heretic-agent is an open-source autonomous security agent for identifying business-logic vulnerabilities such as BOLA/IDOR, price tampering, workflow bypasses, and data exposure. It is intended for application security teams, penetration testers, and bug bounty researchers.
In the Penetration testing & red teaming space, heretic-agent takes a focused approach. It focuses on finding business-logic vulnerabilities in applications without manually testing every workflow and authorization path. It is built as an open-source project for application security professionals and penetration testers. The project is open source (Apache-2.0). It ships for the command line, and it can be self-hosted.
Behind heretic-agent is SYCO7, and it first shipped in 2026. The project is developed in the open on GitHub with 29 commits in the last 90 days. Among its 7 catalogued features are business-logic scanning, BOLA/IDOR detection, and price tampering detection.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Same category — not a similarity match