to 25 (httpx accepts 50; Schemathesis uses one base URL) |
| Network operations | up to 500 |
| Rate | 5 requests/s, 2 connections |
| Time | 120 s (httpx/Katana) · 300 s (Schemathesis) · 10 min (Nuclei) |
| Results | 1,000 per task |
| Katana | `depth` up to 2 and `pages` up to 25, no browser or JavaScript execution |
| Schemathesis | `operations`/`paths` up to 20; `examples` up to 25; integer `seed` |
| TCP ports | up to 32 per task, one target per task |
| TLS | one port per step |

Cancellation does **not** return a reservation whose consumption is unknown. Completed batches (up to five destinations and five templates) are reused; repeating a batch with an unknown result requires an explicit choice.

## Reviewed templates (Nuclei)

The manifest is a list of `id`, `path`, `sha256` and `name` in pt-BR/en. Update the hash **only** after you review the YAML.

```json
{
  "templates": [
    {
      "id": "aurora-cache",
      "path": "examples/aurora-cache.yaml",
      "sha256": "…",
      "name": {"pt-BR": "Cache do Aurora", "en": "Aurora cache"}
    }
  ]
}
```

Only **HTTP GET/HEAD**, `{{BaseURL}}`-based targets, matchers and extractors are accepted. Code, executable JavaScript, headless, DNS, OAST, external workflows, raw requests and configured redirects are **not** accepted. Headers that change host or framing are refused. Hashes are verified before **each** run.

## Data the tool receives

- The default `endpoints-only` profile does **not** forward cookies, tokens or bodies.
- `selected-headers` shares up to **16 headers / 16 KiB** explicitly chosen in the step and included in the approval.
- `Cookie` and `Authorization` require explicit selection and **SECRET** classification; host/framing headers are refused.
- Selected values live in a private temporary file removed when the task ends. Bodies are **never** sent to Nuclei.

## Resources sent to the workflow

Some adapters use resources you upload in signed chunks of up to 64 KiB, bound to device, flow, revision and classification; the hash is part of the immutable approval.

| Resource | Limit |
|---|---|
| Dictionary (wordlist) | 2 to 500 unique entries up to 128 characters |
| File snapshot | 100 files, 256 KiB per file, 1 MiB total |
| JWT | SECRET resource up to 16 KiB |

Absolute paths, directory traversal and symbolic links are refused.

## Results and evidence

Results arrive in signed pages of up to **50 records or 512 KiB**, with verifiable receipts, versions and hashes of the executable and templates. Credential values and parameters recognized as secret are hidden.

> [!WARNING]
> A tool signal is **evidence for review**, not proof of exploitation. A Schemathesis contract failure, for example, is recorded as an informational, observed finding — it does not prove a vulnerability.

## Next step

- [Install and pair CatBridge](https://netcattest.com/catsuite/en/docs/catbridge/install)
- [Visual workflows](https://netcattest.com/catsuite/en/docs/workflows)
- [Error reference](https://netcattest.com/catsuite/en/docs/reference/errors)
