I got tired of doing the same recon for the 1000th time. So I built an AI agent that does it for me and it turned out to find real bugs. In the wild: OTP bypasses, IDORs exposing millions of records, leaked credentials, Cloudflare WAF bypasses, RBAC privilege escalation, S3 misconfigurations. Full workflow: recon → exploitation → reporting. Autonomous, but with real guardrails (scope validation, blocklists, audit logs). For bug bounty hunters and pentesters. Solo built.
Hey Product Hunt 👋
Solo maker here. Quick honest pitch on what this is and what it isn't.
WHY I BUILT IT
I was doing bug bounty on the side and burning out — not on the bugs
(those are fun), but on the 4 hours of recon and scanning before I
could even start thinking. So I built an AI agent to handle the boring
80%. It turned into something bigger than I expected.
WHAT IT DOES
You point it at a target. It does recon, vulnerability scanning,
exploitation attempts, and writes a clean report. You review and
submit. Fully autonomous, but you stay in control.
WHAT IT'S FOUND (real findings, real targets)
→ OTP bypass on an auth flow
→ IDOR exposing editorial data across millions of records
→ Exposed credentials in publicly accessible sources
→ Cloudflare WAF evasion on protected endpoints
→ RBAC privilege escalation (low-priv user → admin actions)
→ S3 bucket misconfigurations leaking internal data
Most of these are mid-to-high severity bugs that a solid hunter would
find except the agent does it in 30 minutes, 24/7, in parallel on
multiple targets.
WHAT I'M HONEST ABOUT
→ It's not god-tier. It works at the level of a strong intermediate-
to-senior hunter, not Orange Tsai. Yet.
→ Some targets it crushes, others it misses things a human would
catch on instinct.
→ Pricing isn't finalized. PH users get extended access in exchange
for honest feedback.
ON THE LEGAL/ETHICAL SIDE
I know "autonomous offensive AI" raises eyebrows. So I built real
guardrails, not theater:
→ Mandatory authorization declaration per mission (user states they
have permission, with framework: bug bounty program / own asset /
lab / written authorization)
→ Hard blocklists for sensitive targets (government, healthcare,
critical infrastructure, banks)
→ Scope validation against HackerOne / Bugcrowd / Intigriti programs
→ Immutable audit logs of every action
→ Rate limits and kill switches
This isn't a tool for script kiddies. It's for people doing legitimate
security work.
WHAT I'M LOOKING FOR
→ Honest feedback from hunters and pentesters
→ Ideas for what to find next
→ Brutal criticism on what's missing or broken
DMs open. Ask me anything in the comments including the hard stuff.
Thanks for checking it out 🙏
Report
No reviews yetBe the first to leave a review for Sentinelle