The design
Explicit scopeAuthorized assets and techniques.
AgentReconnaissance and non-destructive validation.
EvidenceReproducible steps and impact.
Fix queueOpens an issue/PR or routes to the owner.
RetestConfirms the fix actually closed the path.
Non-negotiable guardrails
- Environment and assets authorized by allow list.
- Rate limits and an execution window.
- No persistence, exfiltration or destructive techniques by default.
- Kill switch and a complete action trail.
Takeaway: The goal isn't to attack more. It's to shrink the time between exposure and fix.
Take this playbook with you
In Markdown to paste into your AI, or as the starting point for your own playbook.