Cawght 作者: Rajan Yadav
Record your app, let AI find where the business logic breaks.
扩展元数据
关于此扩展
Description:
Cawght watches how your web app behaves, then tries to break its business rules.
Traditional security scanners catch XSS and SQL injection — but they don't know that your discount code should only work once, that only admins can delete posts, or that User A shouldn't access User B's data. Cawght does.
How it works:
1. Open the sidebar and click Start Recording.
2. Use your web app normally — browse, click, submit forms.
3. Click Stop & Test — Cawght analyzes the captured traffic.
4. AI generates adversarial test scenarios targeting business logic.
5. Tests run automatically and findings are reported with evidence.
What it catches:
* Privilege escalation
* IDOR (Insecure Direct Object Reference)
* State manipulation
* Business constraint violations
* Data isolation failures
Privacy & Requirements:
* Bring your own AI key (Gemini, OpenAI, or Anthropic).
* No data is collected without your explicit action.
Cawght watches how your web app behaves, then tries to break its business rules.
Traditional security scanners catch XSS and SQL injection — but they don't know that your discount code should only work once, that only admins can delete posts, or that User A shouldn't access User B's data. Cawght does.
How it works:
1. Open the sidebar and click Start Recording.
2. Use your web app normally — browse, click, submit forms.
3. Click Stop & Test — Cawght analyzes the captured traffic.
4. AI generates adversarial test scenarios targeting business logic.
5. Tests run automatically and findings are reported with evidence.
What it catches:
* Privilege escalation
* IDOR (Insecure Direct Object Reference)
* State manipulation
* Business constraint violations
* Data isolation failures
Privacy & Requirements:
* Bring your own AI key (Gemini, OpenAI, or Anthropic).
* No data is collected without your explicit action.
评分 0(1 位用户)
权限与数据
必要权限:
- 获取浏览器标签页
- 获知浏览器导航时的行为状态
- 访问您在所有网站的数据
可选权限:
- 访问您在所有网站的数据
根据开发者所述,必要的数据收集:
- 网站活动
根据开发者所述,可选的数据收集有:
- 技术和交互数据
更多信息
- 版本
- 2.1.1
- 大小
- 1.09 MB
- 上次更新
- 2 个月前 (2026年3月30日)
- 相关分类
- 许可证
- 保留所有权利
- 隐私政策
- 阅读此附加组件的隐私政策
- 版本历史
- 添加到收藏集