Black box, grey box or white box: how much a pentest gets to see.
A URL, a set of logins or the repository. Each one lets the agent reach further into the application, and all three are held to the same rule: nothing is reported until it is proven against the running app.
One agent, three starting points.
What you hand over decides where the test starts. The agent, the standard of proof and the report stay the same.
A URL, and what an outsider can reach.
The agent maps what is reachable from the internet, follows every route it can find and registers its own account where signup is open. It answers one question precisely: what can someone with no access and no inside knowledge get to?
- Only the target URL to set up
- Its own accounts wherever signup is open
The token from a completed reset, replayed two hours later:
Logins for the roles that matter.
Add test accounts as headers or a cookie jar and the agent tests everything behind the login. With two roles or two tenants it can be both at once, which is how one customer reading another customer's data gets caught.
- Bearer tokens, API keys or session cookies, encrypted at rest
- Where broken access control turns up
The repository, read after the exploit.
Connect GitHub, GitLab or Bitbucket. The agent still proves each finding against the running application, then reads the code behind it, so the finding names the file and the line and the fix arrives as a pull request. Committed secrets and the dependencies you ship come into scope as well.
- Against your deployment, or one built from the repository
- Everything black box and grey box reach, plus the source

The handler joins the query parameter onto the upload directory without normalising it:
What each one needs, and what comes back.
Each step keeps everything the one before it reaches. Moving from black box to white box loses nothing.
Pick by what you can share.
The mode is set per run, so one application can run more than one of them.
You have the source
Run white box. It covers everything the other two reach and adds the code path, committed secrets, dependencies and the fix as a pull request.
You have logins, but not the code
Run grey box. A vendor application, a partner's API or a system whose repository sits with another team: test accounts still reach everything a signed-in user can.
You have only a URL
Run black box for the outsider's view of your public surface, or as a first run before test accounts or a repository are connected.
Questions, answered.
Start with a URL. Add logins and the repository later.
A URL is enough for the first run. Add test accounts or connect the repository whenever you are ready, and the next run reaches further.
