OMU-2026·scope: enforcing·engines: onlineauthorized operations only

Autonomous security operations

An AI operator that runs authorized assessments end to end

Omukuumi is a security expert that lives in your terminal: it scopes, plans, and executes web, API and network assessments, captures evidence, and writes the report — inside the boundaries you authorize.

Scope-first · rule-checked · evidence-backed

Web & API

OWASP · authz · BOLA · JWT

Network

assets · services · segmentation

Threat intel

IOC · CVE correlation

Fintech

payments · webhooks · mobile money

Field procedure

Four steps, none of them optional

  1. 01

    Authorize the scope

    Every Omukuumi session starts with a written scope — domains, networks, exclusions, expiry. Nothing runs outside it.

  2. 02

    Plan the assessment

    The agent reads the environment, builds a test plan, and decides which tools belong to which phase.

  3. 03

    Execute under policy

    Each tool call is checked against scope, risk, and approval rules. Evidence is captured before anything runs.

  4. 04

    Report findings

    Observed behavior becomes evidence, evidence becomes findings, findings become the report.

The operator console

Command it from the terminal. Observe it from anywhere.

The TUI is the cockpit for serious work: live activity, approvals, findings. The dashboard mirrors the same state — assessments, licenses, and operations in one place.

FINDINGS

evidence → finding → report

SCOPE

enforced on every tool call

APPROVAL

human-in-the-loop when it matters

Honest positioning

What Omukuumi is not

  • A memorized checklist disconnected from what the API actually does

  • Scanners that produce a list of CVEs instead of findings you can act on

  • An AI that can run anything, everywhere, with no concept of authorization

Start with an authorized scope.

Create an assessment, add your targets, and let Omukuumi plan the work — every action inside the lines you draw.