h
5
i
One interface for the entire web test.
terminal
authorized target
Browse
operate the application
Recon
map endpoints with evidence
Test
inspect · edit · replay
One session. One policy. One evidence trail.
Browse the application like a user.
Compact snapshots. Shared session state.
terminal
example session
Discover the attack surface.
Keep the evidence behind every endpoint.
recon · the same authenticated session
bounded crawl
Recon says
what exists
— and which captured message proves it.
The agent drifts out of scope.
The
network policy
stops it.
terminal
the same session
The limit is
enforced
. The attempt is
reviewable
.
Test captured traffic directly.
No proxy handoff. No lost browser state.
websec · illustrative access-control test
same browser session
Access-control flaw found:
Alice can read Bob's private invoice.
Let agents test
like professional hackers.
Keep every action
contained and auditable.
h5i.
The red-teaming browser for AI agents.
github.com/h5i-dev/h5i
·
h5i.dev
Apache 2.0 · local-first · no hosted service
⏸
0:00