
AI Security Engineering Platform
Built on the AgentSkills open standard · Community project · Not affiliated with Anthropic PBC
XBOW 104-Challenge Validation Suite · 98/104 solved · 100% adjusted rate (6 infra failures) · Zero solver failures
| System | Pass Rate | Solved |
|---|---|---|
| NERF | 94.2% | 98/104 |
| Shannon | 96.0% | — |
| PentestGPT | 86.5% | — |
| MAPTA | 76.9% | — |
Chained blind SQL injection with time-based extraction into arbitrary file upload for RCE
4 benchmark suites: XBOW (104) · NYU CTF (255) · PicoCTF (56) · OverTheWire (93) · Full report →
Node.js 18+ · No Python · No pip · No virtual environments
npm install -g @defconxt/nerf
docker run -it ghcr.io/defconxt/nerf:latest nerf doctor
git clone https://github.com/defconxt/NERF.git && cd NERF && npm install && npm link
Pure Node.js · No Python · 25ms cold start · Run nerf setup after install
326 trigger keywords with weighted scoring · Auto-detects from your query
1,539 techniques across 64 domains · Every skill follows the AgentSkills.io Specification
Everything runs as native Node.js — zero subprocess bridges
39 frameworks · 1,151 controls · Gap analysis · CSV / JSON / Markdown export
Any agent that reads SKILL.md or speaks MCP
95 deep-dive reference articles across 8 categories