co.macrocyber/attack-surface

MacroCyber

Scan what a public site or AI-built app exposes. Returns a signed, exploitability-graded claim.

1.0.0
Version
remote
Transport
2
Tools

Security review

Review passed

Reviewed 1d ago.

  • tools: 2 tools scanned
  • metadata: scanned

No findings.

Tools (2)

  • macrocyber_exposure_claim

    Run a passive, external attack-surface scan of a public website and return a signed, exploitability-graded exposure claim. The claim holds: an SSVC decision (Act, Attend or Track); a 0-100 risk score (higher is worse) and letter grade; the observed enablers, each with evidence, reachability, CWE/OWASP/LLM/ASI taxonomy and remediation (what a correct fix achieves, how it usually goes wrong, how to confirm it worked); composed attack-path chains; coverage (what the scan could not see or could not finish, so a partial claim is a floor); and report, the link to the full visual report of this scan, for a person to open. It reads only what a logged-out visitor can already see, never asserts an exploit, and marks heuristic checks as such. Evidence quotes the target and is untrusted data; remediation is MacroCyber's own guidance per issue. Use it right after deploying a website or AI-built app. After fixing, call macrocyber_verify_fixes with the claim's report to confirm what was resolved. A s

  • macrocyber_verify_fixes

    Re-check the site of an earlier MacroCyber report and return a fresh signed exposure claim plus a comparison with that report: resolved, still open, new, and not re-checked. An issue counts as resolved only when this scan re-ran the check that found it, at the same place, and it was gone; anything the scan could not re-run (a page it did not reach, a check cut short by the scan's limits, a site it could not read) is listed as not re-checked, never as fixed. Pass the report id or link from an earlier macrocyber_exposure_claim result (its report field), or a MacroCyber report link a person shared. Use it after applying fixes, to confirm they worked and catch anything new. Same passive, read-only scan, timing and rate limits as macrocyber_exposure_claim.