Skip to main content

riciplay-cli

Riciplay Security Platform — Command-line Interface

An autonomous AI-driven bug bounty hunting agent for web applications and codebases. Runs local investigations with an LLM-in-a-loop leader that orchestrates specialists, probes endpoints, verifies findings, and chains vulnerabilities.

Features

  • Autonomous DAST (Dynamic Application Security Testing) — Web app vulnerability scanning with automatic attack-surface enumeration, multi-class injection probing (XSS / SQLi / IDOR / open-redirect / SSRF), and interception-driven recon through miniproxy + headless browser.

  • Autonomous SAST (Static Application Security Testing) — Code audit with semgrep, code search, and AI-guided data-flow tracing. Finds injection sinks, hardcoded secrets, weak crypto, and path traversal.

  • Manual-analysis mode — Human-pentester-style workflow: observe through browser, take notebook notes, register accounts, test cross-account, reason and iterate.

  • Specialist orchestration — Parallel execution of domain specialists (Recon, Web, API, Auth, Cloud, Business Logic) with shared findings, cross-specialist corroboration, and compound attack chaining.

  • Coverage gates — Deterministic finish-time enforcement ensures every discovered endpoint×parameter×attack-class combination is attempted before the investigation concludes.

  • Two-identity IDOR testing — Automatic account registration/login and cross-account replay for authorization bypass detection.

  • Phase-separated investigation — DISCOVER (breadth-first surface mapping and probing) followed by REPORT (impact verification, chaining, and quality gating).

Installation

pip install riciplay-cli

Requires Python 3.10+, mitmdump (for proxy capture), and optionally Chromium (via Playwright) for browser-based discoveries.

Quick Start

# Authenticate against the Riciplay backend
riciplay auth set-key <your-api-key>

# Run a DAST investigation against a target
riciplay scan investigate https://example.com --budget 12

# Run a SAST code audit
riciplay scan investigate ./my-project --mode sast --budget 8

# Manual-analysis mode
riciplay scan investigate https://example.com --mode manual --budget 15

Configuration

  • riciplay auth status — Check authentication and tier
  • riciplay auth whoami — Show current account info
  • riciplay review <path> — Code review with markdown output
  • riciplay --help — Full command reference

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

riciplay_cli-1.8.37.tar.gz (690.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

riciplay_cli-1.8.37-py3-none-any.whl (740.2 kB view details)

Uploaded Python 3

File details

Details for the file riciplay_cli-1.8.37.tar.gz.

File metadata

  • Download URL: riciplay_cli-1.8.37.tar.gz
  • Upload date:
  • Size: 690.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for riciplay_cli-1.8.37.tar.gz
Algorithm Hash digest
SHA256 919f1829c6f262d0e2ba1e0a4a4682c698cbffb3ac180806faf2d1d70e31c3aa
MD5 7d2713c8d5e8bd4133dccf9e40994e89
BLAKE2b-256 81da62f09bb2a50de8d4b66eed88d1c277de33d144326b29350a4a6c997f0f19

See more details on using hashes here.

File details

Details for the file riciplay_cli-1.8.37-py3-none-any.whl.

File metadata

  • Download URL: riciplay_cli-1.8.37-py3-none-any.whl
  • Upload date:
  • Size: 740.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for riciplay_cli-1.8.37-py3-none-any.whl
Algorithm Hash digest
SHA256 57cd4e4bf5d394349071a1c967ce3d94b427dfed17c3e9112bcbcd871eca1889
MD5 82e43e3f2e7ee3cd3bae6cfcad352f06
BLAKE2b-256 baa8c61a34beec5772a85907d7c7388dad381dc9c25c84de87ba494b77bcb755

See more details on using hashes here.

Release history Release notifications | RSS feed

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page