Autonomous security operations
An AI operator that runs authorized assessments end to end
Omukuumi is a security expert that lives in your terminal: it scopes, plans, and executes web, API and network assessments, captures evidence, and writes the report — inside the boundaries you authorize.
Scope-first · rule-checked · evidence-backed
Web & API
OWASP · authz · BOLA · JWT
Network
assets · services · segmentation
Threat intel
IOC · CVE correlation
Fintech
payments · webhooks · mobile money
Field procedure
Four steps, none of them optional
- 01
Authorize the scope
Every Omukuumi session starts with a written scope — domains, networks, exclusions, expiry. Nothing runs outside it.
- 02
Plan the assessment
The agent reads the environment, builds a test plan, and decides which tools belong to which phase.
- 03
Execute under policy
Each tool call is checked against scope, risk, and approval rules. Evidence is captured before anything runs.
- 04
Report findings
Observed behavior becomes evidence, evidence becomes findings, findings become the report.
The operator console
Command it from the terminal. Observe it from anywhere.
The TUI is the cockpit for serious work: live activity, approvals, findings. The dashboard mirrors the same state — assessments, licenses, and operations in one place.
FINDINGS
evidence → finding → report
SCOPE
enforced on every tool call
APPROVAL
human-in-the-loop when it matters
Honest positioning
What Omukuumi is not
A memorized checklist disconnected from what the API actually does
Scanners that produce a list of CVEs instead of findings you can act on
An AI that can run anything, everywhere, with no concept of authorization
Start with an authorized scope.
Create an assessment, add your targets, and let Omukuumi plan the work — every action inside the lines you draw.