PentestHub AI — Master Specification
This is the canonical Master Specification for PentestHub AI. All architecture, module, and roadmap decisions must trace back to this document. Do not fork or rewrite this file casually — amend it deliberately as the product evolves.
Core Philosophy
The platform must become the daily workspace of every pentester.
Users should no longer need to constantly switch between:
- HackerOne
- Bugcrowd
- Intigriti
- GitHub
- Burp Suite documentation
- PayloadAllTheThings
- HackTricks
- NVD
- CVE databases
- OWASP
- Google searches
- ChatGPT
Everything should exist inside one unified ecosystem.
Local-First Core Principle
Added 2026-07-16, superseding the implicit "backend executes everything" assumption in every section below that predates it. Full audit, decision record, and build plan:
docs/migration/local-first-architecture-migration.md,docs/adr/0007-local-first-desktop-agent-architecture.md,docs/migration/desktop-agent-roadmap.md.
PentestHub AI is local-first. The backend must never be responsible for expensive computation. It exists only for: Authentication, User accounts, Workspace/Project/Target/Note metadata, Findings metadata, Activity timeline, Team collaboration, API keys, Preferences, Reports metadata, Synchronization, Notifications, RBAC, and Audit logs.
All computationally expensive work — Recon and Vulnerability tool execution, AI inference, local storage, file indexing, voice processing, local RAG, and report/PDF/Markdown/DOCX generation — runs in a new Desktop Agent (Tauri preferred; Electron acceptable only if a required capability has no workable Tauri equivalent), targeting Windows, Linux, and macOS.
Key rules that follow from this:
- Private target/finding/evidence data never leaves the user's machine unless the user explicitly opts into sync.
- AI never requires PentestHub's own API keys — every user brings their own provider (OpenAI, Anthropic, Gemini, OpenRouter, Ollama, LM Studio, DeepSeek, Mistral, Groq, Azure OpenAI), defaulting to local Ollama with no key, and degrading gracefully (never crashing) if Ollama is also unavailable.
- Voice is local-first (Web Speech API primary; Whisper.cpp/Piper TTS as Desktop Agent fallbacks) — cloud TTS/STT is optional, never required.
- RAG is local only (SQLite+embeddings or LanceDB) — no mandatory cloud vector database, no private data uploaded without opt-in.
- Sync is user-selectable: Off / Metadata-Only (default) / Everything.
- Offline mode works for workspace/projects/notes/findings/recon/ scanning/reports/local AI/voice/search.
- Free tier is unlimited for everything that runs locally (Projects, Targets, Recon, Scans, Reports, Markdown/PDF export, Local AI, Voice, the Desktop Agent itself). Premium unlocks only Cloud Sync, Team Collaboration, Cloud Backup, Advanced Analytics, Priority Queue, Organization Features, and Enterprise Integrations — users never pay to scan locally.
This principle is being retrofitted onto Modules 1-6 via a phased, strangler-fig migration (see the roadmap doc) that preserves existing API contracts and does not break the current web UI. As of this writing, no migration code has shipped yet — Modules 3-6 still execute tool runners, AI calls, RAG, voice, and report rendering server-side, tracked as violations to fix in the roadmap's phases. See the audit doc's module-by-module findings for specifics.
Target Users
- Bug Bounty Hunters
- Penetration Testers
- Red Teamers
- Security Engineers
- Students
- CTF Players
- SOC Analysts
- DevSecOps Engineers
Platforms
Build everything from a single codebase where possible.
Required:
- Responsive Website
- Progressive Web App (PWA)
- Android Application
- iOS Application
- Windows Desktop
- macOS Desktop
- Linux Desktop
Prefer Flutter for mobile/desktop and a modern web framework for the web.
Authentication
Support:
- Google OAuth
- GitHub OAuth
- Email Registration
- Login
- Remember Me
- Email Verification
- Password Reset
- Change Password
- MFA / Two-Factor Authentication
- Session Management
- Device Management
User Dashboard
Each user has:
- Personal Workspace
- Saved Payloads
- Saved Notes
- Saved Reports
- Saved Targets
- Saved Recon Data
- Saved CVEs
- Saved Tools
- Recent Activity
- Favorites
- API Keys
- Notification Center
AI Assistant
Note: Built as Module 5 — AI Security Copilot — Phase 1 and Phase 2 both done (backend "brain": workspace/project-aware chat with automatic context gathering, RAG over pgvector, a 5-provider abstraction — OpenAI, Anthropic, Gemini, Ollama, OpenRouter — switchable by configuration with no keys wired yet, an editable prompt-module architecture, tool calling — search findings/recon/ evidence/notes/projects/targets/templates, create note, draft report, generate PoC, generate payloads — SSE token streaming with cancel/regenerate/continue, prompt-injection guardrails, and strict workspace/project isolation; frontend:
/aidashboard with conversation history, context indicator, suggested questions, streaming chat, Markdown rendering). Phase 2 (the "UX layer") adds: Voice Interaction (Web Speech API mic input + text-to-speech message playback, plus a backendSpeechProviderabstraction with 4 unconfigured cloud adapters — OpenAI, Azure, Google, ElevenLabs — same "ships complete, wired later" posture as the chat providers), a Smart Code Block toolbar (language badge, one-click download, wrap toggle, expand/collapse, fullscreen view), One-Click Code/Conversation Export (per-message download plus whole-conversation Markdown export), Terminal Mode (a monospace/dark toggle view for the whole conversation), Artifact Mode (a dedicated side panel for substantial generated content — PoCs, payload sets, draft reports — decoupled from the chat bubble), and Interactive Canvas (pannable/zoomable Mermaid diagram rendering forRendering diagram…
Integrate a powerful AI assistant.
The AI must understand cybersecurity.
Capabilities:
- Explain vulnerabilities
- Explain CVEs
- Generate payloads
- Analyze Burp requests
- Analyze HTTP responses
- Analyze Nmap output
- Analyze Nikto output
- Analyze ffuf output
- Analyze nuclei output
- Generate exploit ideas
- Explain exploit chains
- Create pentest reports
- Explain code
- Analyze JavaScript
- Decode JWT
- Decode Tokens
- Explain APIs
- Suggest next attack surface
- Help with CTFs
- Summarize writeups
Never hallucinate technical facts. Clearly distinguish verified facts from suggestions.
Voice Assistant
Note: Built as part of Module 5's AI Security Copilot, Phase 2. A
SpeechProviderbackend interface (apps/api/src/modules/ai/speech/) with 5 adapters — WEB_SPEECH (a documented client-side marker, always "configured") plus 4 real, unconfigured-until-keyed cloud adapters (OpenAI Whisper+TTS, Azure Speech, Google Speech, ElevenLabs TTS-only), surfaced viaGET /ai/speech/providers. The only backend actually reachable today is the frontend's own Web Speech API integration (apps/web/features/ai/hooks/use-ai-voice.ts): a mic button appends recognized speech into the chat input (SpeechRecognition), and a Speak/Stop Speaking message action reads assistant replies aloud (speechSynthesis) — both degrade to hidden buttons on browsers without support (e.g. Firefox has no SpeechRecognition) rather than erroring. Seedocs/adr/0005-ai-security-copilot-module.md.
Support speech recognition.
Users can say:
"Analyze this request."
"Generate XSS payload."
"Explain this CVE."
"Open Recon."
"Create report."
"Search CVE."
Support voice replies where available.
Pentesting Workspace
Provide projects.
Each project contains:
Targets
Subdomains
Notes
Screenshots
Payloads
Credentials
Reports
Timeline
Bookmarks
Files
Tasks
Collaborators
Recon Module
Include:
WHOIS
DNS
Subdomain Enumeration
ASN Lookup
Technology Detection
HTTP Headers
robots.txt
sitemap.xml
Wayback URLs
Security Headers
TLS Analysis
Directory Discovery
Port Information
Fingerprinting
Visual Screenshots
Vulnerability Tools
Note: "Module 4" in the rollout order below was redefined by the project owner into the Vulnerability Engine (external scanner orchestration — Nuclei/ffuf/dirsearch/feroxbuster/Nikto — producing validated Findings; see
docs/adr/0004-vulnerability-engine-module.md), not the client-side payload/encoder toolbox described in this section. The toolbox below remains an unimplemented, unscheduled idea, kept here for future reference.
Include:
Reverse Shell Generator
Payload Generator
SQL Injection Payloads
XSS Payloads
SSTI Payloads
Command Injection Payloads
LFI Payloads
RFI Payloads
XXE Payloads
SSRF Payloads
JWT Decoder
JWT Editor
JWT Generator
Hash Identifier
Hash Generator
Password Generator
URL Encoder
URL Decoder
Base64
Hex
Binary
Unicode
Regex Tester
JSON Formatter
XML Formatter
YAML Formatter
HTTP Formatter
Cookie Parser
Request Parser
Response Parser
Header Analyzer
CSP Analyzer
CORS Analyzer
JWT Cracker (only for authorized testing)
Wordlist Generator
Fuzz Helper
Bug Bounty Workspace
Support:
Target Notes
Scope Tracking
Program Notes
Recon Notes
Custom Checklist
Evidence
Screenshots
Findings
Severity Calculator
CVSS Calculator
Timeline
Submission History
Templates
Duplicate Detection
Markdown Editor
Report Generator
Generate professional reports.
Support:
Markdown
HTML
DOCX
Executive Summary
Technical Details
Risk Rating
Mitigation
Screenshots
Evidence
CVSS
OWASP Mapping
CWE Mapping
Knowledge Base
Include searchable resources for:
OWASP
HackTricks
Payload references
Cheat Sheets
Ports
Protocols
HTTP Status Codes
Linux Privilege Escalation
Windows Privilege Escalation
Active Directory
Cloud Security
Web Security
API Security
Mobile Security
Wireless Security
Cryptography
Reverse Engineering
Malware Analysis
Red Team
Blue Team
MITRE ATT&CK
CVE Center
Provide:
CVE Search
Filters
CVSS
Affected Products
References
Exploit Links
Patch Status
Vendor Links
Timeline
Integrations
Support integrations with services such as:
GitHub
Google Drive
Discord
Slack
Webhook endpoints
Email notifications
Calendar reminders
UI/UX
Modern dark-first interface.
Responsive.
Fast.
Keyboard shortcuts.
Command Palette.
Global Search.
Dockable panels.
Resizable layouts.
Professional dashboards.
Security
Use:
JWT with refresh tokens
Rate limiting
CSRF protection
CSP
Input validation
Secure headers
Encrypted secrets
Audit logging
Role-based access control
Secure file uploads
Session expiration
Account lockout after repeated failures
Admin Panel
Manage:
Users
Reports
Subscriptions
Feature flags
Analytics
Logs
Announcements
Support tickets
System health
API usage
Future Features
Team collaboration
Shared workspaces
Private organizations
Marketplace
Plugin SDK
Extension system
Browser extension
CLI tool
Public REST API
GraphQL API
Offline mode
AI automation workflows
Code Quality
Produce production-ready code.
Use clean architecture.
Use modular design.
Follow SOLID principles.
Write tests.
Document APIs.
Avoid duplicated code.
Ensure accessibility.
Optimize for performance and maintainability.
Every feature should be designed so that additional tools and integrations can be added without major refactoring.
Build Process (binding rule)
Never write the entire project at once. Always:
- Plan first.
- Build exactly one module at a time.
- Finish a module (production-ready, tested, documented) before starting the next.
- Every module must ship with tests and documentation before being considered done.
Locked Architecture Decisions
These decisions were made explicitly with the project owner and take precedence over the open-ended "prefer X" language above where they conflict.
| Area | Decision |
|---|---|
| Repo structure | Monorepo (Turborepo) at ~/pentesthub-ai |
| Web frontend | Next.js (React, TypeScript) |
| Backend API | Node.js / NestJS (TypeScript) |
| Mobile/Desktop | Flutter (deferred until web core is stable) |
| First module | Auth (email + Google/GitHub OAuth) + Dashboard shell |
Monorepo layout (actual, as of scaffold)
pentesthub-ai/
├── PROJECT_SPEC.md
├── turbo.json
├── pnpm-workspace.yaml
├── apps/
│ ├── web/ # Next.js 16 (React 19, TS) frontend
│ └── api/ # NestJS 11 (TS) backend
├── packages/
│ ├── shared/ # shared types / DTOs (@pentesthub/shared)
│ ├── ui/ # shared design system / components (@pentesthub/ui)
│ ├── eslint-config/ # shared eslint flat configs (@pentesthub/eslint-config)
│ └── typescript-config/ # shared tsconfig bases (@pentesthub/typescript-config)
└── docs/
└── modules/ # per-module design docs, ADRs
Package manager: pnpm (workspaces). Task runner: Turborepo (build, lint,
check-types, test, dev pipelines all verified working end to end).
Module rollout order (subject to revision after each module ships)
- Auth (Module 1) — done (NestJS API: register, email verification,
login, logout, JWT + refresh-token rotation with reuse detection,
argon2 password hashing, forgot/reset/change password, Google/GitHub
OAuth, TOTP MFA + backup codes, RBAC foundation, session/device
management, audit logging, rate limiting, Swagger docs, seed data.
See
docs/modules/01-auth.mdanddocs/adr/0001-auth-module.md). - Workspace Foundation + Dashboard UI (Module 2) — done (backend:
Workspaces, Projects, Targets, Notes, Evidence, Attachments, Tags,
event-driven Activity Timeline, Search — all domain-agnostic storage,
no Recon/AI logic attached; frontend: full Next.js dashboard covering
Module 1 auth UI plus every Module 2 resource, Settings, command
palette, dark-mode-first responsive shell. See
docs/adr/0002-workspace-foundation-module.md). - Recon Module (Module 3) — done (backend: 14 tools — Subfinder,
Amass, Assetfinder, HTTPX, Katana, Gau, Waybackurls, DNSx, Naabu, Nmap,
WhatWeb, Gowitness, WHOIS, ASN lookup — behind one
ToolRunner/Normalizerabstraction, a distributed-worker-safe job queue with atomic claiming/retry/cancel/orphan-sweep, a polymorphicReconFindingmodel with dedup-key + unique-constraint deduplication, "Promote Finding to Target," SSE live logs; frontend: job list/detail/progress/ findings UI integrated into the target and project pages plus a workspace-wide/reconlanding page. Seedocs/adr/0003-recon-engine-module.md). - Vulnerability Engine (Module 4) — done. Redefined from this
document's original "Vulnerability Tools" placeholder (a client-side
encoder/payload-generator toolbox) into a full scanner-orchestration
engine per explicit direction from the project owner: Recon Assets →
Scan Jobs → external scanners (Nuclei, ffuf, dirsearch, feroxbuster,
Nikto behind one
ScannerRunner/Normalizerabstraction, extension points reserved for SQLMap/XSStrike/Dalfox/Wapiti/OWASP ZAP) → normalizedVulnFindings (severity/CVSS/CWE/OWASP category, dedup-key- unique-constraint deduplication, auto-attached text Evidence) → Scan
Queue with Pause/Resume/Cancel/Retry/Priority/Worker Heartbeat/Dead
Worker Recovery → Activity Timeline → events reserved for a future AI
hook. The original "Vulnerability Tools" payload/encoder toolbox this
section used to describe is not built and isn't currently on the
roadmap under that name; the encoder/JWT/hash-utility items listed
above this section remain unimplemented client-side utilities, not
part of Module 4. See
docs/adr/0004-vulnerability-engine-module.md.
- unique-constraint deduplication, auto-attached text Evidence) → Scan
Queue with Pause/Resume/Cancel/Retry/Priority/Worker Heartbeat/Dead
Worker Recovery → Activity Timeline → events reserved for a future AI
hook. The original "Vulnerability Tools" payload/encoder toolbox this
section used to describe is not built and isn't currently on the
roadmap under that name; the encoder/JWT/hash-utility items listed
above this section remain unimplemented client-side utilities, not
part of Module 4. See
- Bug Bounty Workspace (Module 6) — done. Merges this document's
original "Bug Bounty Workspace" and "Report Generator" placeholders into
one module, the same way Module 4 absorbed "Vulnerability Tools":
Programs (platform/status/rules/severity-matrix/disclosure policy) with
a Scope Manager (9 scope-item types, IPv4 CIDR/range auto-classification,
OUT_OF_SCOPE-wins-over-IN_SCOPE), a Program Importer (HackerOne/Bugcrowd/
Intigriti/Markdown/JSON), a read-through Asset Inventory over Targets +
Recon/Vuln findings + Notes/Evidence (no new storage), a Finding
Lifecycle stage machine (New → Triaged → Verified → Reported → Resolved
→ Closed → Archived, plus Duplicate/Need More Info side-branches), a Bug
Report Generator (one persisted report rendered into 5 platform
templates, PDF/Markdown/HTML/JSON/CSV export) with an AI Report Draft
Assistant and lexical+semantic Duplicate Detection (both reusing Module
5's AI seam), a Payload Library (16 categories, seed + custom entries,
AI explain), a Personal Knowledge Base, Bookmarks, a Dashboard +
Statistics view, a Calendar with a self-scheduling deadline-notifier
poller, Notifications, and Global Search — plus this codebase's first
use of optimistic locking (on
BugReport.version). Frontend: 11 pages under/bugbounty. Seedocs/adr/0006-bug-bounty-workspace-module.mdanddocs/releases/module-6-release-notes.md. - AI Assistant integration (Module 5) — Phase 1 and Phase 2 done.
Built as the "AI Security Copilot": workspace/project-aware AI Chat
with automatic context gathering (no manual pasting), a RAG layer over
pgvector (per-workspace/per-project isolated memory), a 5-provider
abstraction (OpenAI/Anthropic/Gemini/Ollama/OpenRouter — switchable by
config, no keys wired yet per explicit direction), an editable
prompt-module architecture (system/security/recon/finding-analysis/
report/coding, never hardcoded in controllers), a provider-agnostic
tool-calling framework (search findings/recon/evidence/notes/projects/
targets/templates, create note, draft report, generate PoC, generate
payloads) built to be extended by future modules without touching the
chat engine, SSE token streaming with cancel/regenerate/continue,
prompt-injection guardrails, and workspace/project isolation enforced
on every command/query. Frontend:
/aidashboard (conversation history, context indicator, suggested questions, streaming chat, Markdown rendering). Phase 2 adds the "UX layer": Voice Interaction (Web Speech API mic input + speak-aloud replies, backed by aSpeechProviderabstraction with 4 unconfigured cloud adapters), a Smart Code Block toolbar (language badge, download, wrap, expand/ collapse, fullscreen), One-Click Code/Conversation Export, Terminal Mode, Artifact Mode (a dedicated side panel for substantial generated content), and Interactive Canvas (pannable/zoomable Mermaid diagrams). Seedocs/adr/0005-ai-security-copilot-module.md. - CVE Center
- Knowledge Base (workspace-wide/cross-project — distinct from Module 6's per-user Personal Knowledge Base, which is done)
- Admin Panel
- Integrations, Voice Assistant, Mobile/Desktop (Flutter), Marketplace/Plugin SDK
Note on items 7-10 above and this list's staleness: items 7-10 are the original placeholder text and predate Modules 7-16 actually being built — they were not updated as those modules shipped and no longer reflect this project's real status (e.g. Mobile/Desktop exist as Modules 12/7, not as item 10's vague placeholder). A full rewrite of this section to match the project's actual module history was judged a separate, larger task and was not attempted as part of Module 16's documentation pass. For authoritative per-module status, see
docs/releases/module-{N}-release-notes.mdfor Modules 2, 4, 5 (phase 1 & 2), 6, 9, 10, 11, 12, 13, 14, 15, 16, and 17 — the most recent, which covers Global Security Intelligence, the Bug Bounty platform (submissions/rewards, Safe Terminal, Playbooks, Risk Engine, CVE matching), and Collaboration (Watchers/Reactions, a real-time SSE gateway, Public Sharing, Knowledge Graph queries, AI Memory, and an Extension API Registry). Mobile, Desktop Agent, and Browser Extension updates for Module 16 were explicitly deferred by user decision and are not part of it. Module 17 (docs/releases/module-17-release-notes.md) covers the Security Operations Center — attack surface monitoring, a Community Edition-friendly Threat Intelligence Engine (public-feed adapter + manual STIX/TAXII import), Incident Management with an AI-assisted investigation workflow, Remediation tracking, an SLA Engine, Risk Engine v2, and the composed SOC/Executive Security dashboards — again reusing the existing EventBus, graph, Evidence, execution-engine, report, and search infrastructure rather than duplicating any of it. See alsodocs/soc.md,docs/threat-intelligence.md,docs/incidents.md,docs/remediation.md,docs/risk.md, anddocs/sla.mdfor per-surface detail. Module 18 (docs/releases/module-18-release-notes.md) adds no product features — it is a production-hardening, observability, and reliability pass across Modules 1-17: request correlation, structured logging, health/readiness endpoints, job-queue race/idempotency fixes, SSRF/ rate-limiting/file-storage security audits, AI prompt-injection regression tests, SSE hardening, Prometheus metrics + Alertmanager config, backup/recovery documentation, frontend security headers, a dependency audit, CLI/SDK/Desktop/Mobile reliability fixes, new security-critical and disaster-recovery regression tests, and a final grep-based security sweep. See that release-notes file's "Known gaps" section for every issue this module found and disclosed rather than fixed.Post-Module-18 reconciliation checkpoint (2026-09-08,
docs/reviews/0021-post-m18-sdk-reconciliation.md): Module 18's dependency audit (Phase 22) had claimedpackages/sdk-pythonandpackages/sdk-go"do not actually exist in this repository," despite earlier module task histories (Module 16's #402/#429, Module 17's #491) reporting Python/Go SDK work as complete. A dedicated audit against the repository itself (not against prior reports) found that claim was wrong: both SDKs exist, complete and at full 14-resource parity with the TypeScript SDK, atsdks/pythonandsdks/go— a different path than the one Phase 22 checked, established since Modules 7-10. The earlier module task histories were accurate; Phase 22's audit methodology (checking one path convention and concluding absence without searching further) was the error, and has been corrected in place indocs/reviews/0014-m18-dependency-security-audit.mdanddocs/releases/module-18-release-notes.mdrather than silently rewritten. Two small, real, previously-undisclosed gaps were found and fixed during this checkpoint: the Go SDK's HTTP transport had no request timeout (http.DefaultClient, same defect class Module 18 had already fixed in the TypeScript SDK — corrected to a 30s default, unverified bygo build/go testsince the Go toolchain remains unavailable in this sandbox, consistent with every prior module); and.github/dependabot.ymlwas missingpip/gomodentries for the two SDKs (added). Both SDKs' READMEs had a stale pre-Module-16 "Scope (v1)" list (corrected). The Python SDK was verified for real in this pass:python3 -m compileallclean, andpython3 -m unittest tests.test_client -v— 5/5 tests genuinely passed in this sandbox.
Local-first migration status (2026-07-16): per the Local-First Core Principle above, Modules 3-6 as described in this list still execute server-side today. Module 3's 14 tool runners and Module 4's 5 scanner runners are slated to move entirely into the new Desktop Agent (backend keeps only job/result metadata, history, activity, and stats). Module 5's provider execution currently uses server-configured keys (a violation, fixed first in the migration's Phase 1), and its RAG (pgvector) and voice (cloud speech adapters) are slated to move to a local vector store and Whisper.cpp/Piper respectively. Module 6's Bug Report template rendering is slated to move client-side (Markdown/HTML/ PDF/DOCX generated locally, only report metadata synced); its AI Draft Assistant and semantic Duplicate Detection inherit Module 5's move. Item 10's "Mobile/Desktop (Flutter)" placeholder is superseded by the Tauri Desktop Agent decision in ADR 0007 for the desktop portion specifically (mobile remains open). Full detail:
docs/migration/local-first-architecture-migration.md,docs/adr/0007-local-first-desktop-agent-architecture.md,docs/migration/desktop-agent-roadmap.md.Module 7 — Desktop Agent (2026-07-19): source-complete. The Tauri desktop app at
apps/desktopnow has its own Local Tool Runner (16 tools), Background Job Queue, local SQLite database, Sync Engine (Off/Metadata-Only/Everything, conflict resolution, retry queue, multi-workspace), Local AI (9 providers, streaming, tool calling), Local RAG (FTS5 + embeddings, fully offline), Voice (Web Speech API + whisper.cpp/Piper fallback), File Manager/Evidence Library (SHA-256 dedup, Folder Watch), Report Generator (PDF/MD/HTML/DOCX/TXT/JSON/ZIP, all local), a full Desktop AI Chat, a Plugin Manager (Nmap/Burp/ZAP/ Metasploit/Custom Script), and Settings/Auto-Update/Security. This fulfills the "Modules 3/4/6 move client-side" migration items described above. Not yet compiled/runtime-verified — seedocs/modules/07-desktop-agent.md's "Verification handoff" section.Module 8 — Browser Extension + Burp Suite Integration (2026-07-20): source-complete. A new Local Bridge Server (
apps/desktop/src-tauri/src/bridge/) gives the Module 7 Desktop Agent a real127.0.0.1-only, bearer-token-authenticated, AES-256-GCM-encrypted HTTP+WebSocket API, since Tauri'sinvoke()IPC is unreachable from outside its own webview. A Manifest V3 Browser Extension (apps/browser-extension, Chrome/Edge/Brave/Opera + a Firefox build) talks to it for Target Capture (19 one-click actions), Recon Shortcuts (7), an AI Side Panel (11 quick actions, streaming Markdown/Mermaid/voice), a DevTools panel (8 tabs), a 12-category/ 35-entry Payload Library, 6-format Export, and Bug Bounty scope import (HackerOne/Bugcrowd/Intigriti/YesWeHack/Synack). A Burp Suite extension (extensions/burp, Jython/legacy Extender API — Community + Pro compatible) adds the same capture/finding/AI-context actions from Burp's context menu. Sensitive-data capture (cookies, storage, tokens) requires explicit confirmation, enforced both client-side and server-side. Live Sync keeps the current Project/Target/Conversation in sync across the desktop app, browser, and Burp via a WS ping + REST snapshot protocol. Not yet compiled/runtime-verified (no browser, Burp Suite, or completednpm installin the build environment) — the pure-logic TypeScript modules and the cross-language AES-256-GCM/HKDF crypto were independently verified via direct Node execution; seedocs/modules/08-browser-extension.md's "Verification handoff" section anddocs/adr/0008-browser-extension-burp-integration.md.Module 9 — Bug Bounty Platform + Collaboration + Reporting Suite (2026-07-20): source-complete. Extends Module 6's per-hunter workflow into a full team platform: a multi-platform Program Manager (favorite/safe-harbor/rate-limits) with an update-detecting Program Importer (SHA-256 fingerprint + human- readable diff, never destructively reclassifies existing scope on reimport), Scope Manager asset-type/status extensions, a Finding Manager with a real CVSS 3.1 calculator plus CWE/CAPEC/OWASP/MITRE ATT&CK mapping, a Report Builder with custom templates, AI grammar correction and technical review, and a TXT export (DOCX disclosed as unimplemented — no document-generation dependency installed); a new Collaboration layer (workspace invites, 3 new roles slotting between ADMIN and MEMBER, comments with @mentions, assignments, task lists, a read-through activity feed); 7 new Bug Bounty Dashboard widgets; an AI Bug Bounty Assistant (9 capabilities — review/payloads/PoC/repro/ impact/remediation/severity/attack-paths/engagement-summary, all "propose, don't auto-apply"); Knowledge Base entry kinds (playbooks, CVE references, tool references, AI conversation snapshots) plus tagging; scheduled Automation jobs; multi-channel Notifications (Discord/Slack/Telegram/custom API/webhook/email — email disclosed as unimplemented, no provider configured) with AES-256-GCM-encrypted channel secrets; a filterable Analytics rollup distinct from Module 6's Statistics; Global Search extended to AI chats/tags/tasks; a Public REST API (personal/workspace API keys, HMAC-signed webhooks, rate limiting, OpenAPI); and a security-hardening pass that closed a plaintext-secret gap on
WebhookToken/NotificationChannelConfig, fixed two pre-existingAuditEventTypeimport bugs, added the missingWORKSPACE_MEMBER_*audit-trail writes, and documented the full Permission Matrix. Frontend and a fullapps/apitypecheck/test run were not independently re-verified in the sandbox this module was built in (the same environment constraint noted for Modules 7-8); all changes were reviewed by hand against the exact repository-interface signatures they call, andpackages/shared's typecheck was re-run clean after every shared-type change. Seedocs/adr/0009-bug-bounty-operating-system.md,docs/modules/09-bug-bounty-operating-system.md, anddocs/security/permission-matrix.md.Module 10 — Enterprise Platform + SaaS + Global Infrastructure (2026-07-22): source-complete. The largest module by scope to date — fourteen subsystems: real multi-tenant
Organization/Teamabove the existingWorkspaceboundary (additive, doesn't replace it); a Postgres-native claim-based Distributed Job System (no new message broker); a Plugin Marketplace with a permission-acceptance model (sandboxing is contractual today, not a separate execution runtime — disclosed follow-up before accepting untrusted third-party plugins); an Integrations framework routing every provider action through one generic executor; Team Workspaces; Enterprise Reporting/Analytics reusing Module 6/9's rendering patterns; a full API Platform (GraphQL, an expanded real webhook delivery pipeline with retry/backoff/dead- letter, and TypeScript/Python/Go SDKs — a cross-reference audit mid- module caught and fixed several drifted fields in the Go SDK); a Workflow Automation Engine (nine step kinds, real integration with Reporting/Notifications/AI/Integrations, not stubs); Compliance (retention enforcement, backup snapshots, a GDPR export pipeline — a mid-implementation privacy bug that would have leaked cross-user audit data was caught and fixed before shipping); Observability (Prometheus metrics, OpenTelemetry tracing, structured logging, health checks); High Availability (every Module 9/10 background poller — seven services — is now safe at any replica count via a new Postgres-row-based distributed lease, closing a previously-documented single-replica limitation); Security Hardening (a Content-Security-Policy fix that would otherwise have broken Swagger UI in any deployment that enabled it, plus HSTS/ clickjacking headers); CI/CD (GitHub Actions — lint/typecheck/test/build, Docker image publishing, CodeQL + dependency audit — the first environment in this project's history with an actual Go toolchain, finally compiling the Go SDK for real); and four Production Deployment paths (Docker Compose, Kubernetes with autoscaling, Linux systemd, Windows Services) documented with an explicit accounting of what's genuinely production-hardened by the application itself versus what remains a deployment-specific responsibility (Postgres itself has no built-in HA in any of these paths — call it out before treating this as a solved problem).packages/sharedwas re-verified clean (tsc --noEmit) after every shared-type change; a fullapps/apitypecheck could not complete within this sandbox's command timeout, and the newly-added@opentelemetry/*tracing dependencies were neverpnpm install'd here (no registry network access) — both disclosed, consistent with the same environment constraint noted for Modules 7-9. Every file was manually re-verified after editing, including a direct cross-check of Prisma field names againstschema.prismarather than assumed.ci.ymlis the first real, automated verification pass this code will receive — treat it as authoritative. Seedocs/adr/0010-enterprise-platform.md,docs/modules/10-enterprise-platform.md,docs/releases/module-10-release-notes.md, anddeploy/README.md.Module 11 — AI Security Copilot + Autonomous Multi-Agent System (2026-07-26): source-complete. Adds a Master AI Orchestrator (
AgentOrchestratorService) on top of Module 5's existing single-turn AI chat: a free-text goal is decomposed into a tree ofAgentTasks, delegated across twelve specialist agents (Recon, Web, API, Mobile, Cloud, Active Directory, AI Research, Exploit Analysis, Report Writer, Code Review, Risk Assessment, Workflow Coordinator — the last able to delegate further sub-tasks), executed with dependency ordering, bounded concurrency, automatic retry, and a self-evaluation critique pass before completion — sharing Module 5's provider abstraction and tool-calling framework rather than forking them. Alongside the orchestrator: a searchable AI Knowledge Base (OWASP/CWE/CAPEC/MITRE ATT&CK/NIST/CVE, opt- in semantic reindex into the existing RAG store); an Explainability layer (pure aggregation of already-persisted reasoning/confidence/evidence into one "why did the system conclude this" narrative — no new persisted concept); per-workspace Privacy Mode (CLOUD/LOCAL/HYBRID) enforced at the provider-resolution seam every AI/agent call passes through (disclosed as narrower than ADR 0007's full local-first definition — it restricts provider choice, not execution location); four performance fixes from a dedicated review pass (an SSE fast path, a batched tool-call-log query fixing two independent N+1s, an invalidate-on-write Knowledge Base cache, a batched memory-chunk insert); a newAgentRunsController/KnowledgeBaseReferencesControllerHTTP surface (list/create/get/cancel/retry/explain a run, plus a live@Sse()progress stream mirroring Module 5's chat-stream pattern exactly) — the first way for a human user or the frontend to reach the orchestrator at all, previously only an internal Workflow Automation step could; and a new/agent+/knowledge-basefrontend surface, deliberately kept separate from Module 5's existing/aichat page since a multi-agent orchestration run has a fundamentally different shape than a chat turn.packages/sharedand a fullapps/apiproject-widetsc --noEmit+eslintpass both completed and stayed clean this module — the first module since 6 where that full backend verification loop actually ran to completion in this sandbox (via a detached-background-process technique that works around the environment's foreground command timeout). The identical technique did not reproduce forapps/webor for Jest later in the same session; both were instead verified by direct manual cross-reference against the real shared DTOs and call signatures, which caught and fixed one real type error (a tuple-inference bug in the new Knowledge Base page). Five new Jest spec files were added to theagentmodule (previously zero) and a pre-existing, since-staleai-provider-registry.service.spec.tswas found and rewritten to match this module's async, privacy-mode-aware provider resolution. Seedocs/adr/0011-ai-security-copilot-multi-agent-system.md,docs/modules/11-ai-security-copilot-multi-agent-system.md, anddocs/releases/module-11-release-notes.md.Module 12 — Cross-Platform Mobile Application (Flutter) (2026-07-28): source-complete. Adds
apps/mobile, a Flutter app (Clean Architecture, feature-first, Riverpod, GoRouter, Dio, Hive + sqflite) joiningapps/webandapps/desktopas a third first-class client ofapps/api, covering Auth (full Module 1 integration: email/Google/GitHub, MFA, refresh-token rotation, biometrics/PIN device lock, secure token storage), Dashboard, offline-first Projects/Targets/Findings (a sharedSyncEngine/outbox pattern — offline writes apply optimistically to a local sqflite row and sync on reconnect via a per-entitySyncPushHandler), Reports, an AI Security Copilot screen (Module 11 integration: streaming chat over a hand-rolled SSE client since Flutter has no built-inEventSource, Markdown/syntax-highlighted code/Mermaid rendering, voice push-to-talk, Master Orchestrator run tracking, Knowledge Base search), Voice (on-device STT/TTS), Notifications, Evidence Capture (camera/gallery/ file/video/mic/QR, on-device SHA-256 hashing, offline upload queue), File Manager, Global Search (online + an offline FTS5 fallback), Settings (incl. Module 11 Privacy Mode), Workspace, Analytics (fl_chart), and security hardening (encrypted storage, certificate pinning, jailbreak/ root detection, clipboard auto-clear, session timeout, remote logout). Deliberately avoids Freezed/riverpod_generator/json_serializable codegen in favor of Dart 3 nativesealed classstate unions, since the authoring sandbox had no reachable Flutter/Dart toolchain at all (storage.googleapis.com, where the Flutter engine/Dart SDK are hosted, is blocked by the network allowlist) — every file was hand-authored and manually cross-referenced against realpackages/sharedcontracts instead of compiler-verified, a stricter constraint than any prior module faced, and one disclosed in full in ADR 0012 §8. Manual review still caught and fixed three self-authored bugs (a malformed color hex literal, aProviderContainerdouble-construction bug inmain.dart's bootstrap, and a data-mapping typo in the Analytics bar chart).android/andios/contain only hand-authoredAndroidManifest.xml/Info.plistpartials — the Gradle/Xcode native scaffold must be generated on a real machine viaflutter create --platforms=android,ios .before this module builds at all, andflutter analyze/flutter test/flutter buildhave not been run against this source. Seedocs/adr/0012-mobile-application.md,docs/modules/12-mobile-application.md,docs/releases/module-12-release-notes.md,docs/mobile/mobile-architecture-guide.md,docs/mobile/flutter-development-guide.md, anddocs/mobile/api-integration-guide.md.Module 13 — AI Automation Platform + MCP Ecosystem + Security Agent SDK (2026-08-06): source-complete. Adopts the Model Context Protocol (
2025-06-18) as the platform's extensibility substrate: a standards- compliant MCP server (POST /mcp/rpc—initialize/tools/list/tools/call/resources/list/resources/read/prompts/list/prompts/get, API-key + scope-scoped sessions) exposing 15 tools (every one dispatching an existingCommandBus/QueryBushandler, no parallel logic), 13 read-only resource types, and Module 11's Prompt Registry; and a dependency-freeMcpClient(@pentesthub/sdk) making the platform an MCP consumer too. On top of that: an AI Agent SDK (packages/agent-sdk) with eleven built-in prompt-specialist agents (Recon, Web Pentest, API Security, Cloud Security, AD Assessment, Code Review, Threat Modeling, Bug Bounty Assistant, Report Writer, Knowledge Curator, Workflow Agent — all instances of one shared factory, not bespoke classes) plus aCUSTOMagent kind; Workflow Builder extensions to Module 10's engine (parallel/approval/MCP-tool-call steps,WEBHOOK/EVENTtriggers) and a matching Event Bus expansion; a Plugin SDK (node:vmhook sandboxing, confirmed-real Ed25519 code signing) and Script Engine (sandboxed JavaScript with a real wall-clock timeout race, a capability-gatedpentesthub.*global, PYTHON rejection) sharing one hardened untrusted-code execution primitive; an Automation Marketplace (the existing Plugin Marketplace, now also listing Agent SDK/Script/Workflow artifacts); Local Execution (a relay queue letting the backend or an external MCP client ask a user's Desktop Agent/Browser Extension to run something locally); AI Evaluation (scores agent/tool/script output against a metric catalog); six new Observability Prometheus series plus aGET /observability/ai-platformdashboard aggregating every Module 13 automation surface; a Developer Portal (browsable catalog, a real "try it" tool-call endpoint, a usage dashboard — regular JWT REST, not an MCP session); andpackages/cli(@pentesthub/cli), a dependency-free CLI built entirely on the existing SDK/shared contracts. A real, pre-existing bug was found and fixed during the Tests pass:MetricsRegistryService'sHistogram.render()was double-cumulating already-cumulative bucket counts, silently corrupting every Prometheus histogram this codebase exposes (including the Module 10 HTTP-duration series) — caught by hand-deriving expected values for a new histogram test.packages/sharedwas re-verified clean (tsc --noEmit) after every shared-type change, andpackages/cli— small and freestanding — was independently verified via a manualnode_modulessymlink to sibling workspace packages plus a directtsc --noEmit, a genuine clean compile;apps/api's ~970-file project remained too slow to fully typecheck or Jest-test in this sandbox (the same constraint disclosed in every module since Module 7 — nopnpmbinary and no registry access here either), so everyapps/apiedit was manually cross-checked against already-verified sibling files instead, and three new Jest spec files were written and reasoned through by hand rather than executed. Seedocs/adr/0013-ai-automation-platform-mcp-ecosystem.md,docs/modules/13-ai-automation-platform-mcp-ecosystem.md,docs/releases/module-13-release-notes.md, anddocs/mcp/mcp-guide.md.Module 14 — Cloud Platform, Enterprise SaaS & High Availability (2026-08-10): source-complete. Closes the gaps Module 10 explicitly left open: three pluggable infrastructure provider seams (
QUEUE_PROVIDERmemory/Redis,CACHE_PROVIDERmemory/Redis/disk,STORAGE_PROVIDERlocal/S3-compatible — each defaulting to the zero-external-dependency binding, each consumed only through an interface); High Availability (PollerLeaseServicegeneralized into a reusable distributed-lock/ leader-election primitive, with proactive lease release on graceful shutdown for faster failover); Distributed Worker extensions (a canonical job-type-category vocabulary, worker version reporting); Database support (pool sizing, optional read-replica routing, a migration drift-validation script now wired into CI); a real backup system (encryptedpg_dump/config/storage backups, checksummed verification, restore instructions, a recovery-test script) built on the same storage abstraction as everything else; Security (opt-in mTLS, IP allow lists, secrets-management/permission-matrix/WAF docs); an Admin Console (one call aggregating cluster/worker/queue/cache/ storage/database/backup/licensing state); Enterprise-only Tenant Management (billing/branding/usage, a newEditionGuardthat treats an unlicensed deployment as trusted rather than locked out); an API Gateway (opt-in per-route response caching); Auto Update (check-and- notify across every client, never silent self-replacement except the pre-existing Tauri desktop path); and production-grade CI/CD (PR-validation/release workflow separation, Turborepo caching, Docker builds with SBOM/provenance/Trivy scanning/cosign signing, a new desktop CI workflow, release-time SBOM generation, secret-gated npm/PyPI publishing). A dedicated Performance pass fixed one real N+1 (GetAvailablePluginUpdatesHandler); a dedicated Community Edition guarantee audit confirmed the standing "no mandatory paid service" guarantee holds across every Module 14 subsystem and, in the process, found and fixed a real bug (deploy/k8s/01-configmap.yaml'sQUEUE_PROVIDER: "in-memory"didn't match the zod schema's accepted values and would have failed boot validation as shipped). This module's sandbox verification hit a different set of constraints than Modules 7-13's "nopnpm, no registry access" ceiling:pnpmand a degraded-but-present network were both available, but theturbonpm package itself was never fully installed in this sandbox (only a dangling.bin/turbosymlink), so the requestedpnpm turbo run build lint check-types test --forceverification could not execute here at all; directtsc/prisma validateinvocations hung with zero output, root-caused to filesystem I/O latency on the mounted host folder rather than a code defect; and no Docker daemon orkubectlwas available for image builds or live manifest validation. What did verify cleanly: structural YAML parsing of every new/modified CI workflow and Kubernetes/Compose manifest (9 files, all passed). No git commit was made for this module's work pending that verification — seedocs/adr/0014-cloud-platform-enterprise-saas-ha.md,docs/modules/14-cloud-platform-enterprise-saas-ha.md,docs/releases/module-14-release-notes.md,docs/architecture/{api-gateway,auto-update,ci-cd}.md, anddocs/reviews/{0006-module-14-performance-review,0007-module-14-community-edition-guarantee}.md.Module 15 — Production Hardening, Monetization & Marketplace (2026-08-14): source-complete. Answers the questions every prior module's release notes deferred: a
PaymentProviderabstraction with a Stripe adapter (plainfetch(), deliberately nostripenpm SDK) over newSubscription/Invoice/Plan/PaymentMethod/QuotaPolicy/UsageCountertables, hosted checkout, and aStripeWebhookController(POST /billing/webhook/stripe) verifying Stripe's own HMAC signature scheme independently of Module 14's pre-existing generic billing webhook;UsageService/QuotaServicemetering and enforcing configurable per-scope limits (BILLING_PROVIDERdefaults tonone, and theFREEplan's limits areUNLIMITEDby seed default, so a self-hosted deployment is never throttled by default); Marketplace security (publisher verification, package checksums, enforced per-plugin permission declarations viaPluginPermissionGrant); a versioned Public API v1 layer and expanded API key management (IP allowlists, per-key rate limits, rotation lineage); nine outbound Integrations (Slack/Discord/Telegram/email/GitHub/GitLab/Jira/Linear/ Microsoft Teams) plus a generic webhook, all through oneIntegrationConnection/IntegrationProviderabstraction; AI cost control (AiModelPricingService/AiBudgetEnforcerService, per- workspace/organization spend budgets with provider/model fallback); privacy groundwork (self-service data export/deletion, telemetry opt-out, an opt-in privacy-awareTelemetryModuleoff by default, documented in the newPRIVACY.mdanddocs/compliance/gdpr-readiness.md); i18n (English/Uzbek/Russian) and an accessibility audit across web/ mobile/desktop; first-run onboarding and an isolated, read-only Demo Mode; Operability (GET /observability/health/diagnostics, a request-correlation ID threaded fromAsyncLocalStoragethrough everyAppExceptionand into root/dashboard-segment React error boundaries, and a Support ticket queue — deliberately without a triage UI, since no deployment-wide platform-admin role exists yet, the same posture Module 14's Tenant Management and Admin Console already established); Release engineering (CHANGELOG.md, aRELEASE_CHANNELenv var, root/apppackage.jsonversions synchronized to the module-tracking scheme for the first time,0.15.0); and a Feature Flags system (FeatureFlagsService.evaluateAll()resolving USER > WORKSPACE > ORGANIZATION overrides, theneditionRulesreusing Module 14'sEditionService.isEnterpriseFor(), thendefaultEnabled— management endpoints exist and work but, matching the same admin-role gap, are reachable via Swagger/curlonly). Dedicated Performance (QuotaService.resolveLimit()'s sequential-findFirst-per-scope loop collapsed into onefindMany), Security (two passes — seedocs/reviews/0008-m15-security-hardening-review.mdand its0011-module-15-security-review-followup.mdfollow-up), UX (a missing loading state found and fixed on the Diagnostics page), and Community Edition guarantee passes all ran and are documented indocs/reviews/. This module's sandbox verification constraint is strictly worse than every prior module's: discovered while building the Stripe webhook, the rootpackage.jsonfiles for@nestjs/common,@nestjs/swagger,@nestjs/cqrs,@nestjs/config, and@prisma/clientare physically missing from this sandbox's pnpm store (confirmed via direct filesystem inspection and a plainnode -e "require.resolve(...)"failure), meaningapps/api'stsc --noEmitcannot complete here at all, not merely slowly — every module back through Module 7 could at least attempt a slow/partial compiler pass; this one couldn't attempt one at all.jestremains absent from this sandbox for the same standing reason disclosed since Module 7; three new spec files (Stripe webhook signature verification, the quota N+1 fix, feature-flag precedence rules) were written and manually traced against their targets' real control flow but never executed.npx prisma generate/ a real migration have not run here either — Module 15's schema changes are captured in one consolidated migration file. Billing UI (/billing,/pricing,/settings/billing) and a Feature Flags admin UI are both disclosed as the largest remaining end-user- facing gaps, tracked as separate follow-up work rather than folded silently into "Module 15 is done." Seedocs/adr/0015-production-hardening-monetization-marketplace.md,docs/releases/module-15-release-notes.md,docs/architecture/{stripe-webhook,feature-flags,release-engineering, health-diagnostics,error-handling,support-system,demo-mode,i18n, onboarding}.md,PRIVACY.md, anddocs/compliance/gdpr-readiness.md.
Module 19 — Product Completion, Monetization & Launch Readiness (2026-09-09)
A baseline-audit-first pass, not a rebuild: the Module 19 brief asked for
a "complete, launch-ready monetization foundation," and the baseline
audit found that foundation already existed in production-quality form
from Module 15 — Plan/Subscription/Invoice/PaymentMethod/
UsageCounter/QuotaPolicy/FeatureFlag/AiModelPricing/
AiBudgetPolicy schema, BillingService/EntitlementService/
QuotaService/UsageService/SubscriptionService/InvoiceService/
AiBudgetEnforcerService, a provider-neutral PaymentProvider interface
(Stripe/Manual/Null adapters), and a real, signature-verified Stripe
webhook controller. The one clear, bounded, previously-tracked gap
(task #332) was that none of it had a frontend: this module built
apps/web/lib/api/{organizations,billing}.ts, features/{organizations,billing}/*
hooks and components, and three pages — /pricing, /settings/billing,
/settings/usage — all honest about Community Edition / no-organization
/ provider-not-configured / past-due / canceled states, with zero fake
payment-success screens (the only "success" state a page can show is a
real BillingCheckoutSessionDto.checkoutUrl redirect or an immediate
plan change for NONE/MANUAL providers). A full historical-backlog
reconciliation (docs/reviews/0022-module-19-backlog-reconciliation.md)
resolved two stale tracker entries (#132, #436 — work existed under
different ticket numbers and was never flipped) and disclosed one
genuine ticket-reassignment ambiguity: #386/#387 ("Research analytics
extensions" / "Security research notebook") were later reused by a
different task (#425, Public Sharing) for real, shipped work — the
originally-titled features were never built and aren't currently
planned, which is recorded as OBSOLETE rather than silently marked done.
Two small, real, previously-undisclosed defects were found and fixed
during the audit: billing-endpoints.ts had every path missing its
leading / (would have produced a malformed URL the moment a frontend
consumer used it — none existed before this module) and
bugbounty-badges.tsx's BugBountyFindingStage/ScopeClassification
badge maps had never been updated for states Module 16/9 added,
a real tsc compile error unrelated to Module 19 itself. A dedicated
security review (docs/reviews/0023-module-19-monetization-security-review.md)
found no IDOR, no client-controlled pricing, and no usage-fabrication
path; it also disclosed two pre-existing, not-fixed-in-this-pass
architectural limitations — Stripe webhook event ordering (not
signature/replay) is unguarded, and quota check-then-act has a
concurrency race — both scoped, real follow-up work. By deliberate
decision, no separate AI-credit ledger
(AICreditBalance/AICreditTransaction) was built on top of the
already-functioning AiBudgetPolicy/UsageCounter system, per the
project's standing anti-duplication rule. apps/api jest and a real
boot/health-check attempt remain VERIFICATION_BLOCKED in this
sandbox — three genuine, disclosed pnpm install attempts (full
monorepo, --filter web..., --filter api...) each hit the tool's
~170s call cap with only single-digit-to-low-tens of packages
downloaded/added, and a background/detached install does not persist
across tool calls here — measured throughput (~1 package per 10-15s
against a 500-1500-package graph) makes full completion infeasible
within this session, not merely slow. See
docs/reviews/0022-module-19-backlog-reconciliation.md,
docs/reviews/0023-module-19-monetization-security-review.md, and
docs/releases/module-19-release-notes.md for full detail.
Module 20 — Final Product Completion, Release & Project Closure (2026-09-09)
The final module of the core development roadmap: a 45-phase closing
pass across every surface built in Modules 1-19, not a feature module.
Per this module's own standing rule, nothing was rewritten, no working
module was replaced, and no duplicate infrastructure was created —
every fix reused an existing pattern (mirroring AiBudgetEnforcerService
for the new quota checks, mirroring each SDK's own per-resource file
convention for the new API-keys wrappers, extending existing deployment
configs rather than introducing new ones).
A baseline audit (Phases 0-5) found the platform already in strong
shape and surfaced a small number of real, bounded gaps rather than
systemic problems: the RECON_JOBS/SCANNER_JOBS quota types had been
defined in plan defaults since Module 15 but never actually enforced or
metered; the Stripe webhook had no defense against out-of-order event
delivery; several deployment artifacts (docker-compose.yml,
.env.example, Kubernetes manifests) were missing billing environment
variables the worker process needs; the installer prompted for
Enterprise Edition provider choices that were silently discarded; and
the public API-keys endpoints (live since Module 15) had zero SDK or
CLI coverage across all three SDKs and the CLI. Each was fixed with the
smallest change that closed the gap (Phases 6-9, 10-14, 15-17), and each
fix is traced in its own docs/reviews/00XX-module-20-*.md document.
Phases 18-21 formalized the project's documentation and legal posture
without making a business decision on its behalf: a root LICENSE file
was added to make the already-consistent UNLICENSED/proprietary
convention (declared individually by every package.json) discoverable
at a glance, explicitly without adopting or recommending any specific
open-source license — that remains a decision for the project's owners.
SECURITY.md and docs/security/supply-chain.md were both re-verified
in full and found still accurate, with one forward-looking note: the
supported-versions language needed a follow-up once the version bump
below landed (done in the same module, so no drift window was left
open). Phases 22-24 then cut the project's first stable release,
1.0.0, per docs/architecture/release-engineering.md's own
pre-existing policy anticipating exactly this once "Module 16+ work
settles the plugin/API-versioning surfaces" — a condition this module,
being the last one, was positioned to confirm — and backfilled four
modules' worth of missing CHANGELOG.md entries (0.16.0-0.19.0) that
had drifted out of sync with their own complete release-notes documents.
Phases 25-39 closed with a confirmation sweep — TODO/FIXME grep, git
history/status audit, a support-docs cross-check, and a guard-decorator
spot-check on three representative recently-touched endpoints — that
found no regressions and no new work items, consistent with the
preceding 24 phases having already done the deep security/performance/
reliability passes.
Two limitations were deliberately left open rather than fixed this
late in the release cycle, both because fixing them risks an
unrelated-module behavior change for cosmetic-to-moderate severity
issues: QUOTA_EXCEEDED is returned as HTTP 403 by the Module-10-era
entity-count quota subsystem but HTTP 429 by the Module-15-era
usage-metering QuotaService, two different subsystems sharing one
error code; and the quota check-then-act concurrency race first
disclosed in Module 19's security review remains unresolved. Both are
recorded in SECURITY.md's disclosed-limitation scope so a report about
either is triaged as already-known rather than novel. This module's
sandbox verification followed the same disclosed, honest pattern as
every prior module: apps/api's full tsc --noEmit/jest remain
infeasible here (confirmed to reproduce identically against untouched
files, not caused by this module), while apps/web, the TypeScript
SDK, the CLI, and the Python SDK were all verified directly (the Python
SDK's full test suite — 5/5 — was re-run after the version bump), and
the Go SDK was manually cross-checked against real method signatures
since go/gofmt are unavailable in this sandbox.
With this module's completion, the core PentestHub AI development
roadmap is CLOSED. Per this module's own standing instruction, no
Module 21 is started, and no further roadmap is proposed; future work
awaits explicit human direction. See docs/reviews/0025 through 0032
(this module's eight phase-by-phase review documents), CHANGELOG.md's
[1.0.0] entry, and LICENSE (new, repository root) for full detail.