Best for
- Authorized security researchers and red/blue team engineers who want verify-before-report workflows
- Agent users who want a full penetration-testing flow driven by one call inside an MCP client
- Developers and security reviewers needing code audit (taint analysis, source-to-sink, variant analysis)
- Teams that want a structured methodology plus knowledge base (manuals, playbooks, escalation chains) instead of scattered scripts