Pentest is not a workflow, It is a search problem.
This is a dev post classified by Jev as Security (a tool drop), kept by the Dev Radar because it carries real work, not commentary.
Pentest is not a workflow, It is a search problem. - Known start. - Defined goal. - Unknown path. - Zero predefined roles. - Zero RAG. - Validated first on autonomous pentesting. - Tencent Cloud AI Pentest Challenge (2nd ed.) 54/54, only all-clear, 3rd of 610 teams. - Use only on systems you are authorized to test. This repo Cairn treats it that way and also treats CTF, vuln research, and proofs the same. The claim is bigger: general state-space search. http://github.com/oritera/Cairn
Posted by Md Ismail Šojal 🕷️ (55.6k followers) 2 h ago · 11 likes · 935 views · view the original post on X. Kept by the Dev Radar as Security. Tools mentioned: cairn.
More dev work like this
- I just built the open-source version of this — @imarikchakma
- Security teams shouldn't have to wait for a critical vulnerability to trigger an… — @thenewstack
- Cloudflare just turned AI agents into SECURITY AUDITORS. — @tonysimons_
- Wow, these slides are fantastic to just read through and contemplate. 😍… — @zooko
- How hackers use SQL Injection to compromise a website — @Hamzaonchain
- Dostlar selamlar, globaldeki en büyük Cybersecurity SFT finetuning datasetlerinden olan… — @AlicanKiraz0
- Cloudflare 团队把其内部找漏洞的那套方法做成了一个 Skill,叫 security-audit,并开源了。 — @GitHub_Daily
- Practical Social Engineering: A Primer for the Ethical Hacker! #BigData #Analytics… — @gp_pulipaka
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 15.2k posts from 4.8k X accounts over the last 21 days, 1.7k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-20 03:24 UTC. Full method.