Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/opposum0112/cusimanse
Defensive ToolsPenetration Testing FrameworksDynamic Analysis (Sandboxing)Vulnerability AnalysisScripting & AutomationSecurity VirtualizationMalware AnalysisUtilities & FrameworksPapers & ResearchLearning & EducationIncident Response
419 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
AI Security
GitHubopposum0112/cusimanse

Cusimanse

Composable research-contract and YAML-recipe framework for agent-operated security experiments on disposable compute

View Repository
Share

Cusimanse

Cusimanse mascot and logo

Validation Go ShellCheck Goose AI Beta

Status: Beta — Research Framework & Runtime Kit

Cusimanse is actively being developed. Fork it, test it, run the reference experiments, report bugs, and submit pull requests. Expect APIs, recipes, documentation and integrations to evolve during beta.

AI use and responsible contribution: Cusimanse uses AI-assisted development and agentic AI as part of its research framework, documentation, analysis workflows and engineering process. AI-generated or AI-assisted output is not automatically authoritative, secure, correct, original or suitable for production use. Contributors are responsible for reviewing, testing and validating AI-assisted changes before submission. Do not rely on an AI system as the sole authority for security decisions, authorization, evidence interpretation or safety-critical actions. Use Cusimanse only for authorized research, respect applicable laws and policies, protect credentials and sensitive data, and keep execution within the project's declared policy and disposable-compute boundaries. Contributions should clearly identify material AI assistance where appropriate, preserve human accountability, and follow the repository's tests, review requirements and responsible-use expectations.

Declarative, agent-operated security research on disposable compute. Researchers declare intent and requirements; agents plan, select and analyze; the Go capability API and policy decide whether and how execution may occur.

Cusimanse architecture

Contract → requirements → prompt handoff → agent → capability resolution → Go runtime → policy/approval → Lima/QEMU → instrumentation/workload → evidence → analysis → independent verification → report → preservation → destroy.

Table of contents

  • What Cusimanse is
  • Architecture and authority boundary
  • Researcher workflow
  • Prompt library and agent handoff
  • Host tooling and installation
  • Gateways
  • Instrumentation
  • Observability
  • Lima/QEMU and guest tooling
  • Go capability API and commands
  • Roles, Skills and learning loop
  • Profiles and requirements
  • Policy and safety
  • Evidence and reproducibility
  • Reference experiments
  • Validation and integration testing
  • Credits and open source community
  • Repository map

What Cusimanse is

LayerResponsibilitySource of truth
Contractpurpose, authorization, scope, acceptancecontracts/
RequirementsOS, isolation, workload, network, instrumentationrecipes/experiments/
Prompt libraryagent-neutral handoffprompts/experiments/
Operator guidesthin adapter handoffprompts/operators/
Profilestrusted reusable capabilitiesrecipes/profiles/
Runtimeresolution, policy, lifecycle, execution boundarycmd/cusimanse/, internal/
Policyauthority and approvalpolicies/, internal/policy/
Containmentdisposable computerecipes/lima/, Lima/QEMU
Evidenceobservations, provenance, verificationruns/<session-id>/

The agent cannot create trusted profiles, expand policy, mutate trusted recipes or execute an untrusted workload directly on the host.

Architecture and authority boundary

  1. Declaration: contract + YAML requirements.
  2. Handoff: shared experiment prompt plus optional operator guide.
  3. Planning: Goose is the native reference operator; other agents use adapters.
  4. Resolution: Go resolves requirements against registered profiles and fails closed on ambiguity.
  5. Policy: Go evaluates authority and approval gates and audits decisions.
  6. Execution: capabilities operate Lima/QEMU and fixed workload handlers.
  7. Evidence: collect, hash, independently verify, report, preserve, then destroy disposable compute.

Boundary rule: the agent decides what research to do; Cusimanse decides whether and how it may execute.

Researcher workflow

1. Contract and requirements

Write contracts/<experiment>.md with research question, authorization, scope, acceptance criteria and safety constraints. Declare only requirements in recipes/experiments/<experiment>.yaml.

Example:

requirements:
  execution: disposable
  os: linux
  workload: npm-threat
  network: localhost-only
  instrumentation: [process, syscall, filesystem, network]

2. Bootstrap and deterministic validation

./scripts/install.sh
export PATH="$HOME/.local/bin:$HOME/go/bin:$PATH"
cusimanse doctor
cusimanse validate
cusimanse preflight
cusimanse policy validate
cusimanse test
cusimanse integration-test

3. Validate and run the Goose recipe

goose recipe validate recipes/npm-threat-001/recipe.yaml
goose recipe validate recipes/subrecipes/evidence-analysis.yaml
goose recipe validate recipes/subrecipes/verification.yaml
goose recipe validate recipes/subrecipes/report.yaml
goose run --recipe ./recipes/npm-threat-001/recipe.yaml --interactive

The recipe explicitly declares the summon platform extension. Summon provides delegation/orchestration only; it does not authorize execution.

4. Resolve and approve

cusimanse resolve npm-threat-001
cusimanse policy explain vm
cusimanse policy explain network
cusimanse policy check-all
cusimanse policy require vm --approved

5. Execute and finish

cusimanse --approved run npm-threat-001 <session-id>
cusimanse observability report <session-id>
cusimanse policy audit

Lifecycle: resolve → policy → provision → configure → instrument → execute → collect → verify → report → preserve → destroy.

Prompt library and agent handoff

The prompt is a handoff, not an authority layer and not a second recipe.

prompts/experiments/<experiment>.md       shared research handoff
prompts/operators/<operator>.md           thin operator guidance
recipes/experiments/<experiment>.yaml     requirements source of truth
recipes/<experiment>/recipe.yaml          Goose/runtime recipe
contracts/<experiment>.md                 authorization/scope source

For OpenCode, Hermes, Antigravity or Pi, provide the same contract, experiment YAML, recipe references, shared prompt and matching operator guide. The alternate operator may plan/delegate/analyze using its native features, but must invoke Cusimanse for capability execution. Unsupported capabilities are recorded as PARTIAL; adapters cannot mutate policy, profiles or trusted recipes.

Download Tool