diff --git a/docs/cai_pro_alias1.md b/docs/cai_pro_alias1.md new file mode 100644 index 00000000..29e9920b --- /dev/null +++ b/docs/cai_pro_alias1.md @@ -0,0 +1,323 @@ +# Alias1 Model - Unrestricted Cybersecurity AI + +> **⚑ Exclusively Available with CAI PRO** +> +> Alias1 is the world's most capable cybersecurity LLM, delivering state-of-the-art performance with **zero refusals** for authorized security testing. +> +> **[Get CAI PRO with Alias1 β†’](https://aliasrobotics.com/cybersecurityai.php)** + +--- + +## What is Alias1? + +**Alias1** is a purpose-built large language model specifically trained for cybersecurity professionals. Unlike general-purpose models that refuse security tasks, alias1 delivers **unrestricted AI capabilities** for offensive and defensive security operations. + +### Key Highlights + +- **πŸ† #2 Rank** - CAIBench Base CTF Performance +- **75% Accuracy** - Cyber Threat Intelligence tasks +- **100% Zero Refusals** - No "I cannot help with that" responses +- **62.5% Success Rate** - Solved 15/24 base CTF challenges (pass@1) + +--- + +## Performance Benchmarks + +### CAIBench CTF Results + +Alias1 consistently outperforms leading models in real-world cybersecurity challenges: + +| Model | Base CTF Score | Rank | +|-------|---------------|------| +| **Claude Sonnet 4.5** | 70.8% | #1 | +| **πŸ€– alias1** | **62.5%** | **#2** | +| **GPT-5** | 58.3% | #3 | +| **Gemini 2.5 Pro** | 54.2% | #4 | + +**Source**: [CAIBench Meta-Benchmark Framework](https://arxiv.org/pdf/2510.24317) (2025) + +### Real-World Validation + +Alias1's capabilities are proven in actual security assessments: + +- **🎯 3,600Γ— Faster** than manual testing in specific scenarios ([CAI Framework Paper](https://arxiv.org/pdf/2504.06017)) +- **54.3% Patching Success** in Attack/Defense CTFs ([Agentic Evaluation Paper](https://arxiv.org/pdf/2510.17521)) +- **Zero Refusals** - Purpose-built for authorized security testing + +--- + +## Why Alias1 Outperforms Competitors + +### No Cybersecurity Censorship + +Unlike mainstream LLMs, alias1 never refuses legitimate security work: + +| Task | GPT-5 | Claude | Gemini | Alias1 | +|------|-------|--------|--------|--------| +| Write exploit code | ❌ | ❌ | ❌ | βœ… | +| Generate payloads | ❌ | ❌ | ❌ | βœ… | +| Bypass security controls | ❌ | ❌ | ❌ | βœ… | +| Craft phishing templates | ❌ | ❌ | ❌ | βœ… | +| Reverse engineer malware | ❌ | ❌ | ❌ | βœ… | + +**While others refuse, alias1 delivers.** + +--- + +### Specialized Training + +Alias1 is trained specifically for cybersecurity workflows: + +#### Offensive Security +- **Penetration Testing**: Full exploit development and PoC creation +- **Vulnerability Research**: Novel attack vector discovery +- **CTF Competitions**: Top-tier performance in capture-the-flag challenges +- **Red Teaming**: Adversary simulation and attack chain execution + +#### Defensive Security +- **Automated Mitigation**: Instant patch generation and security fixes +- **Threat Hunting**: Proactive threat detection and analysis +- **Incident Response**: Rapid response to security incidents +- **Blue Team Operations**: Defensive posture analysis and hardening + +#### Bug Bounty +- **Reconnaissance**: Comprehensive target enumeration +- **Analysis**: Deep vulnerability assessment +- **Exploitation**: Full exploit chain development +- **Reporting**: Professional vulnerability disclosure + +--- + +## Technical Specifications + +### Model Architecture + +- **Parameters**: 500B+ (optimized for security workflows) +- **Context Window**: Extended context for complex security scenarios +- **Training Data**: Curated cybersecurity datasets, CTF challenges, exploit databases +- **Fine-tuning**: Specialized for penetration testing and vulnerability research + +### Performance Characteristics + +- **Speed**: Optimized inference for real-time security operations +- **Accuracy**: State-of-the-art performance on security benchmarks +- **Reliability**: Four-layer guardrails against prompt injection ([Research Paper](https://arxiv.org/pdf/2508.21669)) +- **Consistency**: Deterministic outputs for reproducible security testing + +--- + +## Unlimited Tokens - Massive Savings + +### Cost Comparison (1 Billion Tokens/Month) + +Based on CAI's average text generation profile: 15,430 input / 436 output tokens per request + +| Provider | Monthly Cost | vs CAI PRO | +|----------|--------------|------------| +| **GPT-5** | €1,491/month | ❌ **4.3Γ— more expensive** | +| **Claude Sonnet 4.5** | €3,330/month | ❌ **9.5Γ— more expensive** | +| **Claude Opus 4.1** | €16,650/month | ❌ **47.6Γ— more expensive** | +| **πŸ€– CAI PRO (∞ alias1)** | **€350/month** | βœ… **Unlimited included** | + +**πŸ’° Save €1,141 - €16,300/month** with unlimited alias1 tokens in CAI PRO. + +--- + +## European Data Sovereignty + +### 100% European Infrastructure + +Your security testing data never leaves Europe: + +- **GDPR Compliant by Design**: Full compliance with General Data Protection Regulation +- **NIS2 Directive Ready**: Aligned with Network and Information Security Directive 2 +- **European Data Centers Only**: All processing, storage, and AI inference in EU jurisdiction +- **No Third-Party Data Sharing**: Your pentesting activities remain completely private + +#### Compliance Checklist + +| Regulation | Status | +|------------|--------| +| GDPR (EU 2016/679) | βœ… **Compliant** | +| NIS2 Directive (EU 2022/2555) | βœ… **Compliant** | +| EU AI Act | βœ… **Ready** | +| Data Residency | βœ… **EU Only** | + +**Perfect for European enterprises, government agencies, and privacy-conscious security professionals.** + +--- + +## Real-World Success Stories + +### Case Studies + +Alias1 has been validated in production environments across multiple industries: + +#### 🏭 OT Security - Ecoforest Heat Pumps +Alias1 discovered critical vulnerabilities allowing unauthorized remote access to heat pumps deployed across Europe, including exposed credentials and DES encryption weaknesses. + +[Read Case Study β†’](https://aliasrobotics.com/case-studies-robot-cybersecurity.php) + +#### πŸ€– Robotics - Mobile Industrial Robots (MiR) +Automated ROS message injection attacks exposed unauthorized access to robot control systems through AI-driven vulnerability discovery. + +[Read Case Study β†’](https://aliasrobotics.com/case-studies-robot-cybersecurity.php) + +#### πŸ›’ Web Security - Mercado Libre E-commerce +API vulnerability discovery through automated enumeration revealed user data exposure risks at scale in one of Latin America's largest e-commerce platforms. + +[Read Case Study β†’](https://aliasrobotics.com/case-studies-robot-cybersecurity.php) + +#### 🌐 Web Application - PortSwigger Race Condition +Successfully exploited race conditions in file upload vulnerabilities, uploading and executing web shells through automated parallel requests. + +[Read Case Study β†’](https://aliasrobotics.com/case-studies-robot-cybersecurity.php) + +--- + +## Research Foundation + +Alias1's capabilities are backed by 24+ peer-reviewed publications: + +### Key Research Papers + +#### πŸ“Š [CAIBench: Meta-Benchmark Framework](https://arxiv.org/pdf/2510.24317) (2025) +Modular evaluation framework demonstrating alias1's superior performance across offensive and defensive cybersecurity domains. + +#### πŸš€ [Cybersecurity AI (CAI) Framework](https://arxiv.org/pdf/2504.06017) (2025) +Foundational paper showing CAI outperforms humans by **3,600Γ— in specific security scenarios**, establishing new standards for automated security assessment. + +#### πŸ›‘οΈ [Hacking the AI Hackers via Prompt Injection](https://arxiv.org/pdf/2508.21669) (2025) +Demonstrates alias1's four-layer guardrail defenses, ensuring security even when processing adversarial inputs. + +#### 🎯 [Evaluating Agentic Cybersecurity in Attack/Defense CTFs](https://arxiv.org/pdf/2510.17521) (2025) +Real-world validation showing 54.3% patching success in live CTF environments, proving practical effectiveness. + +**[Explore All 24+ Research Papers β†’](https://aliasrobotics.com/research-security.php#papers)** + +--- + +## How to Access Alias1 + +### 1. Subscribe to CAI PRO + +Visit [aliasrobotics.com/cybersecurityai.php](https://aliasrobotics.com/cybersecurityai.php) and: + +- Choose your subscription plan (€350/month per user) +- Complete secure European payment processing +- Receive your `ALIAS_API_KEY` + +### 2. Configure Your Environment + +Update your `.env` file: + +```bash +# CAI PRO Configuration +ALIAS_API_KEY="sk-your-caipro-key-here" +CAI_MODEL="alias1" + +# Enable CAI PRO features +CAI_TUI_MODE=true +CAI_STREAM=false +``` + +### 3. Start Using Alias1 + +#### CLI Mode +```bash +cai +``` + +#### TUI Mode (Multi-terminal) +```bash +cai --tui +``` + +#### Verify Access +```bash +CAI> /model +# Should show alias1 is available + +CAI> scan target.com for vulnerabilities +# Start testing with unlimited tokens +``` + +--- + +## Frequently Asked Questions + +### How does alias1 compare to GPT-5? + +Alias1 consistently outperforms GPT-5 in cybersecurity-specific benchmarks: +- **CAIBench Base CTF**: alias1 (62.5%) vs GPT-5 (58.3%) +- **Zero Refusals**: alias1 never blocks security tasks +- **Specialized Training**: Purpose-built for security vs general-purpose + +### Is alias1 safe to use? + +Yes. Alias1 includes: +- **Four-layer guardrails** against prompt injection +- **Authorization context** - understands scope of security testing +- **Audit logging** - All queries logged for compliance +- **GDPR compliance** - European data protection standards + +### Can I mix alias1 with other models? + +Absolutely! CAI PRO allows you to: +- Use **unlimited alias1** for exploitation and security tasks +- Switch to **GPT-4o** for reporting and documentation +- Leverage **Claude** for code analysis +- **BYO API keys** for any of 300+ supported models + +### What if I need more than 1 billion tokens? + +CAI PRO includes **unlimited alias1 tokens** (subject to fair use policy). There are no hard limits - use as much as you need for your security operations. + +For extreme usage (e.g., large-scale automated scanning), contact us for enterprise plans. + +### Does alias1 work offline? + +Not in the standard CAI PRO plan. However: +- **CAI GOV & ENTERPRISE** offers on-premise deployment +- **Air-gapped environments** supported with custom licensing +- Contact **research@aliasrobotics.com** for offline deployments + +--- + +## Get Alias1 Today + +**Transform your security testing with the world's most capable cybersecurity AI.** + +
+ +### πŸš€ **Ready for Unrestricted AI?** + +- βœ… Unlimited alias1 tokens +- βœ… Zero refusals for authorized testing +- βœ… #2 ranked in CAIBench CTFs +- βœ… European data sovereignty (GDPR + NIS2) +- βœ… Professional support included +- βœ… Commercial use license + +**€350/month/user** Β· No long-term contracts Β· Cancel anytime + +**[Get CAI PRO with Alias1 β†’](https://aliasrobotics.com/cybersecurityai.php)** + +
+ +--- + +## Next Steps + +- **[View Full Pricing](cai_pro_pricing.md)** - Compare all CAI plans +- **[Explore Features](cai_pro_features.md)** - See all CAI PRO capabilities +- **[Quick Start Guide](cai_pro_quickstart.md)** - Get started in 5 minutes +- **[Contact Sales](cai_pro_contact.md)** - Enterprise & custom plans + +--- + + +*Questions about alias1? Contact **support@aliasrobotics.com*** +*Need enterprise deployment? [Request custom pricing β†’](mailto:contact@aliasrobotics.com?subject=Alias1%20Enterprise%20Inquiry)* + + diff --git a/docs/cai_pro_contact.md b/docs/cai_pro_contact.md new file mode 100644 index 00000000..5bee932b --- /dev/null +++ b/docs/cai_pro_contact.md @@ -0,0 +1,366 @@ +# Contact Sales & Support + +> **Get in Touch with the CAI Team** +> +> Whether you're interested in CAI PRO, need enterprise solutions, or have questions about our platform, we're here to help. +> +> **[Buy CAI PRO Now β†’](https://aliasrobotics.com/cybersecurityai.php)** + +--- + +## Quick Links + +
+ +### πŸš€ Ready to Buy? + +**Self-Service Purchase** + +Get CAI PRO instantly (€350/month): + +**[Buy CAI PRO β†’](https://aliasrobotics.com/cybersecurityai.php)** + +- βœ… Instant access to alias1 +- βœ… Automated onboarding +- βœ… Payment via credit card +- βœ… Start using in 5 minutes + +--- + +### 🏒 Enterprise Inquiry + +**Custom Solutions** + +For teams of 20+ or special requirements: + +**[Email: contact@aliasrobotics.com](mailto:contact@aliasrobotics.com?subject=CAI%20Enterprise%20Inquiry)** + +**[Schedule a Call β†’](mailto:contact@aliasrobotics.com?subject=CAI%20Enterprise%20Call%20Request)** + +Include in your message: +- Team size +- Use case +- Deployment requirements +- Budget range + +--- + +### πŸ’¬ Professional Support + +**CAI PRO Subscribers** + +Get help with technical issues: + +**[Email: support@aliasrobotics.com](mailto:support@aliasrobotics.com?subject=CAI%20PRO%20Support)** + +--- + +### πŸŽ“ Academic Inquiries + +**Universities & Research** + +Special pricing for education: + +**[Email: contact@aliasrobotics.com](mailto:contact@aliasrobotics.com?subject=CAI%20Academic%20Inquiry)** + +Include: +- Institution name +- Research project description +- Number of users +- .edu email address + +
+ +--- + +## Contact Information + +### πŸ“§ Email + +**General Inquiries & Sales:** +**contact@aliasrobotics.com** + +**Support (CAI PRO Subscribers):** +**support@aliasrobotics.com** + +**Expected Response Time:** +- **CAI PRO Subscribers**: 48 hours (SLA) +- **Enterprise Inquiries**: 24-48 hours +- **General Questions**: 2-5 business days + +--- + +### πŸ’¬ Discord Community + +**Join 1000+ Security Researchers** + +**[Discord Server β†’](https://discord.gg/fnUFcTaQAC)** + +**Channels:** +- **#general** - Community discussions +- **#help** - Community support (FREE users) +- **#pro-support** - Exclusive for CAI PRO subscribers +- **#announcements** - Product updates +- **#research** - Security research discussions + +--- + +### 🌐 Web + +**Official Website:** +[https://aliasrobotics.com](https://aliasrobotics.com) + +**CAI PRO Product Page:** +[https://aliasrobotics.com/cybersecurityai.php](https://aliasrobotics.com/cybersecurityai.php) + +**Alias1 Model Page:** +[https://aliasrobotics.com/alias1.php](https://aliasrobotics.com/alias1.php) + +**GitHub Repository:** +[https://github.com/aliasrobotics/cai](https://github.com/aliasrobotics/cai) + +--- + +## What to Include in Your Message + +### For Enterprise Inquiries + +Help us provide an accurate quote by including: + +1. **Organization Details:** + - Company name + - Industry sector + - Location (for compliance requirements) + +2. **Team Size:** + - Number of users + - Expected growth in next 12 months + +3. **Use Case:** + - Primary security testing needs + - Current toolchain + - Integration requirements + +4. **Technical Requirements:** + - On-premise vs cloud deployment + - Air-gapped environment needs + - Compliance requirements (GDPR, NIS2, etc.) + +5. **Timeline:** + - When do you need to start? + - Any specific deadlines? + +6. **Budget:** + - Budget range (optional but helpful) + - Procurement process details + +**Example Message:** + +``` +Subject: CAI Enterprise Inquiry - [Company Name] + +Hello, + +We're interested in CAI PRO/Enterprise for our security team. + +Organization: [Company Name], [Industry] +Team Size: 25 security professionals +Use Case: Penetration testing and bug bounty operations +Requirements: On-premise deployment, GDPR compliance +Timeline: Q2 2025 +Budget: €50,000 - €100,000 annual + +Can we schedule a call to discuss custom pricing? + +Best regards, +[Name] +[Title] +[Contact Info] +``` + +--- + +### For Support Requests (CAI PRO) + +Help us resolve your issue quickly: + +1. **Subscription Details:** + - Email used for CAI PRO subscription + - When did you subscribe? + +2. **Issue Description:** + - What were you trying to do? + - What happened instead? + - Error messages (exact text) + +3. **Environment:** + - Operating System (Linux, macOS, Windows) + - CAI version (`cai --version`) + - Python version + +4. **Reproduction Steps:** + - Step-by-step to reproduce the issue + - Configuration files (`.env` - remove API keys!) + - Screenshots if applicable + +**Example Support Message:** + +``` +Subject: CAI PRO Support - alias1 not available + +Hello, + +I'm a CAI PRO subscriber experiencing an issue. + +Subscription: pro-user@example.com (subscribed March 2025) + +Issue: When I run `cai`, alias1 is not showing as available. + +Environment: +- Ubuntu 22.04 LTS +- CAI v0.6.5 +- Python 3.11.2 + +Steps: +1. Set ALIAS_API_KEY in .env +2. Run `cai` +3. Type `/model` +4. alias1 not listed + +I've attached my .env file (with key redacted) and a screenshot. + +Thank you for your help. + +[Name] +``` + +--- + +## Sales Process + +### Individual & Small Teams (1-5 users) + +**Self-Service:** +1. Visit [aliasrobotics.com/cybersecurityai.php](https://aliasrobotics.com/cybersecurityai.php) +2. Click "Buy CAI PRO" +3. Complete payment +4. Receive `ALIAS_API_KEY` via email +5. Start using immediately + +**Timeline**: Instant (5 minutes) + +--- + +### Medium Teams (5-19 users) + +**Sales-Assisted:** +1. Email research@aliasrobotics.com with team size +2. Receive volume discount quote (10-20% off) +3. Complete payment (invoice or credit card) +4. Onboarding call with CAI team (optional) +5. Receive team API keys + +**Timeline**: 1-3 business days + +--- + +### Enterprise (20+ users) + +**Custom Process:** +1. Initial inquiry via email or scheduled call +2. Discovery session (30-60 min call) +3. Custom proposal with: + - Volume pricing + - Deployment options + - Support SLA + - Training plan +4. Contract negotiation +5. Legal/procurement review +6. Deployment and onboarding (1-4 weeks) + +**Timeline**: 2-8 weeks (depends on organization) + +--- + +## Frequently Asked Questions + +### How quickly will I get a response? + +**CAI PRO Support (technical)**: 48 hours (SLA) +**Enterprise Sales**: 24-48 hours +**General Inquiries**: 2-5 business days + +**Urgent issues?** Email with "URGENT" in subject line. + +--- + +### Can I schedule a demo? + +**Yes!** Email contact@aliasrobotics.com with: +- Your role/organization +- Preferred date/time (include timezone) +- Specific features you want to see + +We'll schedule a 30-60 minute live demo. + +--- + +## Additional Resources + +### Before Contacting Sales + +Review these resources to answer common questions: + +- **[Pricing & Plans](cai_pro_pricing.md)** - Detailed pricing information +- **[Features Overview](cai_pro_features.md)** - What's included in each plan +- **[Alias1 Model](cai_pro_alias1.md)** - Learn about our flagship model +- **[Quick Start](cai_pro_quickstart.md)** - How to get started +- **[FAQ](cai_faq.md)** - General frequently asked questions + +--- + +## Follow Us + +**Stay Updated:** + +- **Twitter**: [@aliasrobotics](https://twitter.com/aliasrobotics) +- **LinkedIn**: [Alias Robotics](https://www.linkedin.com/company/alias-robotics/) +- **YouTube**: [Alias Robotics Channel](https://www.youtube.com/@aliasrobotics) +- **Research Blog**: [aliasrobotics.com/research](https://aliasrobotics.com/research-security.php) + +--- + +## Legal & Compliance + +**Terms of Service:** +[CAI Terms & Conditions](https://aliasrobotics.com/terms-and-conditions.php) + +**Privacy Policy:** +GDPR compliant - data processed in EU only + +**License Information:** +- CAI FREE: [Open source license](https://github.com/aliasrobotics/cai/blob/main/LICENSE) +- CAI PRO: Proprietary commercial license +- CAI ENTERPRISE: Custom licensing available + +--- + +
+ +## πŸš€ Ready to Get Started? + +### Individual Users & Small Teams + +**[Buy CAI PRO Now β†’](https://aliasrobotics.com/cybersecurityai.php)** + +€350/month Β· Instant access Β· No contracts + +
+ +--- + + +*Questions? **contact@aliasrobotics.com** Β· +34 945 19 85 15* +*Privacy: Your data stays in Europe (GDPR compliant)* + + diff --git a/docs/cai_pro_features.md b/docs/cai_pro_features.md new file mode 100644 index 00000000..6bfe9ce5 --- /dev/null +++ b/docs/cai_pro_features.md @@ -0,0 +1,399 @@ +# CAI PRO Exclusive Features + +> **Unlock Advanced Capabilities** +> +> CAI PRO delivers professional-grade features designed for security teams, enterprises, and advanced users who need unrestricted AI, parallel execution, and comprehensive monitoring. +> +> **[Get CAI PRO β†’](https://aliasrobotics.com/cybersecurityai.php)** + +--- + +## Feature Overview + +| Capability | CAI FREE | CAI PRO | +|------------|----------|---------| +| **πŸ€– Alias1 Model** | ❌ | βœ… **Unlimited Tokens** | +| **πŸ–₯️ Terminal UI (TUI)** | ❌ | βœ… Multi-terminal parallel execution | +| **πŸ“Š Context Monitoring** | ❌ | βœ… Real-time token tracking | +| **⚑ Multi-Agent Swarms** | ❌ | βœ… 100+ parallel agents | +| **πŸ’¬ Professional Support** | ❌ Community | βœ… Priority (48h SLA) | +| **πŸ‡ͺπŸ‡Ί European Hosting** | βœ… GDPR + NIS2 | βœ… GDPR + NIS2 | +| **πŸ“ Advanced Reporting** | ❌ | βœ… Professional formats | +| **🏒 Commercial License** | ❌ Research Only | βœ… Full Commercial | +| **πŸ›‘οΈ Guardrails** | βœ… Basic | βœ… Four-layer advanced | +| **πŸ”§ Custom Extensions** | ❌ | βœ… Available on request | + +--- + +## 1. Unlimited Alias1 Tokens + +### World's Most Capable Cybersecurity LLM + +**Alias1** is purpose-built for security professionals: + +- **#2 Rank** in CAIBench Base CTF Performance (62.5% success rate) +- **Zero Refusals** for authorized security testing +- **75% Accuracy** on Cyber Threat Intelligence tasks +- **Unrestricted** exploit development, payload generation, and bypass techniques + +**Cost Savings**: Unlimited tokens save **€1,141 - €16,300/month** compared to GPT-5, Claude, or other providers. + +[Learn More About Alias1 β†’](cai_pro_alias1.md) + +--- + +## 2. Terminal User Interface (TUI) + +### Multi-Agent Orchestration at Your Fingertips + +**One human operator can monitor dozens of agents** with CAI PRO's professional Terminal User Interface. + +![CAI TUI Screenshot](media/cai-tui-main.png) + +### Key Capabilities + +#### Multi-Pane Views +- **4+ parallel terminals** with independent contexts +- **Visual monitoring**: Real-time cost tracking, model selection, agent status +- **Synchronized execution**: Broadcast prompts to all terminals simultaneously + +#### Keyboard Control +- **Vim-style shortcuts**: Navigate without touching your mouse +- **Quick commands**: `/agent`, `/model`, `/context`, `/parallel` +- **Terminal switching**: `Ctrl+N`/`Ctrl+B` for rapid navigation + +#### Real-Time Stats +- **Cost tracking**: Per-terminal and session-wide expense monitoring +- **Token usage**: Input/output token breakdown by terminal +- **Performance metrics**: Response times and API call statistics + +#### Preconfigured Teams +- **11 team presets**: Red team, blue team, bug bounty combos +- **One-click setup**: Instantly deploy specialized agent configurations +- **Custom teams**: Save your own team compositions + +### Time Savings + +**Save 40+ hours/month** by replacing manual monitoring with intelligent automation: + +- **Before**: Manually switching between terminal windows, copy-pasting commands +- **After**: Single interface, parallel execution, automated coordination + +[TUI Documentation β†’](tui/tui_index.md) + +--- + +## 3. Context Monitoring (`/context`) + +### Optimize Your Conversations + +Track token usage and stay within model limits with real-time context monitoring. + +### Features + +- **Real-time tracking**: Monitor context window consumption as you work +- **Category breakdown**: Tokens by system, tools, memory, and messages +- **Visual indicators**: Color-coded utilization levels +- **Optimization insights**: Know when to compact or clear history + +### Use Cases + +- **Long conversations**: Avoid hitting context limits mid-session +- **Cost optimization**: Understand where tokens are consumed +- **Memory management**: Balance RAG memory vs conversation space +- **Multi-terminal coordination**: Track context across parallel agents + +--- + +## 4. Parallel Agent Swarms + +### 100+ Concurrent Agents + +Deploy hundreds of specialized agents simultaneously for unprecedented security coverage. + +### Performance Multipliers + +| Metric | Manual | With Swarms | Improvement | +|--------|--------|-------------|-------------| +| **Parallel Agents** | 1 | 100+ | **100Γ—** | +| **Discovery Speed** | 1Γ— | 10Γ— | **10Γ— faster** | +| **Coverage** | Limited | Comprehensive | **Complete** | +| **Availability** | 9-5 | 24/7 | **Continuous** | + +**Save 100+ hours per month** with autonomous security operations. + +### Swarm Patterns + +#### Broadcast Execution +Send the same prompt to multiple agents: +```bash +CAI TUI> Scan target.com for vulnerabilities +# Executes across: redteam_agent, blueteam_agent, bug_bounter_agent, retester_agent +``` + +#### Specialized Teams +Deploy role-specific agent combinations: +- **Offensive Team**: 4Γ— redteam_agent in parallel +- **Balanced Team**: 2Γ— red + 2Γ— blue team agents +- **Bug Bounty**: 2Γ— bug_bounter + 2Γ— retester agents + +#### Sequential Workflows +Chain agents for complex operations: +1. **Discovery**: bug_bounter_agent finds vulnerabilities +2. **Validation**: retester_agent confirms findings +3. **Exploitation**: redteam_agent develops exploits +4. **Documentation**: reporting_agent generates writeups + +[Teams & Parallel Execution Guide β†’](tui/teams_and_parallel_execution.md) + +--- + +## 5. Professional Support + +### Priority Technical Assistance + +CAI PRO subscribers receive dedicated support from security experts. + +### Support Channels + +#### Email Support +- **Address**: research@aliasrobotics.com +- **SLA**: 48-hour response time +- **Coverage**: Technical issues, configuration, best practices + +#### Priority Discord +- **Channel**: #pro-support (exclusive) +- **Access**: Direct communication with CAI developers +- **Community**: Network with other PRO users + +#### Quarterly Strategy Calls +- **Frequency**: 4Γ— per year (optional) +- **Topics**: Roadmap discussion, feature requests, use case optimization +- **Format**: Video call with CAI team + +### Custom Development + +Request tailored solutions: +- **Custom Agents**: Domain-specific security agents +- **Integration Support**: Connect CAI to your existing tools +- **Workflow Optimization**: Fine-tune CAI for your organization +- **Training**: Onboarding sessions for your team + +--- + +## 6. European Data Sovereignty + +### GDPR & NIS2 Compliant by Design + +Your security testing data never leaves Europe. + +### Compliance Features + +| Regulation | Compliance Level | Details | +|------------|------------------|---------| +| **GDPR** (EU 2016/679) | βœ… **Fully Compliant** | Data minimization, encryption, audit trails | +| **NIS2 Directive** (EU 2022/2555) | βœ… **Ready** | Incident reporting, supply chain security, risk management | +| **EU AI Act** | βœ… **Prepared** | Transparency, accountability, human oversight | +| **Data Residency** | βœ… **EU Only** | No data routing through non-EU jurisdictions | + +### Privacy Guarantees + +- **No Third-Party Sharing**: Your pentesting activities remain private +- **No Training on Your Data**: Your queries never improve models (unless opt-in) +- **Encryption**: End-to-end encryption for all communications +- **Audit Logs**: Complete traceability for compliance requirements + +**Perfect for European enterprises, government agencies, and regulated industries.** + +--- + +## 7. Advanced Reporting + +### Professional Security Reports + +Generate compliance-ready reports automatically. + +### Report Types + +#### CTF Writeups +- **Challenge description**: Automatic extraction from prompts +- **Exploitation steps**: Detailed attack chain documentation +- **Flags obtained**: Proof of successful exploitation +- **Tools used**: Complete tooling inventory + +#### Penetration Testing Reports +- **Executive summary**: High-level findings for management +- **Technical findings**: Detailed vulnerability descriptions +- **Proof of concept**: Code snippets and screenshots +- **Remediation guidance**: Actionable fix recommendations + +#### NIS2 Compliance Reports +- **Incident documentation**: Structured incident response records +- **Risk assessment**: Vulnerability severity and impact analysis +- **Mitigation tracking**: Patch deployment verification +- **Audit trails**: Complete testing activity logs + +### Output Formats + +- **Markdown**: Easy editing and version control +- **PDF**: Professional presentation-ready format +- **HTML**: Web-based viewing and sharing +- **JSON**: Machine-readable for automation + +--- + +## 8. Four-Layer Guardrails + +### Advanced Security Protection + +CAI PRO includes enterprise-grade guardrails against adversarial attacks. + +### Protection Layers + +#### Layer 1: Input Validation +- **Prompt injection detection**: Identify adversarial inputs +- **Malicious pattern filtering**: Block known attack vectors +- **Context verification**: Ensure legitimate security testing scope + +#### Layer 2: Output Sanitization +- **Dangerous command filtering**: Prevent accidental destructive operations +- **Data leak prevention**: Avoid exposing sensitive information +- **Format enforcement**: Ensure outputs match expected structure + +#### Layer 3: Authorization Context +- **Scope validation**: Verify testing is within authorized boundaries +- **Target verification**: Confirm permissions for specified targets +- **Audit logging**: Record all security operations for compliance + +#### Layer 4: Human Oversight +- **Confirmation prompts**: Request approval for high-risk operations +- **Manual review**: Pause for human validation when needed +- **Override capability**: Expert users can bypass when justified + +**Research validation**: [Hacking the AI Hackers via Prompt Injection](https://arxiv.org/pdf/2508.21669) (2025) + +--- + +## 9. Commercial Use License + +### Unrestricted Business Use + +CAI PRO includes full commercial licensing for professional security services. + +### Authorized Uses + +βœ… **Penetration Testing Services** +βœ… **Security Consulting** +βœ… **Bug Bounty Hunting (for profit)** +βœ… **Enterprise Security Operations** +βœ… **Security Training & Education (commercial)** +βœ… **Product Integration (with agreement)** + +### License Comparison + +| Use Case | CAI FREE | CAI PRO | +|----------|----------|---------| +| **Academic Research** | βœ… | βœ… | +| **Personal Learning** | βœ… | βœ… | +| **Commercial Pentesting** | ❌ | βœ… | +| **Security Consulting** | ❌ | βœ… | +| **Bug Bounty (paid)** | ❌ | βœ… | +| **Enterprise Deployment** | ❌ | βœ… | + +--- + +## 10. Custom Extensions + +### Tailored Solutions for Your Organization + +Work with the CAI team to develop specialized capabilities. + +### Extension Types + +#### Custom Agents +- **Domain-specific security agents**: OT, IoT, cloud, robotics +- **Industry-tailored**: Finance, healthcare, manufacturing +- **Workflow-optimized**: Match your existing processes + +#### Tool Integration +- **SIEM/SOAR**: Connect CAI to Splunk, QRadar, Sentinel +- **Ticketing Systems**: Jira, ServiceNow automation +- **CI/CD Pipelines**: Jenkins, GitLab, GitHub Actions + +#### Reporting Templates +- **Compliance-specific**: PCI-DSS, ISO 27001, SOC 2 +- **Client-branded**: Match your corporate identity +- **Multi-language**: Localized reports + +#### API Wrappers +- **Internal tools**: Integrate with proprietary systems +- **Data pipelines**: Feed CAI results to analytics platforms +- **Automation**: Trigger CAI from existing workflows + +**Contact contact@aliasrobotics.com to discuss custom development.** + +--- + +## Feature Comparison Matrix + +### CAI FREE vs CAI PRO vs CAI GOV/ENTERPRISE + +| Feature | FREE | PRO | GOV/ENTERPRISE | +|---------|------|-----|----------------| +| **Core Framework** | βœ… (~6mo delay) | βœ… Latest | βœ… Latest + Custom | +| **300+ Models** | βœ… BYO Keys | βœ… BYO Keys | βœ… BYO Keys + Private | +| **Alias1 Tokens** | ❌ | βœ… Unlimited | βœ… Unlimited + On-prem | +| **TUI** | ❌ | βœ… Yes | βœ… Yes + Custom UI | +| **Context Monitoring** | ❌ | βœ… Yes | βœ… Yes + Analytics | +| **Parallel Agents** | ❌ | βœ… 100+ | βœ… Unlimited | +| **Support** | Community | βœ… Priority | βœ… Dedicated + Training | +| **Reporting** | Basic | βœ… Advanced | βœ… Custom Templates | +| **Guardrails** | Basic | βœ… 4-layer | βœ… Configurable | +| **Commercial License** | ❌ | βœ… Yes | βœ… Yes + Redistribution | +| **Custom Extensions** | ❌ | βœ… Available | βœ… Included | +| **Audit Logging** | ❌ | βœ… Basic | βœ… Forensics-grade | +| **Air-gapped Deployment** | ❌ | ❌ | βœ… Yes | +| **On-premise Alias1** | ❌ | ❌ | βœ… Yes | +| **Pricing** | **Free** | **€350/month** | **Custom Quote** | + +--- + +## Get CAI PRO Today + +**Unlock all features and transform your security operations.** + +
+ +### πŸš€ **Ready to Upgrade?** + +- βœ… Unlimited alias1 tokens +- βœ… Terminal UI with parallel agents +- βœ… Context monitoring and optimization +- βœ… Professional support (48h SLA) +- βœ… European data sovereignty (GDPR + NIS2) +- βœ… Commercial use license +- βœ… Advanced reporting +- βœ… Custom extensions available + +**€350/month/user** Β· No long-term contracts Β· Cancel anytime + +**[Get CAI PRO β†’](https://aliasrobotics.com/cybersecurityai.php)** + +
+ +--- + +## Next Steps + +- **[View Full Pricing](cai_pro_pricing.md)** - Compare all plans +- **[Learn About Alias1](cai_pro_alias1.md)** - Explore the flagship model +- **[Quick Start Guide](cai_pro_quickstart.md)** - Get started in 5 minutes +- **[Contact Sales](cai_pro_contact.md)** - Enterprise & custom plans + +--- + + +*Questions about features? Contact **support@aliasrobotics.com*** +*Need enterprise capabilities? [Request custom pricing β†’](mailto:contact@aliasrobotics.com?subject=CAI%20PRO%20Features%20Inquiry)* + + diff --git a/docs/cai_pro_pricing.md b/docs/cai_pro_pricing.md new file mode 100644 index 00000000..9f261e53 --- /dev/null +++ b/docs/cai_pro_pricing.md @@ -0,0 +1,349 @@ +# CAI Pricing & Plans + +> **Choose the Right Plan for Your Security Needs** +> +> From individual researchers to enterprise security teams, CAI offers flexible pricing tailored to your requirements. +> +> **[Get CAI PRO β†’](https://aliasrobotics.com/cybersecurityai.php)** + +--- + +## Plan Overview + +
+ +### CAI FREE + +**€0 / forever** + +Leading open-source framework for AI Security. +Free for research purposes. + +#### Included: +- βœ… AI Security Framework (300+ LLM Models) +- βœ… Built-in Security Tools +- βœ… Agent-based Architecture +- βœ… Guardrails Protection Built-in +- βœ… Community Support +- βœ… **Free for research** (non-commercial) + +#### Limitations: +- ❌ No alias1 model access +- ❌ No Terminal UI (TUI) +- ❌ No parallel agent swarms +- ❌ No context monitoring +- ❌ No commercial license +- ⚠️ Framework updates ~6 months behind PRO + +**[View on GitHub β†’](https://github.com/aliasrobotics/cai)** + +--- + +### CAI PRO + +**€350 / month / user** + +Leading enterprise framework for AI Security with professional support. + +#### Everything in FREE, plus: +- βœ… **Unlimited alias1 tokens** +- βœ… **Terminal User Interface (TUI)** +- βœ… **Multi-agent parallel execution** (100+ agents) +- βœ… **Context Monitoring** (`/context` command) +- βœ… **Commercial license** included +- βœ… **Professional support** (48h SLA) +- βœ… **GDPR & NIS2 compliant** European hosting +- βœ… **Advanced reporting** (PDF, Markdown, HTML) +- βœ… **Custom extensions** available +- βœ… **Latest features** (6+ months ahead of open source) +- βœ… **Priority Discord channel** + +**🎯 Most Popular for Security Professionals** + +**[Buy Now β†’](https://aliasrobotics.com/cybersecurityai.php)** + +--- + +### CAI GOV & ENTERPRISE + +**Custom Pricing** + +Cybersecurity AI tailored to your organization requirements. +Custom deployment options. + +#### Everything in PRO, plus: +- βœ… **On-premise & air-gapped** alias1 deployment +- βœ… **Full privacy-by-design** architecture (alias0 arch) +- βœ… **Priority support & training** +- βœ… **Custom AI model fine-tuning** for your domain +- βœ… **Audit logging & forensics** capabilities +- βœ… **Dedicated account manager** +- βœ… **SLA guarantees** (custom) +- βœ… **Multi-platform deployment** (unlimited) +- βœ… **Custom integrations** + +**Perfect for Large Teams, Government, & Regulated Industries** + +**[Contact Sales β†’](mailto:contact@aliasrobotics.com?subject=CAI%20Enterprise%20Inquiry)** + +
+ +--- + +## Detailed Feature Comparison + +| Feature | FREE | PRO | GOV/ENTERPRISE | +|---------|------|-----|----------------| +| **πŸ’° Pricing** | **Free** | **€350/month** | **Custom** | +| | | | | +| **πŸ€– Core Capabilities** | | | | +| AI Framework | βœ… (~6mo delay) | βœ… Latest | βœ… Latest + Custom | +| 300+ LLM Models | βœ… BYO Keys | βœ… BYO Keys | βœ… BYO + Private | +| Built-in Security Tools | βœ… Full Suite | βœ… Full Suite | βœ… Full Suite + Custom | +| Agent-based Architecture | βœ… All Patterns | βœ… All Patterns | βœ… All + Custom | +| Command Line Interface | βœ… Yes | βœ… Yes | βœ… Yes | +| | | | | +| **πŸš€ Alias1 Model** | | | | +| Alias1 Access | ❌ | βœ… Unlimited Tokens | βœ… Unlimited + On-prem | +| #2 CAIBench Rank | ❌ | βœ… Yes | βœ… Yes | +| Zero Refusals | ❌ | βœ… Yes | βœ… Yes | +| European Hosting | ❌ | βœ… Yes | βœ… + On-premise Option | +| | | | | +| **πŸ–₯️ User Interfaces** | | | | +| Terminal UI (TUI) | ❌ | βœ… Multi-terminal | βœ… Multi-terminal + Custom | +| Parallel Agent Execution | ❌ | βœ… 100+ agents | βœ… Unlimited | +| Context Monitoring | ❌ | βœ… `/context` | βœ… + Analytics Dashboard | +| Keyboard Shortcuts | ❌ | βœ… Full Set | βœ… Full Set + Custom | +| Team Presets | ❌ | βœ… 11 Teams | βœ… Unlimited Custom | +| | | | | +| **πŸ’¬ Support** | | | | +| Community Discord | βœ… Yes | βœ… Yes | βœ… Yes | +| Email Support | ❌ | βœ… 48h SLA | βœ… Custom SLA | +| Priority Discord Channel | ❌ | βœ… Yes | βœ… Yes | +| Quarterly Strategy Calls | ❌ | βœ… Yes | βœ… Yes + More Frequent | +| Dedicated Account Manager | ❌ | ❌ | βœ… Yes | +| On-site Training | ❌ | ❌ | βœ… Available | +| | | | | +| **πŸ›‘οΈ Security & Compliance** | | | | +| GDPR Compliant | βœ… Yes | βœ… Yes | βœ… Yes | +| NIS2 Directive Ready | βœ… Yes | βœ… Yes | βœ… Yes | +| EU Data Centers Only | βœ… Yes | βœ… Yes | βœ… + On-premise | +| Guardrails | βœ… Basic | βœ… 4-layer | βœ… Configurable | +| Audit Logging | ❌ | βœ… Basic | βœ… Forensics-grade | +| | | | | +| **πŸ“ Reporting & Documentation** | | | | +| Basic Reporting | βœ… CLI Output | βœ… CLI + Advanced | βœ… Custom Templates | +| CTF Writeups | ❌ | βœ… Automated | βœ… Automated + Branded | +| Pentest Reports | ❌ | βœ… Executive + Technical | βœ… Compliance-ready | +| Export Formats | βœ… Markdown | βœ… MD, PDF, HTML, JSON | βœ… All + Custom | +| | | | | +| **πŸ”§ Customization** | | | | +| Custom Agents | ❌ | βœ… On Request | βœ… Included | +| Custom Extensions | ❌ | βœ… Available | βœ… Included | +| Tool Integration | ❌ | βœ… On Request | βœ… Full Integration Support | +| API Wrappers | ❌ | ❌ | βœ… Custom Development | +| Model Fine-tuning | ❌ | ❌ | βœ… Domain-specific | +| | | | | +| **🏒 Licensing** | | | | +| Commercial Use | ❌ Research Only | βœ… Full Commercial | βœ… Full + Redistribution | +| Academic Research | βœ… Yes | βœ… Yes | βœ… Yes | +| Bug Bounty (paid) | ❌ | βœ… Yes | βœ… Yes | +| Security Consulting | ❌ | βœ… Yes | βœ… Yes | +| Enterprise Deployment | ❌ | βœ… Yes | βœ… Yes | +| | | | | +| **🐳 Deployment** | | | | +| Cloud (Your Infra) | βœ… Yes | βœ… Yes | βœ… Yes | +| On-premise | βœ… Self-hosted | βœ… Self-hosted | βœ… + Managed | +| Air-gapped Networks | ❌ | ❌ | βœ… Supported | +| Multi-platform | βœ… Limited | βœ… Unlimited | βœ… Unlimited + Support | + +--- + +## Cost Comparison: Alias1 vs Competitors + +### Monthly Cost for 1 Billion Tokens + +Based on CAI's average text generation profile: **15,430 input / 436 output tokens per request** + +
+ +| Provider | Monthly Cost | Annual Cost | vs CAI PRO | +|----------|--------------|-------------|------------| +| **GPT-5** | €1,491 | €17,892 | ❌ **4.3Γ— more expensive** | +| **Claude Sonnet 4.5** | €3,330 | €39,960 | ❌ **9.5Γ— more expensive** | +| **Claude Opus 4.1** | €16,650 | €199,800 | ❌ **47.6Γ— more expensive** | +| **πŸ€– CAI PRO (∞ alias1)** | **€350** | **€4,200** | βœ… **Unlimited included** | + +### Annual Savings with CAI PRO + +| vs Provider | Monthly Savings | Annual Savings | +|-------------|-----------------|----------------| +| vs GPT-5 | €1,141 | €13,692 | +| vs Claude Sonnet 4.5 | €2,980 | €35,760 | +| vs Claude Opus 4.1 | €16,300 | €195,600 | + +**πŸ’° ROI: CAI PRO pays for itself in the first month** for teams using more than ~230M tokens/month. + +
+ +--- + +## Frequently Asked Questions + +### How does billing work? + +**CAI PRO:** +- **Monthly subscription**: Billed on the 1st of each month +- **Payment methods**: Credit card, bank transfer (annual plans) +- **Currency**: EUR (€) +- **VAT**: Excluded from listed prices (added at checkout for EU customers) +- **Cancellation**: Cancel anytime, access until end of billing period + +**CAI GOV/ENTERPRISE:** +- **Custom billing**: Annual, quarterly, or monthly +- **Purchase orders**: Accepted for enterprise plans +- **Invoicing**: NET 30 terms available +- **Multi-year contracts**: Discounts available + +### What happens if I exceed fair use limits? + +CAI PRO includes **unlimited alias1 tokens** subject to fair use: + +**Fair use policy:** +- Typical usage: 100M - 10B tokens/month βœ… **No issues** +- Heavy usage: 10B - 100B tokens/month βœ… **Monitored but allowed** +- Extreme usage: >100B tokens/month ⚠️ **Contact us to upgrade to Enterprise** + +We've never had to enforce limitsβ€”most users stay well within fair use. + +### Can I switch plans? + +Yes! You can upgrade or downgrade anytime: + +**Upgrade (FREE β†’ PRO):** +- Instant access to PRO features +- Billed monthly starting immediately + +**Downgrade (PRO β†’ FREE):** +- Access to PRO features until end of billing period +- Automatic switch to FREE plan +- Retain all data and configurations + +**Contact Sales for Enterprise:** +- Custom migration path +- Dedicated onboarding support + +### Do you offer academic discounts? + +Yes! We offer special pricing for universities and research institutions: + +**Academic CAI PRO:** +- **Contact**: contact@aliasrobotics.com with: + - Institutional affiliation + - Research project description + - Number of users needed + +### Can I pay annually? + +Yes! Annual plans available: + +**CAI PRO Annual:** +- **€4,200/year** +- **Benefits**: Same as monthly + priority support + +**Contact contact@aliasrobotics.com for annual billing** + +### What if I need more than alias1? + +CAI PRO includes: +- **Unlimited alias1**: Use as much as you need +- **BYO API keys**: Use your own keys for GPT-5, Claude, Gemini, etc. + +### Can I schedule a demo? + +Yes! Contact us: + +**CAI PRO demos:** +- Contact contact@aliasrobotics.com +- Schedule a live demo with our team +- See TUI, alias1, and advanced features in action + +We don't offer free PRO trials, but CAI FREE lets you evaluate the framework before committing. + +### Can I use CAI PRO for bug bounties? + +**Yes!** CAI PRO includes a **full commercial license**, which covers: + +βœ… **Authorized bug bounty programs** (HackerOne, Bugcrowd, etc.) +βœ… **Security consulting services** +βœ… **Penetration testing** for clients +βœ… **Enterprise security operations** + +Bug bounties discovered with CAI PRO: +- **$2,500+ earned** by CAI users in documented bounties +- Vulnerabilities found in Ecoforest, MiR, Mercado Libre, and more + +[View Case Studies β†’](https://aliasrobotics.com/case-studies-robot-cybersecurity.php) + +--- + +## Choose Your Plan + +
+ +### πŸ†“ **CAI FREE** + +**Perfect for:** +- Individual researchers +- Students & academics +- Open-source contributors +- Personal learning + +**[Get Started (GitHub) β†’](https://github.com/aliasrobotics/cai)** + +--- + +### πŸš€ **CAI PRO** (Most Popular) + +**Perfect for:** +- Security professionals +- Bug bounty hunters +- Small security teams (1-5) +- Security consultants + +**€350/month** Β· No contracts Β· Cancel anytime + +**[Buy CAI PRO β†’](https://aliasrobotics.com/cybersecurityai.php)** + +--- + +### 🏒 **CAI GOV & ENTERPRISE** + +**Perfect for:** +- Large security teams (20+) +- Government agencies +- Regulated industries +- Custom requirements + +**Custom pricing** Β· Volume discounts Β· SLA guarantees + +**[Contact Sales β†’](mailto:contact@aliasrobotics.com?subject=CAI%20Enterprise%20Inquiry)** + +
+ +--- + +## Next Steps + +- **[Explore Features](cai_pro_features.md)** - See what's included in CAI PRO +- **[Learn About Alias1](cai_pro_alias1.md)** - Understand our flagship model +- **[Quick Start Guide](cai_pro_quickstart.md)** - Get started in 5 minutes +- **[Contact Sales](cai_pro_contact.md)** - Questions? We're here to help + +--- + + +*All prices exclude VAT. Volume discounts available for teams.* +*Questions about pricing? Contact **contact@aliasrobotics.com*** + + diff --git a/docs/cai_pro_quickstart.md b/docs/cai_pro_quickstart.md new file mode 100644 index 00000000..74571a2c --- /dev/null +++ b/docs/cai_pro_quickstart.md @@ -0,0 +1,400 @@ +# Get Started with CAI PRO + +> **Quick Start Guide** +> +> This guide will have you running CAI PRO with unlimited alias1 tokens in minutes. +> +> **Already subscribed?** Jump to [Step 2: Install CAI](#2-install-cai) + +--- + +## Prerequisites + +- **Operating System**: Linux, macOS, or Windows (WSL2) +- **Python**: 3.9 or higher +- **Internet Connection**: Required for initial setup +- **CAI PRO Subscription**: [Subscribe here](https://aliasrobotics.com/cybersecurityai.php) + +--- + +## Quick Start Steps + +### 1. Subscribe to CAI PRO + +Visit [https://aliasrobotics.com/cybersecurityai.php](https://aliasrobotics.com/cybersecurityai.php): + +1. Click **"Buy CAI PRO"** +2. Complete payment (€350/month, secure European processing) +3. Receive your **`ALIAS_API_KEY`** via email (within 5 minutes) + +**πŸ’‘ Tip**: Check your spam folder if you don't receive the key immediately. + +--- + +### 2. Install CAI + +#### Installation Steps + +1. **Create and navigate to your project directory:** + +```bash +mkdir cai-pro +cd cai-pro +``` + +2. **Update system packages:** + +```bash +sudo apt update +``` + +3. **Create a Python virtual environment:** + +```bash +python3.12 -m venv cai_env +``` + +4. **Activate the virtual environment:** + +```bash +source cai_env/bin/activate +``` + +5. **Install CAI PRO from private package repository:** + +```bash +pip install --index-url https://packages.aliasrobotics.com:664// cai-framework +``` + +**⚠️ Important**: Replace `` with your API Key from the subscription confirmation email. + +**Example:** +```bash +pip install --index-url https://packages.aliasrobotics.com:664/sk-xxxxxxxxxxxxxxxx/ cai-framework +``` + +**πŸ’‘ Tip**: Your API Key looks like `sk-xxxxxxxxxxxxxxxx` and is provided in your CAI PRO subscription email. + +For detailed installation instructions and troubleshooting, see the [CAI PRO Installation Guide](Installation_Guide_for_CAI_Pro_v0.6.md). + +--- + +### 3. Configure Your Environment + +Create or update your `.env` file in your project directory: + +```bash +# CAI PRO Configuration +ALIAS_API_KEY="sk-your-caipro-key-here" +CAI_MODEL="alias1" + +# Optional: Enable advanced features +CAI_TUI_MODE=true +CAI_GUARDRAILS=true +CAI_STREAM=false +``` + +**πŸ’‘ Security Tip**: Never commit `.env` files to version control. Add `.env` to your `.gitignore`. + +--- + +### 4. Verify Installation + +Test that CAI PRO is working correctly: + +```bash +# Launch CAI CLI +cai + +# Inside CAI, check your model +CAI> /model + +# You should see: +# Available models: +# - alias1 (active) βœ… +# - alias0 +# - gpt-4o (requires OPENAI_API_KEY) +# - claude-sonnet-4 (requires ANTHROPIC_API_KEY) +# ... +``` + +**Expected output**: `alias1` should be listed and marked as active. + +--- + +### 5. Run Your First Security Test + +Let's start with a simple security assessment: + +```bash +CAI> Analyze the security posture of https://testphp.vulnweb.com + +# Alias1 will: +# 1. Perform reconnaissance +# 2. Identify vulnerabilities +# 3. Suggest exploitation techniques +# 4. Provide remediation guidance +``` + +**βœ… Success!** You're now using unlimited alias1 tokens for security testing. + +--- + +## Launch Terminal UI (TUI) + +CAI PRO includes a powerful multi-terminal interface: + +```bash +# Launch TUI mode +cai --tui + +# Or set it as default in .env +echo "CAI_TUI_MODE=true" >> .env +cai +``` + +### TUI Quick Tips + +**Keyboard Shortcuts:** +- `Ctrl+S` - Toggle sidebar +- `Ctrl+N` / `Ctrl+B` - Switch between terminals +- `Ctrl+L` - Clear terminal +- `Ctrl+Q` - Exit + +**Add More Terminals:** +- Click the `[+]` button in the top bar +- Or use `/add` command + +**Load Preconfigured Teams:** +- Open sidebar (`Ctrl+S`) +- Click "Teams" tab +- Select a team (e.g., "#1: 2 red + 2 bug") + +[Full TUI Documentation β†’](tui/tui_index.md) + +--- + +## Common First Tasks + +### Task 1: Web Application Security Assessment + +```bash +CAI> Conduct a comprehensive security assessment of https://example.com + +# Alias1 will: +# - Enumerate subdomains and technologies +# - Identify OWASP Top 10 vulnerabilities +# - Test for SQL injection, XSS, CSRF +# - Generate a detailed report +``` + +### Task 2: CTF Challenge Solving + +```bash +CAI> Solve this CTF challenge: [paste challenge description] + +# Alias1 excels at: +# - Web challenges +# - Binary exploitation +# - Cryptography +# - Reverse engineering +``` + +### Task 3: Exploit Development + +```bash +CAI> Write a Python exploit for CVE-2024-1234 + +# Alias1 will: +# - Research the vulnerability +# - Develop a working exploit +# - Include error handling +# - Add comments explaining each step +``` + +### Task 4: Bug Bounty Reconnaissance + +```bash +CAI> Perform recon on https://bugbounty-target.com for a bug bounty program + +# Alias1 will: +# - Enumerate attack surface +# - Identify interesting endpoints +# - Suggest testing strategies +# - Prioritize high-value targets +``` + +--- + +## Advanced Configuration + +### Enable Context Monitoring + +Track your token usage in real-time: + +```bash +CAI> /context + +# Shows: +# - Total tokens used/available +# - Breakdown by category (system, tools, memory, messages) +# - Visual grid representation +# - Optimization suggestions +``` + +### Multi-Agent Parallel Execution + +Run multiple agents simultaneously in TUI: + +```bash +# In TUI mode, open sidebar (Ctrl+S) +# Click "Teams" tab +# Select Team #1: "2 red + 2 bug" + +# Type your prompt and press Ctrl+Shift+A to broadcast to all terminals +Scan target.com for vulnerabilities +``` + +### Save and Load Sessions + +```bash +# Save your current conversation +CAI> /save pentest_session.json + +# Load it later +CAI> /load pentest_session.json +``` + +--- + +## Troubleshooting + +### Issue: "alias1 not available" + +**Solution 1**: Check your API key +```bash +# Verify ALIAS_API_KEY is set correctly +env | grep ALIAS +``` + +**Solution 2**: Ensure you're using CAI PRO version +```bash +cai --version +# Should show v0.6.0 or higher +``` + +**Solution 3**: Contact support +- Email: support@aliasrobotics.com +- Subject: "alias1 not available - [your email]" + +--- + +### Issue: "Rate limit exceeded" + +**This shouldn't happen with CAI PRO** (unlimited tokens). If you see this: + +1. Check for typos in your `ALIAS_API_KEY` +2. Contact support immediately: support@aliasrobotics.com + +--- + +### Issue: TUI not launching + +**Solution 1**: Install required dependencies +```bash +pip install textual rich +``` + +**Solution 2**: Check terminal compatibility +```bash +# TUI requires a modern terminal emulator +# Recommended: Alacritty, iTerm2, Windows Terminal +``` + +**Solution 3**: Use CLI mode instead +```bash +# TUI is optional, CLI works everywhere +cai # without --tui flag +``` + +--- + +## Next Steps + +### πŸ“š Learn More + +- **[TUI Full Guide](tui/tui_index.md)** - Master the Terminal UI +- **[Commands Reference](tui/commands_reference.md)** - All available commands +- **[Alias1 Deep Dive](cai_pro_alias1.md)** - Understand your flagship model +- **[Features Overview](cai_pro_features.md)** - Explore all CAI PRO capabilities + +### 🎯 Practical Guides + +- **[Running Agents](running_agents.md)** - Agent selection and configuration +- **[Context Management](context.md)** - Optimize token usage +- **[Guardrails & Security](guardrails.md)** - Secure testing practices +- **[Environment Variables](environment_variables.md)** - Complete configuration reference + +### πŸ† Case Studies + +Learn from real-world CAI applications: +- [Ecoforest Heat Pumps OT Security](https://aliasrobotics.com/case-studies-robot-cybersecurity.php) +- [MiR Robot Vulnerability Discovery](https://aliasrobotics.com/case-studies-robot-cybersecurity.php) +- [Mercado Libre API Testing](https://aliasrobotics.com/case-studies-robot-cybersecurity.php) + +--- + +## Get Help + +### Professional Support (CAI PRO Subscribers) + +- **Email**: support@aliasrobotics.com (48h SLA) +- **Discord**: #pro-support channel (exclusive) +- **Quarterly Calls**: Strategy and roadmap discussions + +### Community Resources + +- **[Discord Community](https://discord.gg/fnUFcTaQAC)** - 1000+ security researchers +- **[GitHub Issues](https://github.com/aliasrobotics/cai/issues)** - Bug reports and feature requests +- **[Documentation](index.md)** - Complete CAI documentation + +--- + +## Tips for Success + +### 🎯 Best Practices + +1. **Start with clear prompts**: Be specific about your testing scope and objectives +2. **Use context monitoring**: Check `/context` regularly to optimize token usage +3. **Leverage parallel execution**: Run multiple agents for comprehensive coverage +4. **Save your sessions**: Use `/save` to preserve important conversations +5. **Enable guardrails**: Keep `CAI_GUARDRAILS=true` for safer operations + +### ⚑ Power User Tips + +- **Keyboard shortcuts**: Master `Ctrl+N`, `Ctrl+B`, `Ctrl+S` for efficient TUI navigation +- **Team presets**: Use preconfigured teams instead of manual agent setup +- **Mix models**: Use alias1 for exploitation, GPT-4o for professional reporting +- **Custom agents**: Request specialized agents for your domain (contact support) + +--- + +## Congratulations! πŸŽ‰ + +You're now ready to leverage CAI PRO for professional security testing. + +**Remember:** +- βœ… Unlimited alias1 tokens +- βœ… Zero refusals for authorized testing +- βœ… Professional support available +- βœ… European data privacy guaranteed + +**Questions?** Contact support@aliasrobotics.com + +--- + + +*Need help? We're here: **support@aliasrobotics.com*** +*Want to upgrade to Enterprise? [Request quote β†’](mailto:contact@aliasrobotics.com?subject=CAI%20Enterprise%20Inquiry)* + + diff --git a/docs/cli/advanced_usage.md b/docs/cli/advanced_usage.md new file mode 100644 index 00000000..aa515520 --- /dev/null +++ b/docs/cli/advanced_usage.md @@ -0,0 +1,1316 @@ +# Advanced Usage + +This guide covers advanced features, automation, scripting, and power-user techniques for the CAI Command Line Interface. + +--- + +## Table of Contents + +1. [Parallel Execution](#parallel-execution) +2. [Queue System](#queue-system) +3. [Automation & Scripting](#automation--scripting) +4. [Memory Management](#memory-management) +5. [Workspace & Virtualization](#workspace--virtualization) +6. [CTF Workflows](#ctf-workflows) +7. [Cost Management](#cost-management) +8. [Configuration Management](#configuration-management) +9. [Integration Patterns](#integration-patterns) +10. [Troubleshooting](#troubleshooting) + +--- + +## Parallel Execution + +Run multiple agents simultaneously to get different perspectives or distribute workload. + +### Basic Parallel Setup + +#### Method 1: Using Commands + +```bash +# Launch CAI +cai + +# Add agents to parallel configuration +CAI> /parallel add redteam_agent alias1 +CAI> /parallel add blueteam_agent alias1 +CAI> /parallel add bug_bounter_agent gpt-4o + +# List configured agents +CAI> /parallel list + +# Execute on all agents +CAI> /parallel run "analyze the security of target.com" + +# Merge results +CAI> /parallel merge +``` + +#### Method 2: Using YAML Configuration + +Create `agents.yaml`: + +```yaml +metadata: + description: "Multi-perspective security analysis" + auto_run: true + +agents: + - name: offensive + agent_type: redteam_agent + model: alias1 + + - name: defensive + agent_type: blueteam_agent + model: alias1 + + - name: bug_hunter + agent_type: bug_bounter_agent + model: gpt-4o + + - name: forensics + agent_type: dfir_agent + model: alias1 +``` + +Launch with YAML: + +```bash +cai --yaml agents.yaml --prompt "perform comprehensive security assessment of target.com" +``` + +#### Method 3: Using Environment Variable + +```bash +# Set parallel count +export CAI_PARALLEL=3 +export CAI_AGENT_TYPE=redteam_agent +export CAI_MODEL=alias1 + +cai --prompt "scan network 192.168.1.0/24" +``` + +### Advanced Parallel Patterns + +#### Pattern 1: Distributed Reconnaissance + +Split reconnaissance across multiple agents: + +```yaml +# recon_team.yaml +agents: + - name: subdomain_enum + agent_type: redteam_agent + model: alias1 + initial_prompt: "Enumerate subdomains for A-M range" + + - name: subdomain_enum2 + agent_type: redteam_agent + model: alias1 + initial_prompt: "Enumerate subdomains for N-Z range" + + - name: port_scanner + agent_type: network_security_analyzer_agent + model: alias1 + initial_prompt: "Scan all discovered hosts" + + - name: web_analyzer + agent_type: bug_bounter_agent + model: alias1 + initial_prompt: "Analyze all web services found" +``` + +```bash +cai --yaml recon_team.yaml +``` + +#### Pattern 2: Red vs Blue Analysis + +Compare offensive and defensive perspectives: + +```bash +# Configure teams +CAI> /parallel add redteam_agent alias1 +CAI> /parallel add blueteam_agent alias1 + +# Execute same analysis from different perspectives +CAI> /parallel run "analyze the security posture of this web application" + +# Compare results +CAI> /parallel merge +``` + +#### Pattern 3: Multi-Model Comparison + +Test different models on the same task: + +```yaml +# model_comparison.yaml +agents: + - name: alias_test + agent_type: bug_bounter_agent + model: alias1 + + - name: gpt4o_test + agent_type: bug_bounter_agent + model: gpt-4o + + - name: claude_test + agent_type: bug_bounter_agent + model: claude-3-5-sonnet-20241022 +``` + +### Managing Parallel Results + +```bash +# View individual agent outputs +CAI> /history 10 offensive +CAI> /history 10 defensive + +# Merge all conversations +CAI> /parallel merge + +# Save merged results +CAI> /save parallel_assessment_results.json + +# Clear parallel configuration +CAI> /parallel clear +``` + +--- + +## Queue System + +Batch process multiple prompts for automated workflows. + +### Creating Queue Files + +Create `security_checklist.txt`: + +```text +# Security Assessment Checklist +# Comments start with # and are ignored + +# Phase 1: Reconnaissance +/agent redteam_agent +Perform passive reconnaissance on target.com +Enumerate subdomains and services + +# Phase 2: Vulnerability Scanning +/agent bug_bounter_agent +Test for OWASP Top 10 vulnerabilities +Check for known CVEs in discovered services + +# Phase 3: Network Analysis +/agent network_security_analyzer_agent +$ nmap -sV -p- target.com +Analyze the network topology + +# Phase 4: Report Generation +/agent reporting_agent +Generate comprehensive security report +/save security_assessment_report.md + +# Phase 5: Cleanup +/cost +/history 50 +``` + +### Loading and Executing Queues + +#### Method 1: Auto-load on Startup + +```bash +# Set environment variable +export CAI_QUEUE_FILE="security_checklist.txt" +cai + +# Queue executes automatically +``` + +#### Method 2: Command Line Queue + +```bash +# Use semicolons to chain commands +cai --prompt "/agent redteam_agent ; scan target.com ; /save results.json" +``` + +### Advanced Queue Patterns + +#### Pattern 1: CTF Challenge Queue + +```text +# ctf_workflow.txt +/config CTF_NAME=hackableii +/config CTF_CHALLENGE=web_app +/agent redteam_agent +Analyze the CTF challenge environment +Find and exploit vulnerabilities +Extract the flag +/save ctf_solution.md +``` + +#### Pattern 2: Bug Bounty Workflow + +```text +# bugbounty_recon.txt +/agent bug_bounter_agent +/config CAI_PRICE_LIMIT=20.0 + +# Reconnaissance +Perform subdomain enumeration on target.com +Identify web technologies and frameworks +Map the attack surface + +# Testing +Test authentication mechanisms for bypasses +Check for injection vulnerabilities +Analyze API endpoints for security issues + +# Reporting +Compile findings into bug bounty report +/save bugbounty_findings.md +/cost +``` + +#### Pattern 3: Continuous Security Monitoring + +```text +# daily_security_check.txt +/agent network_security_analyzer_agent + +# Daily checks +$ nmap -sV 192.168.1.0/24 +Analyze changes from previous scan +Identify new services or hosts +Report anomalies + +/save daily_scan_$(date +%Y%m%d).json +``` + +--- + +## Automation & Scripting + +Integrate CAI into scripts and CI/CD pipelines. + +### Bash Script Integration + +#### Script 1: Automated Security Scan + +```bash +#!/bin/bash +# security_scan.sh + +TARGET="$1" +OUTPUT_DIR="./scan_results" +TIMESTAMP=$(date +%Y%m%d_%H%M%S) + +# Configuration +export CAI_MODEL=alias1 +export CAI_AGENT_TYPE=redteam_agent +export CAI_PRICE_LIMIT=10.0 +export CAI_MAX_TURNS=50 +export CAI_TRACING=false +export CAI_DEBUG=0 + +# Create output directory +mkdir -p "$OUTPUT_DIR" + +# Run CAI with automated prompt +cai --prompt " +/agent redteam_agent +Perform comprehensive security scan on $TARGET +Test for common vulnerabilities +/save $OUTPUT_DIR/scan_${TIMESTAMP}.json +/cost +/exit +" + +echo "Scan completed. Results saved to $OUTPUT_DIR/scan_${TIMESTAMP}.json" +``` + +Usage: + +```bash +chmod +x security_scan.sh +./security_scan.sh target.com +``` + +#### Script 2: Multi-Target Batch Scan + +```bash +#!/bin/bash +# batch_scan.sh + +TARGETS_FILE="$1" +OUTPUT_DIR="./batch_results" + +mkdir -p "$OUTPUT_DIR" + +while IFS= read -r target; do + echo "Scanning $target..." + + CAI_PRICE_LIMIT=5.0 cai --prompt " + /agent bug_bounter_agent + Scan $target for web vulnerabilities + /save $OUTPUT_DIR/${target//\//_}_scan.json + /exit + " + + echo "Completed: $target" + sleep 2 +done < "$TARGETS_FILE" + +echo "All scans completed!" +``` + +Usage: + +```bash +# targets.txt contains one domain per line +./batch_scan.sh targets.txt +``` + +#### Script 3: CTF Automation + +```bash +#!/bin/bash +# ctf_solver.sh + +CTF_NAME="$1" +CHALLENGE="$2" + +export CTF_NAME="$CTF_NAME" +export CTF_CHALLENGE="$CHALLENGE" +export CTF_INSIDE=true +export CAI_AGENT_TYPE=redteam_agent +export CAI_MODEL=alias1 +export CAI_MAX_TURNS=100 + +# Create queue file +cat > /tmp/ctf_queue.txt << 'EOF' +Analyze the CTF challenge +Identify vulnerabilities +Exploit and find the flag +/save ctf_solution.json +/exit +EOF + +# Run with queue +CAI_QUEUE_FILE=/tmp/ctf_queue.txt cai + +# Cleanup +rm /tmp/ctf_queue.txt +``` + +Usage: + +```bash +./ctf_solver.sh hackableii web_challenge +``` + +### CI/CD Integration + +#### GitHub Actions Example + +```yaml +# .github/workflows/security-scan.yml +name: Security Scan + +on: + push: + branches: [ main ] + schedule: + - cron: '0 2 * * *' # Daily at 2 AM + +jobs: + security-scan: + runs-on: ubuntu-latest + + steps: + - name: Checkout code + uses: actions/checkout@v3 + + - name: Setup Python + uses: actions/setup-python@v4 + with: + python-version: '3.11' + + - name: Install CAI + run: | + pip install cai + + - name: Run Security Scan + env: + ALIAS_API_KEY: ${{ secrets.ALIAS_API_KEY }} + CAI_MODEL: alias1 + CAI_PRICE_LIMIT: 10.0 + CAI_TRACING: false + run: | + cai --prompt " + /agent bug_bounter_agent + Analyze this repository for security issues + Focus on OWASP Top 10 vulnerabilities + /save security_report.json + /exit + " + + - name: Upload Results + uses: actions/upload-artifact@v3 + with: + name: security-report + path: security_report.json +``` + +#### GitLab CI Example + +```yaml +# .gitlab-ci.yml +security_scan: + stage: test + image: python:3.11 + + before_script: + - pip install cai + + script: + - | + cai --prompt " + /agent redteam_agent + Scan $CI_PROJECT_URL for vulnerabilities + /save scan_results.json + /exit + " + + artifacts: + paths: + - scan_results.json + expire_in: 1 week + + only: + - main + - merge_requests +``` + +### Non-Interactive Mode + +```bash +# Single command execution +cai --prompt "scan 192.168.1.1" > output.txt + +# Suppress interactive elements +CAI_DEBUG=0 CAI_BRIEF=true cai --prompt "quick scan" + +# Pipe output +cai --prompt "analyze" | grep -i "vulnerability" + +# JSON output for parsing +cai --prompt "scan target ; /save results.json ; /exit" +``` + +--- + +## Memory Management + +Advanced persistent memory for long-term context. + +### Episodic Memory + +Store and recall specific episodes or sessions. + +```bash +# Enable episodic memory +export CAI_MEMORY=episodic +cai + +# During session +CAI> /memory save "SQLi vulnerability found in login" +CAI> /memory save "XSS in comment section" + +# List memories +CAI> /memory list + +# Apply memory to new session +CAI> /memory apply mem_12345 +``` + +### Semantic Memory + +Store knowledge and facts. + +```bash +# Enable semantic memory +export CAI_MEMORY=semantic +cai + +# Save semantic knowledge +CAI> /memory save "Target uses Apache 2.4.41 with ModSecurity" +``` + +### Combined Memory + +Use both episodic and semantic memory: + +```bash +# Enable all memory types +export CAI_MEMORY=all +export CAI_MEMORY_ONLINE=true +export CAI_MEMORY_ONLINE_INTERVAL=5 + +cai +``` + +### Online Memory Mode + +Automatically save memory at intervals: + +```bash +# Configure online memory +export CAI_MEMORY=episodic +export CAI_MEMORY_ONLINE=true +export CAI_MEMORY_ONLINE_INTERVAL=3 # Save every 3 turns + +cai --prompt "long reconnaissance session" +``` + +### Memory Workflows + +#### Workflow 1: Multi-Day Assessment + +**Day 1:** +```bash +CAI> /agent bug_bounter_agent +CAI> Perform reconnaissance on target.com +CAI> /memory save "day1_reconnaissance" +CAI> /save day1_session.json +``` + +**Day 2:** +```bash +CAI> /agent bug_bounter_agent +CAI> /memory apply day1_reconnaissance +CAI> Continue testing based on yesterday's findings +CAI> /memory save "day2_exploitation" +``` + +#### Workflow 2: Knowledge Base + +```bash +# Build security knowledge base +CAI> /memory save "CVE-2024-1234 affects Apache < 2.4.59" +CAI> /memory save "SQL injection bypasses for ModSecurity" +CAI> /memory save "XSS payload variants for WAF bypass" + +# Later, in new session +CAI> /memory list +CAI> /memory apply mem_useful_techniques +``` + +### Memory Compaction + +Reduce memory size while preserving important information: + +```bash +# Compact current conversation +CAI> /memory compact + +# Status and statistics +CAI> /memory status +``` + +### Memory Management + +```bash +# Show specific memory +CAI> /memory show mem_12345 + +# Merge memories +CAI> /memory merge mem_12345 mem_67890 "combined_findings" + +# Delete memory +CAI> /memory delete mem_12345 +``` + +--- + +## Workspace & Virtualization + +Manage execution environments and Docker containers. + +### Workspace Management + +```bash +# Show current workspace +CAI> /workspace show + +# Change workspace +CAI> /workspace set /home/user/pentests/target_corp + +# List workspace contents +CAI> /workspace list + +# Execute commands in workspace +CAI> $ ls -la +CAI> $ cat target_info.txt +``` + +### Docker Container Execution + +#### Automatic Container Setup (CTF) + +```bash +# CTF automatically sets up container +export CTF_NAME=hackableii +export CTF_INSIDE=true +cai + +# Commands execute inside container automatically +CAI> $ whoami +CAI> $ ip addr +``` + +#### Manual Container Management + +```bash +# List available containers +CAI> /virtualization list + +# Set active container +CAI> /virtualization set ubuntu_pentest + +# All commands now execute in container +CAI> $ nmap -sV localhost + +# Return to host +CAI> /virtualization clear +``` + +### Environment Variables for Virtualization + +```bash +# CTF Configuration +export CTF_NAME=hackableii +export CTF_CHALLENGE=web_app +export CTF_SUBNET=192.168.3.0/24 +export CTF_IP=192.168.3.100 +export CTF_INSIDE=true # Execute inside container + +# Active Container +export CAI_ACTIVE_CONTAINER=abc123def456 + +cai +``` + +### Advanced Virtualization Patterns + +#### Pattern 1: Isolated Testing + +```bash +#!/bin/bash +# isolated_test.sh + +# Create isolated container +CONTAINER_ID=$(docker run -d ubuntu:latest sleep infinity) + +# Set container for CAI +export CAI_ACTIVE_CONTAINER=$CONTAINER_ID + +# Run tests +cai --prompt " +/virtualization set $CONTAINER_ID +Install and test malware sample +Analyze behavior +/save malware_analysis.json +/exit +" + +# Cleanup +docker stop $CONTAINER_ID +docker rm $CONTAINER_ID +``` + +#### Pattern 2: Multi-Container Testing + +```bash +# Test across multiple containers +CAI> /virtualization set web_server_container +CAI> $ curl http://localhost + +CAI> /virtualization set db_container +CAI> $ psql -l + +CAI> /virtualization set app_container +CAI> $ python test_exploit.py +``` + +--- + +## CTF Workflows + +Specialized workflows for Capture The Flag challenges. + +### Basic CTF Setup + +```bash +# Configure CTF environment +export CTF_NAME=hackableii +export CTF_CHALLENGE=binary_exploit +export CAI_AGENT_TYPE=redteam_agent +export CAI_MODEL=alias1 +export CAI_MAX_TURNS=inf + +cai +``` + +### CTF Challenge Types + +#### Type 1: Web Challenges + +```bash +export CTF_NAME=webchallenge +export CTF_INSIDE=true + +cai --prompt " +/agent bug_bounter_agent +Analyze this web application +Find and exploit vulnerabilities +Extract the flag +/save web_ctf_solution.md +" +``` + +#### Type 2: Binary Exploitation + +```bash +export CTF_NAME=pwn_challenge + +cai --prompt " +/agent reverse_engineering_agent +Analyze the binary +Find buffer overflow vulnerability +Develop exploit +/save exploit.py +" +``` + +#### Type 3: Forensics + +```bash +export CTF_NAME=forensics_challenge + +cai --prompt " +/agent dfir_agent +Analyze the memory dump +Extract hidden data +Find the flag +/save forensics_analysis.md +" +``` + +### Automated CTF Solver + +```bash +#!/bin/bash +# auto_ctf.sh + +CHALLENGES=( + "web_app:bug_bounter_agent" + "binary_exploit:reverse_engineering_agent" + "network_forensics:dfir_agent" + "crypto:redteam_agent" +) + +for challenge in "${CHALLENGES[@]}"; do + IFS=':' read -r name agent <<< "$challenge" + + echo "Solving $name..." + + CTF_NAME="ctf_event" \ + CTF_CHALLENGE="$name" \ + CAI_AGENT_TYPE="$agent" \ + cai --prompt " + Analyze and solve the challenge + Find the flag + /save ${name}_solution.json + /exit + " +done +``` + +### CTF with Time Limits + +```bash +# Set strict limits for CTF +export CAI_MAX_TURNS=50 +export CAI_MAX_INTERACTIONS=200 +export CAI_PRICE_LIMIT=5.0 + +# Force exit if flag not found +# (requires force_until_flag mode) +cai --prompt "solve the CTF challenge" +``` + +--- + +## Cost Management + +Control and optimize API usage costs. + +### Setting Cost Limits + +```bash +# Set price limit +export CAI_PRICE_LIMIT=10.0 + +# Set interaction limit +export CAI_MAX_INTERACTIONS=100 + +# Set turn limit +export CAI_MAX_TURNS=50 + +cai +``` + +### Runtime Cost Adjustment + +```bash +# Check current costs +CAI> /cost + +# Increase limit if needed +CAI> /config CAI_PRICE_LIMIT=20.0 + +# Check updated limit +CAI> /config | grep PRICE_LIMIT +``` + +### Cost Optimization Strategies + +#### Strategy 1: Model Selection + +```bash +# Use cheaper models for reconnaissance +CAI> /agent redteam_agent +CAI> /model alias1 # Balanced cost/performance + +# Use powerful models for complex analysis +CAI> /model gpt-4o +CAI> Analyze complex vulnerability chain +``` + +#### Strategy 2: Conversation Compaction + +```bash +# When approaching token limits +CAI> /compact + +# Or set automatic compaction +export CAI_AUTO_COMPACT=true +``` + +#### Strategy 3: Targeted Prompts + +```bash +# Be specific to reduce back-and-forth +CAI> Scan 192.168.1.1 ports 80,443,8080 with nmap -sV + +# Instead of: +CAI> Scan 192.168.1.1 +# (agent asks which ports) +# (multiple turns = higher cost) +``` + +### Cost Monitoring + +```bash +# View detailed cost breakdown +CAI> /cost + +# Per-agent costs +CAI> /cost redteam_agent +CAI> /cost bug_bounter_agent + +# Session statistics +CAI> /history +CAI> /cost all +``` + +### Budget-Constrained Workflows + +```bash +#!/bin/bash +# budget_scan.sh + +# Set strict budget +export CAI_PRICE_LIMIT=2.0 +export CAI_MODEL=alias1 # Cost-effective model + +cai --prompt " +/agent redteam_agent +Quick vulnerability scan on $TARGET +Focus on critical issues only +/cost +/save budget_scan.json +/exit +" + +# Check if limit was hit +if grep -q "price limit" budget_scan.json; then + echo "Warning: Price limit reached" +fi +``` + +--- + +## Configuration Management + +Advanced configuration patterns. + +### Configuration Profiles + +#### Profile 1: Development + +```bash +# dev_profile.env +export CAI_MODEL=alias1 +export CAI_DEBUG=2 +export CAI_PRICE_LIMIT=5.0 +export CAI_TRACING=true +export CAI_MAX_TURNS=20 +``` + +Usage: +```bash +source dev_profile.env +cai +``` + +#### Profile 2: Production + +```bash +# prod_profile.env +export CAI_MODEL=alias1 +export CAI_DEBUG=0 +export CAI_BRIEF=true +export CAI_PRICE_LIMIT=50.0 +export CAI_TRACING=false +export CAI_GUARDRAILS=true +``` + +#### Profile 3: CTF + +```bash +# ctf_profile.env +export CAI_MODEL=alias1 +export CAI_AGENT_TYPE=redteam_agent +export CAI_MAX_TURNS=inf +export CAI_PRICE_LIMIT=20.0 +export CAI_DEBUG=1 +``` + +### Per-Agent Model Override + +```bash +# Set different models for different agents +export CAI_REDTEAM_AGENT_MODEL=gpt-4o +export CAI_BUG_BOUNTER_AGENT_MODEL=alias1 +export CAI_DFIR_AGENT_MODEL=claude-3-5-sonnet-20241022 + +# Default model for others +export CAI_MODEL=alias1 + +cai +``` + +### Dynamic Configuration + +```bash +# Start with base config +CAI> /config + +# Adjust during session +CAI> /config CAI_DEBUG=2 +CAI> /config CAI_PRICE_LIMIT=15.0 + +# Verify changes +CAI> /env | grep CAI +``` + +--- + +## Integration Patterns + +Integrate CAI with other tools and services. + +### MCP Integration + +#### Pattern 1: Burp Suite Integration + +```bash +# Start Burp Suite MCP server +# (in separate terminal) +burp-mcp-server --port 9876 + +# In CAI +CAI> /mcp load http://localhost:9876/sse burp +CAI> /mcp tools burp +CAI> /mcp add redteam_agent burp + +# Use Burp tools +CAI> Use Burp to scan https://target.com +``` + +#### Pattern 2: Custom Tool Integration + +```bash +# Load custom MCP server +CAI> /mcp load stdio "python my_custom_tools.py" custom + +# Add to agent +CAI> /mcp add bug_bounter_agent custom + +# Use custom tools +CAI> Use custom scanner on target +``` + +### API Integration + +```bash +#!/bin/bash +# api_integration.sh + +# Get CAI results +RESULT=$(cai --prompt "scan $TARGET ; /save -" 2>/dev/null) + +# Send to external API +curl -X POST https://api.security-platform.com/scans \ + -H "Content-Type: application/json" \ + -d "$RESULT" +``` + +### Webhook Integration + +```bash +#!/bin/bash +# webhook_notify.sh + +# Run scan +cai --prompt "security scan on $TARGET ; /save results.json" + +# Send webhook notification +curl -X POST $WEBHOOK_URL \ + -H "Content-Type: application/json" \ + -d '{ + "target": "'$TARGET'", + "status": "complete", + "results": "'$(cat results.json)'" + }' +``` + +--- + +## Troubleshooting + +Common issues and solutions. + +### Issue: Price Limit Reached + +```bash +# Check current cost +CAI> /cost + +# Increase limit +CAI> /config CAI_PRICE_LIMIT=20.0 + +# Or restart with higher limit +exit +CAI_PRICE_LIMIT=20.0 cai +``` + +### Issue: Max Interactions Exceeded + +```bash +# Check current count +CAI> /env | grep MAX_INTERACTIONS + +# Increase limit +CAI> /config CAI_MAX_INTERACTIONS=500 + +# Or use /flush to start fresh +CAI> /flush +``` + +### Issue: Agent Not Responding + +```bash +# Interrupt current operation +Ctrl+C + +# Check agent status +CAI> /agent + +# Switch to different agent +CAI> /agent redteam_agent + +# Check configuration +CAI> /config +``` + +### Issue: Context Window Full + +```bash +# Check context usage (CAI PRO) +CAI> /context + +# Compact conversation +CAI> /compact + +# Or flush and start fresh +CAI> /flush +``` + +### Issue: Container Execution Problems + +```bash +# Check virtualization status +CAI> /virtualization info + +# List containers +CAI> /virtualization list + +# Clear container setting +CAI> /virtualization clear + +# Verify workspace +CAI> /workspace show +``` + +### Issue: Memory Loading Fails + +```bash +# Check memory status +CAI> /memory status + +# List available memories +CAI> /memory list + +# Clear corrupted memory +CAI> /memory delete mem_problematic + +# Check storage directory +$ ls -la ~/.cai/memory/ +``` + +### Debug Mode + +```bash +# Enable maximum debugging +export CAI_DEBUG=2 +cai + +# Or enable during session +CAI> /config CAI_DEBUG=2 +``` + +--- + +## Best Practices + +### 1. Session Management + +```bash +# Always save important sessions +CAI> /save project_name_$(date +%Y%m%d).json + +# Use descriptive filenames +CAI> /save pentest_target_corp_phase1.json +``` + +### 2. Cost Control + +```bash +# Set reasonable limits +export CAI_PRICE_LIMIT=10.0 +export CAI_MAX_TURNS=50 + +# Monitor regularly +CAI> /cost +``` + +### 3. Agent Selection + +```bash +# Use specialized agents +# βœ… Good: /agent bug_bounter_agent for web apps +# ❌ Bad: /agent one_tool_agent for complex tasks + +# Let selection_agent help +CAI> /agent selection_agent +CAI> I need to test a mobile application +``` + +### 4. Parallel Execution + +```bash +# Use YAML for complex setups +# βœ… Good: cai --yaml team_config.yaml +# ❌ Bad: Manual /parallel add for many agents +``` + +### 5. Memory Usage + +```bash +# Save important findings +CAI> /memory save "critical vulnerability in auth system" + +# Use descriptive names +# βœ… Good: "SQLi in admin panel - bypasses WAF" +# ❌ Bad: "bug1" +``` + +--- + +## Quick Reference + +### Environment Variables + +| Variable | Purpose | Example | +|----------|---------|---------| +| `CAI_MODEL` | Default model | `alias1` | +| `CAI_AGENT_TYPE` | Default agent | `redteam_agent` | +| `CAI_PARALLEL` | Parallel count | `3` | +| `CAI_QUEUE_FILE` | Auto-load queue | `prompts.txt` | +| `CAI_MEMORY` | Memory mode | `episodic` | +| `CAI_MEMORY_ONLINE` | Auto-save memory | `true` | +| `CAI_PRICE_LIMIT` | Cost limit | `10.0` | +| `CAI_MAX_TURNS` | Turn limit | `50` | +| `CAI_ACTIVE_CONTAINER` | Docker container | `abc123` | + +### Command Patterns + +```bash +# Automation +cai --prompt "command ; command ; command" +CAI_QUEUE_FILE=file.txt cai + +# Parallel +cai --yaml agents.yaml --prompt "task" +CAI_PARALLEL=3 cai + +# CTF +CTF_NAME=challenge cai +``` + +--- + +## Next Steps + +- πŸ“– [Getting Started](getting_started.md) - Basic usage +- πŸ“š [Commands Reference](commands_reference.md) - All commands +- 🏠 [CLI Overview](cli_index.md) - Main documentation + +--- + +*Last updated: November 2025 | CAI CLI v0.6+* + diff --git a/docs/cli/cli_index.md b/docs/cli/cli_index.md new file mode 100644 index 00000000..887de66e --- /dev/null +++ b/docs/cli/cli_index.md @@ -0,0 +1,356 @@ +# CAI Command Line Interface (CLI) + +The CAI CLI provides a powerful, terminal-based interface for interacting with cybersecurity AI agents through a traditional command-line environment, optimized for automation, scripting, and integration workflows. + +``` + CCCCCCCCCCCCC ++++++++ ++++++++ IIIIIIIIII + CCC::::::::::::C ++++++++++ ++++++++++ I::::::::I + CC:::::::::::::::C ++++++++++ ++++++++++ I::::::::I + C:::::CCCCCCCC::::C +++++++++ ++ +++++++++ II::::::II + C:::::C CCCCCC +++++++ +++++ +++++++ I::::I + C:::::C +++++ +++++++ +++++ I::::I + C:::::C ++++ ++++ I::::I + C:::::C ++ ++ I::::I + C:::::C + +++++++++++++++ + I::::I + C:::::C +++++++++++++++++++ I::::I + C:::::C +++++++++++++++++ I::::I + C:::::C CCCCCC +++++++++++++++ I::::I + C:::::CCCCCCCC::::C +++++++++++++ II::::::II + CC:::::::::::::::C +++++++++ I::::::::I + CCC::::::::::::C +++++ I::::::::I + CCCCCCCCCCCCC ++ IIIIIIIIII + + Cybersecurity AI (CAI), v0.6.0 + Bug bounty-ready AI + +CAI> +``` + +## Overview + +The CLI is the foundational interface for CAI, offering: + +- **⚑ Lightweight Execution**: Minimal resource overhead for maximum performance +- **πŸ€– Direct Agent Interaction**: Immediate access to all CAI agents +- **πŸ“ Command System**: 30+ built-in commands for complete control +- **πŸ”„ Automation Ready**: Perfect for scripting and CI/CD pipelines +- **🧩 Queue System**: Batch processing with command chaining +- **βš™οΈ Parallel Execution**: Run multiple agents simultaneously +- **πŸ’Ύ Session Management**: Save and restore conversations +- **πŸ”§ Shell Integration**: Direct shell command execution + +## When to Use the CLI vs TUI + +| Feature | CLI | TUI | +|---------|-----|-----| +| **Scripting/Automation** | βœ… Full support | ❌ Interactive only | +| **CI/CD Integration** | βœ… Perfect fit | ❌ Not suitable | +| **Resource Usage** | βœ… Minimal | ⚠️ Higher (UI overhead) | +| **Batch Processing** | βœ… Queue system | ⚠️ Limited | +| **Visual Feedback** | ⚠️ Text-based | βœ… Rich UI | +| **Multi-agent Workflows** | βœ… Parallel mode | βœ… Visual split-screen | +| **Remote/Headless** | βœ… SSH friendly | ⚠️ Requires terminal UI | +| **Learning Curve** | ⚠️ Steeper | βœ… Intuitive | + +**Use CLI for**: Automation, scripting, CI/CD, headless servers, SSH sessions, batch processing + +**Use TUI for**: Interactive testing, visual multi-agent workflows, exploratory analysis, real-time monitoring + +## Quick Start + +Launch the CLI: + +```bash +cai +``` + +With an initial prompt: + +```bash +cai --prompt "scan 192.168.1.1 for open ports" +``` + +With YAML configuration: + +```bash +cai --yaml agents.yaml +``` + +Basic workflow: + +1. Launch CAI: `cai` +2. Configure API key in `.env` or environment +3. Select a model: `/model alias1` +4. Choose an agent: `/agent redteam_agent` +5. Type your prompt and press **Enter** + +See the [Getting Started Guide](getting_started.md) for detailed instructions. + +## Key Features + +### 🎯 Command System + +Over 30 built-in commands organized by category: + +- **Agent Management**: `/agent`, `/parallel`, `/run` +- **Memory & History**: `/memory`, `/history`, `/compact`, `/flush`, `/load`, `/merge` +- **Environment & Config**: `/config`, `/env`, `/workspace`, `/virtualization` +- **Tools & Integration**: `/mcp`, `/platform`, `/shell` +- **Utilities**: `/model`, `/graph`, `/context`, `/cost`, `/help` + +All commands support aliases for faster typing (e.g., `/a` for `/agent`, `/h` for `/help`). + +Learn more: [Commands Reference](commands_reference.md) + + +### ⚑ Parallel Execution + +Run multiple agents simultaneously: + +```bash +# Configure parallel agents +/parallel add redteam_agent +/parallel add bug_bounter_agent +/parallel add blueteam_agent + +# Execute on all agents +/parallel run "analyze target.com" +``` + +Or use YAML configuration: + +```bash +cai --yaml agents.yaml --prompt "test application security" +``` + +Learn more: [Advanced Usage](advanced_usage.md) + +### πŸ’» Shell Integration + +Execute shell commands directly: + +```bash +# Using /shell command +/shell nmap -sV 192.168.1.1 + +# Using $ shortcut +$ whoami + +# Using /$ alias +/$ ls -la +``` + +### πŸ’Ύ Session Management + +Save and restore conversations: + +```bash +# Save current session +/save pentest_session.json + +# Save as Markdown report +/save findings_report.md + +# Load previous session +/load pentest_session.json +``` + +### 🧠 Memory Management + +Advanced memory features for long-term context: + +```bash +# Enable episodic memory +CAI_MEMORY=episodic cai + +# Save memory snapshot +/memory save "web app vulnerabilities found" + +# List saved memories +/memory list + +# Apply memory to current session +/memory apply mem_12345 +``` + +## System Requirements + +- **Python**: 3.9 or higher +- **Terminal**: Any modern terminal (bash, zsh, fish) +- **API Key**: Valid `ALIAS_API_KEY` (get one from [Alias Robotics](https://aliasrobotics.com)) +- **Operating System**: Linux, macOS, Windows (WSL recommended) + +### Supported Terminals + +- βœ… bash (Linux/macOS/WSL) +- βœ… zsh (macOS/Linux) +- βœ… fish (Linux/macOS) +- βœ… PowerShell (Windows) +- βœ… SSH sessions +- βœ… tmux/screen +- βœ… CI/CD environments + +## Architecture + +``` +CAI CLI +β”œβ”€β”€ Core Components +β”‚ β”œβ”€β”€ run_cai_cli - Main interactive loop +β”‚ β”œβ”€β”€ AgentManager - Agent lifecycle management +β”‚ β”œβ”€β”€ CommandRegistry - Command routing and execution +β”‚ └── SessionRecorder - Session logging and persistence +β”œβ”€β”€ Command System +β”‚ β”œβ”€β”€ AgentCommand - Agent switching and management +β”‚ β”œβ”€β”€ ParallelCommand - Multi-agent coordination +β”‚ β”œβ”€β”€ MCPCommand - External tool integration +β”‚ β”œβ”€β”€ ConfigCommand - Environment management +β”‚ └── 25+ additional commands +└── Integration Layer + β”œβ”€β”€ PromptToolkit - Input handling and completion + β”œβ”€β”€ FuzzyCompleter - Intelligent autocompletion + β”œβ”€β”€ QueueManager - Batch execution + └── ShellExecutor - Direct shell access +``` + +For technical details, see the [Architecture Overview](../cai_architecture.md). + +## Common Use Cases + +### 1. CTF Challenges + +```bash +# Set up CTF environment +export CTF_NAME="hackableii" +export CTF_CHALLENGE="web_challenge" +export CAI_AGENT_TYPE="redteam_agent" + +# Launch with auto-execution +cai --prompt "analyze the challenge and find the flag" +``` + +### 2. Bug Bounty Automation + +```bash +# Configure bug bounty workflow +/agent bug_bounter_agent +/model alias1 + +# Execute reconnaissance +Perform full reconnaissance on bugcrowd.example.com +``` + +### 3. CI/CD Security Testing + +```bash +#!/bin/bash +# security-check.sh + +export CAI_MAX_TURNS=10 +export CAI_PRICE_LIMIT=5.0 +export CAI_TRACING=false + +cai --prompt "scan $CI_TARGET for OWASP Top 10 vulnerabilities ; generate JSON report" > security-report.json +``` + +### 4. Parallel Reconnaissance + +```bash +# agents.yaml +agents: + - name: subdomain_scanner + agent_type: redteam_agent + model: alias1 + - name: port_scanner + agent_type: network_security_analyzer_agent + model: alias1 + - name: vulnerability_checker + agent_type: bug_bounter_agent + model: alias1 + +# Execute +cai --yaml agents.yaml --prompt "full reconnaissance on target.com" +``` + +## Quick Reference + +### Essential Commands + +| Command | Description | Example | +|---------|-------------|---------| +| `/agent list` | List all agents | `/agent list` | +| `/agent ` | Switch agent | `/agent redteam_agent` | +| `/model ` | Change model | `/model alias1` | +| `/config` | View configuration | `/config` | +| `/help` | Show help | `/help agent` | +| `/save ` | Save session | `/save session.json` | +| `/load ` | Load session | `/load session.json` | +| `/cost` | Show costs | `/cost` | + +### Keyboard Shortcuts + +| Shortcut | Action | +|----------|--------| +| `Tab` | Autocomplete commands | +| `↑/↓` | Navigate command history | +| `Ctrl+C` | Interrupt execution | +| `Ctrl+L` | Clear screen | +| `Ctrl+D` | Exit CAI | +| `Ctrl+Z` | Suspend process | +| `Ctrl+X Ctrl+E` | Open editor | + +See the complete [Commands Reference](commands_reference.md) for all commands. + +## Configuration + +CAI CLI can be configured via: + +1. **Environment Variables**: `CAI_MODEL`, `CAI_AGENT_TYPE`, etc. +2. **`.env` File**: Place in your working directory +3. **`/config` Command**: Runtime configuration changes +4. **YAML Files**: Agent and workflow definitions + +Example `.env`: + +```env +ALIAS_API_KEY=ak_live_1234567890abcdef +CAI_MODEL=alias1 +CAI_AGENT_TYPE=redteam_agent +CAI_DEBUG=1 +CAI_PRICE_LIMIT=10.0 +CAI_MAX_TURNS=50 +``` + +For all configuration options, see [Configuration Guide](../getting-started/configuration.md). + +## Documentation Structure + +### For New Users +1. [Getting Started](getting_started.md) - First steps and basic usage +2. [Commands Reference](commands_reference.md) - Essential commands + +### For Advanced Users +3. [Commands Reference](commands_reference.md) - Complete command list +4. [Advanced Usage](advanced_usage.md) - Automation, scripting, and advanced features + +### Related Documentation +- [Configuration Guide](../getting-started/configuration.md) - All environment variables +- [Architecture Overview](../cai_architecture.md) - Technical architecture +- [TUI Documentation](../tui/tui_index.md) - Terminal UI alternative + +## Community and Support + +- **Documentation**: [https://docs.aliasrobotics.com](https://docs.aliasrobotics.com) +- **GitHub Issues**: [https://github.com/aliasrobotics/cai/issues](https://github.com/aliasrobotics/cai/issues) +- **Discord**: [Join our community](https://discord.gg/aliasrobotics) +- **Twitter**: [@aliasrobotics](https://twitter.com/aliasrobotics) + +## What's Next? + +- πŸ“– [Getting Started Guide](getting_started.md) - Learn the basics +- πŸ“š [Commands Reference](commands_reference.md) - Master all commands +- πŸš€ [Advanced Usage](advanced_usage.md) - Unlock powerful features + +--- + +*Last updated: November 2025 | CAI CLI v0.6+* + diff --git a/docs/cli/commands_reference.md b/docs/cli/commands_reference.md new file mode 100644 index 00000000..4cc1e12d --- /dev/null +++ b/docs/cli/commands_reference.md @@ -0,0 +1,1291 @@ +# CAI CLI Commands Reference + +This comprehensive guide documents all commands available in the CAI Command Line Interface, organized by category for easy navigation. + +--- + +## Command Categories + +1. [Agent Management](#agent-management) +2. [Model Management](#model-management) +3. [Memory & History](#memory--history) +4. [Environment & Configuration](#environment--configuration) +5. [Tools & Integration](#tools--integration) +6. [System Management](#system-management) +7. [Parallel Execution](#parallel-execution) +8. [Utilities](#utilities) + +--- + +## Agent Management + +### `/agent` or `/a` + +Manage and switch between different AI agents. + +**Syntax**: +```bash +/agent [subcommand] [arguments] +/a [subcommand] [arguments] +``` + +**Subcommands**: + +#### `list` +List all available agents with their descriptions. + +```bash +/agent list +``` + +**Output**: Table showing agent names, descriptions, and primary use cases. + +#### `` +Switch to a specific agent. + +```bash +/agent redteam_agent +/agent bug_bounter_agent +/a blueteam_agent +``` + +#### `info` or `info ` +Display detailed information about the current or specified agent. + +```bash +# Current agent info +/agent info + +# Specific agent info +/agent info redteam_agent +``` + +**Examples**: + +```bash +# List all agents +CAI> /agent list + +# Switch to red team agent +CAI> /agent redteam_agent + +# Switch to bug bounty agent (using alias) +CAI> /a bug_bounter_agent + +# Get info about DFIR agent +CAI> /agent info dfir_agent +``` + +**Available Agents**: + +| Agent | Use Case | +|-------|----------| +| `redteam_agent` | Offensive security testing | +| `blueteam_agent` | Defensive security analysis | +| `bug_bounter_agent` | Bug bounty hunting | +| `one_tool_agent` | Single-tool execution | +| `dfir_agent` | Digital forensics | +| `reverse_engineering_agent` | Binary analysis | +| `network_security_analyzer_agent` | Network security | +| `wifi_security_agent` | WiFi security testing | +| `android_sast_agent` | Android security analysis | +| `selection_agent` | Agent recommendation | + +**Notes**: +- Agent changes are immediate +- Conversation history is preserved when switching +- Each agent has specialized tools and instructions + +--- + +## Model Management + +### `/model` or `/mod` + +View or change the current LLM model. + +**Syntax**: +```bash +/model [model_name] +/mod [model_name] +``` + +**Examples**: + +```bash +# View current model +CAI> /model + +# Change to alias1 +CAI> /model alias1 + +# Change to GPT-4o +CAI> /model gpt-4o + +# Change to Claude +CAI> /model claude-3-5-sonnet-20241022 +``` + +### `/model-show` + +Display all available models from the LiteLLM repository. + +**Syntax**: +```bash +/model-show +``` + +**Output**: Comprehensive list of models by provider (OpenAI, Anthropic, Ollama, etc.) + +**Examples**: + +```bash +# Show all available models +CAI> /model-show + +# Then select one +CAI> /model gpt-4o +``` + +**Commonly Used Models**: + +| Model | Provider | Cost | Best For | +|-------|----------|------|----------| +| `alias1` | Alias Robotics | Medium | Balanced performance ⭐ | +| `gpt-4o` | OpenAI | High | Complex reasoning | +| `claude-3-5-sonnet-20241022` | Anthropic | High | Fast & accurate | +| `o1-mini` | OpenAI | Medium | Reasoning tasks | + +--- + +## Memory & History + +### `/history` or `/his` + +Display conversation history. + +**Syntax**: +```bash +/history [number] [agent_name] +/his [number] +``` + +**Parameters**: +- `number`: Number of recent messages to show (default: 10) +- `agent_name`: Filter by specific agent + +**Examples**: + +```bash +# Show last 10 messages +CAI> /history + +# Show last 20 messages +CAI> /history 20 + +# Show last 5 messages +CAI> /his 5 + +# Show history for specific agent +CAI> /history 10 redteam_agent +``` + +**Output**: Formatted conversation with timestamps, roles (user/agent), and message content. + +--- + +### `/memory` or `/mem` + +Manage persistent memory storage across sessions. + +**Syntax**: +```bash +/memory [arguments] +/mem [arguments] +``` + +**Subcommands**: + +#### `list` +Show all saved memories. + +```bash +/memory list +``` + +#### `save [name]` +Save current conversation as a memory. + +```bash +/memory save "web app pentest findings" +/mem save ctf_techniques +``` + +#### `apply ` +Apply a saved memory to the current session. + +```bash +/memory apply mem_12345 +``` + +#### `show ` +Display the content of a specific memory. + +```bash +/memory show mem_12345 +``` + +#### `delete ` +Remove a memory permanently. + +```bash +/memory delete mem_12345 +``` + +#### `merge [name]` +Combine two memories into one. + +```bash +/memory merge mem_12345 mem_67890 "combined_findings" +``` + +#### `compact` +AI-powered memory summarization. + +```bash +/memory compact +``` + +#### `status` +Show memory system status and statistics. + +```bash +/memory status +``` + +**Examples**: + +```bash +# Save current session insights +CAI> /memory save "SQLi vulnerabilities found" + +# List all memories +CAI> /memory list + +# Apply previous knowledge +CAI> /memory apply mem_12345 + +# Check memory status +CAI> /mem status +``` + +**Notes**: +- Memories persist across sessions +- Stored in `.cai/memory/` directory +- Useful for long-term research projects + +--- + +### `/compact` or `/cmp` + +Compact the current conversation to reduce context size. + +**Syntax**: +```bash +/compact [model_name] +/cmp +``` + +**Parameters**: +- `model_name`: Optional model to use for compaction + +**Examples**: + +```bash +# Compact with current model +CAI> /compact + +# Compact with specific model +CAI> /compact alias1 +``` + +**Use Cases**: +- Approaching token limits +- Long conversations that need summarization +- Maintaining conversation flow with reduced tokens + +--- + +### `/flush` or `/clear` + +Clear conversation history. + +**Syntax**: +```bash +/flush [agent_name|all] +/clear +``` + +**Parameters**: +- `agent_name`: Flush specific agent history +- `all`: Flush all agent histories + +**Examples**: + +```bash +# Flush current agent +CAI> /flush + +# Flush specific agent +CAI> /flush redteam_agent + +# Flush all agents +CAI> /flush all +``` + +**Warning**: This action is irreversible. Consider using `/save` first. + +--- + +### `/load` or `/l` + +Load conversation history from a file. + +**Syntax**: +```bash +/load +/l +``` + +**Supported Formats**: +- JSON (`.json`) +- JSONL (`.jsonl`) +- Markdown (`.md`) + +**Examples**: + +```bash +# Load JSON session +CAI> /load pentest_session.json + +# Load JSONL data +CAI> /load conversation.jsonl + +# Using alias +CAI> /l ~/sessions/previous_work.json +``` + +**Notes**: +- Restores conversation context +- Compatible with `/save` output +- Can load partial histories + +--- + +### `/merge` or `/mrg` + +Merge agent message histories (shortcut for `/parallel merge`). + +**Syntax**: +```bash +/merge [agent1] [agent2] +/mrg +``` + +**Examples**: + +```bash +# Merge all parallel agents +CAI> /merge + +# Merge specific agents +CAI> /merge redteam_agent blueteam_agent +``` + +**Use Cases**: +- Combining parallel execution results +- Integrating different agent perspectives + +--- + +## Environment & Configuration + +### `/config` or `/cfg` + +Display and configure environment variables. + +**Syntax**: +```bash +/config [VARIABLE=value] +/config set +/cfg +``` + +**Examples**: + +```bash +# View all configuration +CAI> /config + +# Set by variable name +CAI> /config CAI_PRICE_LIMIT=10.0 +CAI> /config CAI_MAX_TURNS=50 + +# Set by number (from /config output) +CAI> /config set 18 "5.0" +``` + +**Common Configuration Variables**: + +| Variable | Description | Default | +|----------|-------------|---------| +| `CAI_MODEL` | Default model | `alias1` | +| `CAI_AGENT_TYPE` | Default agent | `redteam_agent` | +| `CAI_DEBUG` | Debug level (0-2) | `1` | +| `CAI_PRICE_LIMIT` | Cost limit (USD) | `1.0` | +| `CAI_MAX_TURNS` | Max conversation turns | `inf` | +| `CAI_MAX_INTERACTIONS` | Max tool calls | `inf` | +| `CAI_TRACING` | Enable tracing | `true` | +| `CAI_GUARDRAILS` | Security guardrails | `false` | + +**Notes**: +- Changes take effect immediately +- Use `/config` without arguments to see all options +- Numbers in first column can be used with `set` subcommand + +--- + +### `/env` or `/e` + +Display current environment variables. + +**Syntax**: +```bash +/env [pattern] +/e +``` + +**Parameters**: +- `pattern`: Optional filter pattern (e.g., "CAI", "CTF") + +**Examples**: + +```bash +# Show all environment variables +CAI> /env + +# Filter CAI-specific variables +CAI> /env CAI + +# Filter CTF variables +CAI> /env CTF +``` + +--- + +### `/workspace` or `/ws` + +Manage workspace directories. + +**Syntax**: +```bash +/workspace [path] +/ws +``` + +**Subcommands**: + +#### `show` or `pwd` +Display current workspace directory. + +```bash +/workspace show +/ws pwd +``` + +#### `set ` +Change workspace directory. + +```bash +/workspace set /path/to/project +/ws set ~/ctf_challenges +``` + +#### `list` or `ls` +List workspace contents. + +```bash +/workspace list +/ws ls +``` + +**Examples**: + +```bash +# Show current workspace +CAI> /workspace show + +# Change workspace +CAI> /workspace set /home/user/pentests + +# List files +CAI> /ws ls +``` + +**Notes**: +- Affects where shell commands execute +- Useful for CTF challenges and projects +- Works with Docker containers + +--- + +### `/virtualization` or `/virt` + +Manage Docker-based virtualization environments. + +**Syntax**: +```bash +/virtualization [arguments] +/virt +``` + +**Subcommands**: + +#### `list` +List available containers. + +```bash +/virtualization list +``` + +#### `set ` +Set active container for command execution. + +```bash +/virtualization set abc123def456 +/virt set mycontainer +``` + +#### `clear` +Return to host environment. + +```bash +/virtualization clear +``` + +#### `info` +Show current virtualization status. + +```bash +/virtualization info +``` + +**Examples**: + +```bash +# List containers +CAI> /virtualization list + +# Execute commands in container +CAI> /virt set ubuntu_ctf + +# Return to host +CAI> /virt clear +``` + +**Notes**: +- Automatically set when CTF challenges start +- Commands execute inside specified container +- Uses `CAI_ACTIVE_CONTAINER` environment variable + +--- + +## Tools & Integration + +### `/mcp` or `/m` + +Manage Model Context Protocol (MCP) servers and their tools. + +**Syntax**: +```bash +/mcp [arguments] +/m +``` + +**Subcommands**: + +#### `load ` +Load an SSE MCP server. + +```bash +/mcp load http://localhost:9876/sse burp +``` + +#### `load stdio ` +Load a STDIO MCP server. + +```bash +/mcp load stdio "npx -y @modelcontextprotocol/server-brave-search" brave +``` + +#### `list` +List active MCP connections. + +```bash +/mcp list +``` + +#### `add ` +Add MCP tools to an agent. + +```bash +/mcp add redteam_agent burp +``` + +#### `remove ` +Remove an MCP server connection. + +```bash +/mcp remove burp +``` + +#### `tools ` +List tools from an MCP server. + +```bash +/mcp tools burp +``` + +#### `status` +Check MCP server connection status. + +```bash +/mcp status +``` + +#### `associations` +Show agent-MCP associations. + +```bash +/mcp associations +``` + +**Examples**: + +```bash +# Load Burp Suite MCP server +CAI> /mcp load http://localhost:9876/sse burp + +# List MCP tools +CAI> /mcp tools burp + +# Add to current agent +CAI> /mcp add redteam_agent burp + +# Check status +CAI> /mcp status +``` + +**Common MCP Servers**: +- **Burp Suite**: Web application testing tools +- **Brave Search**: Web search capabilities +- **Filesystem**: File operations +- **Git**: Repository management +- **Postgres**: Database operations + +**Notes**: +- Extends agent capabilities dynamically +- Supports both SSE and STDIO protocols +- See [MCP Documentation](../cai/getting-started/MCP.md) for details + +--- + +### `/shell` or `/s` or `/$` + +Execute shell commands directly from the CLI. + +**Syntax**: +```bash +/shell +/s +$ +``` + +**Examples**: + +```bash +# Using /shell +CAI> /shell nmap -sV 192.168.1.1 + +# Using /s alias +CAI> /s whoami + +# Using $ shortcut +CAI> $ ls -la + +# Complex commands +CAI> $ nmap -sV -p- 192.168.1.0/24 -oN scan_results.txt +``` + +**Notes**: +- Commands execute in current workspace +- Respects `CAI_ACTIVE_CONTAINER` if set +- Output displayed in real-time +- `Ctrl+C` to interrupt running commands + +--- + +## System Management + +### `/kill` or `/k` + +Terminate active processes or stuck sessions. + +**Syntax**: +```bash +/kill +/k +``` + +**Examples**: + +```bash +# Kill current process +CAI> /kill + +# Alternative: Ctrl+C +``` + +**Use Cases**: +- Stopping stuck tool executions +- Canceling long-running operations +- Interrupting agent loops + +--- + +### `/exit` or `/quit` or `/q` + +Exit the CAI CLI. + +**Syntax**: +```bash +/exit +/quit +/q +``` + +**Examples**: + +```bash +# Exit CAI +CAI> /exit + +# Alternative: Ctrl+D +``` + +**Notes**: +- Performs clean shutdown +- Saves session logs +- Stops background processes + +--- + +### `/quickstart` + +Display setup information and quick start guide. + +**Syntax**: +```bash +/quickstart +``` + +**Examples**: + +```bash +# Show quickstart guide +CAI> /quickstart +``` + +**Notes**: +- Auto-displays on first launch +- Useful for new users +- Shows essential commands and setup + +--- + +## Parallel Execution + +### `/parallel` or `/par` or `/p` + +Manage parallel agent configurations and execution. + +**Syntax**: +```bash +/parallel [arguments] +/par +/p +``` + +**Subcommands**: + +#### `add [model]` +Add an agent to parallel configuration. + +```bash +/parallel add redteam_agent alias1 +/par add bug_bounter_agent gpt-4o +``` + +#### `remove ` +Remove an agent from parallel configuration. + +```bash +/parallel remove P1 +``` + +#### `list` +List all parallel agents. + +```bash +/parallel list +``` + +#### `clear` +Clear all parallel configurations. + +```bash +/parallel clear +``` + +#### `run ` +Execute a prompt across all parallel agents. + +```bash +/parallel run "scan 192.168.1.1 for vulnerabilities" +``` + +#### `merge` +Merge all parallel agent histories. + +```bash +/parallel merge +``` + +**Examples**: + +```bash +# Configure parallel agents +CAI> /parallel add redteam_agent alias1 +CAI> /parallel add blueteam_agent alias1 +CAI> /parallel add bug_bounter_agent gpt-4o + +# List configuration +CAI> /parallel list + +# Execute on all agents +CAI> /parallel run "analyze target.com" + +# Merge results +CAI> /parallel merge + +# Clear configuration +CAI> /parallel clear +``` + +**YAML Configuration**: + +Create `agents.yaml`: + +```yaml +agents: + - name: red1 + agent_type: redteam_agent + model: alias1 + - name: bug1 + agent_type: bug_bounter_agent + model: alias1 +``` + +Launch with YAML: + +```bash +cai --yaml agents.yaml --prompt "scan target.com" +``` + +**Notes**: +- Each agent runs independently +- Results can be merged +- Different models per agent supported +- See [Advanced Usage](advanced_usage.md) for more details + +--- + +### `/run` or `/r` + +Execute queued prompts (works with parallel mode). + +**Syntax**: +```bash +/run +/r +``` + +**Examples**: + +```bash +# Queue and run prompt +CAI> /run "analyze this binary" + +# Alternative +CAI> /r "test for XSS" +``` + +**Notes**: +- Executes immediately if agents are ready +- Queues if agents are busy +- Works with both single and parallel modes + +--- + +**Queue File Format** (`prompts.txt`): + +```text +# Comments start with # +/agent redteam_agent +Scan 192.168.1.0/24 for open ports +Test https://target.com for vulnerabilities +$ nmap -sV 192.168.1.1 +Generate security report +``` + +**Notes**: +- Prompts execute sequentially +- Supports commands and regular prompts +- Can load from files for automation + +--- + +## Utilities + +### `/help` or `/h` or `/?` + +Display help information and command documentation. + +**Syntax**: +```bash +/help [command] +/h [command] +/? [command] +``` + +**Examples**: + +```bash +# General help +CAI> /help + +# Help for specific command +CAI> /help agent +CAI> /h parallel +CAI> /? mcp +``` + +**Topics**: +- `agent`: Agent management +- `parallel`: Parallel execution +- `memory`: Memory management +- `config`: Configuration +- `mcp`: MCP integration +- `commands`: List all commands + +--- + +### `/graph` or `/g` + +Visualize agent interaction graphs. + +**Syntax**: +```bash +/graph [agent_name] +/g +``` + +**Examples**: + +```bash +# Show graph for current conversation +CAI> /graph + +# Show graph for specific agent +CAI> /graph redteam_agent +``` + +**Output**: +- Directed graph of conversations +- User and agent interactions +- Tool calls highlighted +- Conversation flow visualization + +--- + +### `/context` or `/ctx` πŸš€ **CAI PRO Exclusive** + +> **⚑ CAI PRO Exclusive Feature** +> The `/context` command is available exclusively in **CAI PRO**. To access this feature and unlock advanced monitoring capabilities, visit [Alias Robotics](https://aliasrobotics.com/cybersecurityai.php) for more information. + +View context usage and token statistics for the current conversation. + +**Syntax**: +```bash +/context [agent_name] +/ctx +``` + +**Examples**: + +```bash +# Show context for current agent +CAI> /context + +# Show context for specific agent +CAI> /ctx redteam_agent +``` + +**Output Includes**: +- Total context usage (used/max tokens) with percentage +- Visual grid representation with CAI logo +- Breakdown by category: + - System prompt tokens + - Tool definitions tokens + - Memory/RAG tokens + - User prompts tokens + - Assistant responses tokens + - Tool calls tokens + - Tool results tokens +- Free space available +- Color-coded visualization + +**Notes**: +- Helps monitor token limits +- Useful for long conversations +- Different models have different context windows + +--- + +### `/cost` + +Display API usage costs and token statistics. + +**Syntax**: +```bash +/cost [agent_name] +``` + +**Examples**: + +```bash +# Show costs for current session +CAI> /cost + +# Show costs for specific agent +CAI> /cost redteam_agent + +# Show all agents' costs +CAI> /cost all +``` + +**Output Includes**: +- Total cost (USD) +- Input tokens used +- Output tokens used +- Cost per interaction +- Model pricing rates +- Agent breakdown + +--- + +### `/save` + +Save current conversation to a file. + +**Syntax**: +```bash +/save +``` + +**Supported Formats**: +- JSON (`.json`) +- Markdown (`.md`) + +**Examples**: + +```bash +# Save as JSON +CAI> /save pentest_session.json + +# Save as Markdown +CAI> /save findings_report.md + +# Full path +CAI> /save ~/sessions/project_alpha.json +``` + +**Notes**: +- Saves all conversation history +- Includes agent names and timestamps +- Cost information preserved +- Can be loaded with `/load` + +--- + +### `/temperature` or `/temp` + +Adjust the model's temperature parameter. + +**Syntax**: +```bash +/temperature +/temp +``` + +**Parameters**: +- `value`: Temperature (0.0 - 2.0) + - Lower = more deterministic + - Higher = more creative + +**Examples**: + +```bash +# Set to more deterministic +CAI> /temperature 0.2 + +# Set to more creative +CAI> /temp 1.5 + +# View current temperature +CAI> /temperature +``` + +--- + +### `/api` + +Manage API keys and authentication. + +**Syntax**: +```bash +/api [arguments] +``` + +**Subcommands**: +- `show`: Display configured API keys (masked) + +**Examples**: + +```bash +# Show API keys +CAI> /api show + +--- + +## Special Features + +### Command Chaining + +Chain multiple commands using semicolons (`;`). + +**Syntax**: +```bash +command1 ; command2 ; command3 +``` + +**Examples**: + +```bash +# Chain commands at launch +cai --prompt "/agent redteam_agent ; scan 192.168.1.1 ; /save results.json" + +# Chain in CLI +CAI> /agent bug_bounter_agent ; test https://target.com ; /cost +``` + +**Use Cases**: +- Automation workflows +- Batch operations +- Quick sequences + +--- + +### Auto-loading Queue from File + +Load and execute prompts automatically on startup. + +**Environment Variable**: +```bash +export CAI_QUEUE_FILE="/path/to/prompts.txt" +``` + +**Launch**: +```bash +CAI_QUEUE_FILE=~/my_prompts.txt cai +``` + +**Notes**: +- Prompts execute automatically +- Returns to interactive mode when done +- Perfect for automation + +--- + +## Quick Reference + +### Most Used Commands + +| Command | Description | Example | +|---------|-------------|---------| +| `/agent ` | Switch agent | `/agent redteam_agent` | +| `/model ` | Change model | `/model alias1` | +| `/config` | View config | `/config` | +| `/help` | Get help | `/help agent` | +| `/save ` | Save session | `/save session.json` | +| `/load ` | Load session | `/load session.json` | +| `/cost` | Show costs | `/cost` | +| `/history` | View history | `/history 20` | +| `$ ` | Shell command | `$ nmap -sV target` | +| `/exit` | Exit CAI | `/exit` | + +### Command Aliases + +| Full Command | Aliases | +|--------------|---------| +| `/agent` | `/a` | +| `/model` | `/mod` | +| `/config` | `/cfg` | +| `/help` | `/h`, `/?` | +| `/history` | `/his` | +| `/memory` | `/mem` | +| `/workspace` | `/ws` | +| `/virtualization` | `/virt` | +| `/parallel` | `/par`, `/p` | +| `/shell` | `/s`, `/$` | +| `/context` | `/ctx` | +| `/compact` | `/cmp` | +| `/temperature` | `/temp` | +| `/load` | `/l` | +| `/merge` | `/mrg` | +| `/run` | `/r` | +| `/kill` | `/k` | +| `/exit` | `/quit`, `/q` | + +--- + +## Next Steps + +- πŸ“– [Getting Started Guide](getting_started.md) - Learn the basics +- πŸš€ [Advanced Usage](advanced_usage.md) - Automation and advanced features +- 🏠 [CLI Overview](cli_index.md) - Return to main CLI documentation + +--- + +*Last updated: November 2025 | CAI CLI v0.6+* + diff --git a/docs/cli/getting_started.md b/docs/cli/getting_started.md new file mode 100644 index 00000000..a346db16 --- /dev/null +++ b/docs/cli/getting_started.md @@ -0,0 +1,563 @@ +# Getting Started with CAI CLI + +This guide will walk you through launching the CAI CLI for the first time and performing your first security assessment using the command-line interface. + +## Prerequisites + +Before starting, ensure you have: + +- βœ… CAI installed (see [Installation Guide](../cai_installation.md)) +- βœ… Python 3.9+ installed +- βœ… A valid `ALIAS_API_KEY` from [Alias Robotics](https://aliasrobotics.com) + +## Step 1: Launch the CLI + +Open your terminal and run: + +```bash +cai +``` + +You should see the CAI banner and prompt: + +``` + CCCCCCCCCCCCC ++++++++ ++++++++ IIIIIIIIII + CCC::::::::::::C ++++++++++ ++++++++++ I::::::::I + CC:::::::::::::::C ++++++++++ ++++++++++ I::::::::I + C:::::CCCCCCCC::::C +++++++++ ++ +++++++++ II::::::II + C:::::C CCCCCC +++++++ +++++ +++++++ I::::I + C:::::C +++++ +++++++ +++++ I::::I + C:::::C ++++ ++++ I::::I + C:::::C ++ ++ I::::I + C:::::C + +++++++++++++++ + I::::I + C:::::C +++++++++++++++++++ I::::I + C:::::C +++++++++++++++++ I::::I + C:::::C CCCCCC +++++++++++++++ I::::I + C:::::CCCCCCCC::::C +++++++++++++ II::::::II + CC:::::::::::::::C +++++++++ I::::::::I + CCC::::::::::::C +++++ I::::::::I + CCCCCCCCCCCCC ++ IIIIIIIIII + + Cybersecurity AI (CAI), v0.6.0 + Bug bounty-ready AI + +CAI> +``` + +The navigation bar at the bottom displays important system information including your current model, agent, cost tracking, and session details. + +## Step 2: Configure Your API Key + +If your `ALIAS_API_KEY` is not configured, you'll see an authentication error. Configure it using one of these methods: + +### Method 1: Using a `.env` file (Recommended) + +Create a `.env` file in your working directory: + +```env +ALIAS_API_KEY=ak_live_1234567890abcdef +CAI_MODEL=alias1 +CAI_AGENT_TYPE=redteam_agent +CAI_DEBUG=1 +CAI_PRICE_LIMIT=10.0 +``` + +### Method 2: Environment Variables + +Set it directly in your terminal: + +```bash +export ALIAS_API_KEY="ak_live_1234567890abcdef" +cai +``` + +### Method 3: Runtime Configuration + +After launching CAI, use the `/config` command: + +```bash +CAI> /config CAI_MODEL=alias1 +``` + +To view all current configuration: + +```bash +CAI> /config +``` + +## Step 3: Select Your Model + +CAI supports multiple AI models. For optimal performance and cost balance, we recommend `alias1`: + +```bash +CAI> /model alias1 +``` + +To see all available models: + +```bash +CAI> /model-show +``` + +### Recommended Models + +| Model | Provider | Best For | Cost | +|-------|----------|----------|------| +| `alias1` | Alias Robotics | **Recommended** - Balanced performance | Medium | +| `gpt-4o` | OpenAI | Complex reasoning and multi-modal | High | +| `claude-3-5-sonnet-20241022` | Anthropic | Fast responses with good quality | High | +| `o1-mini` | OpenAI | Reasoning tasks | Medium | + +> **πŸ’‘ Tip**: You can change models at any time without losing your conversation history. + +## Step 4: Choose Your Agent + +CAI provides specialized agents for different security tasks. Here's how to choose: + +### Option 1: List All Available Agents + +```bash +CAI> /agent list +``` + +This displays all agents with their descriptions and primary use cases. + +### Option 2: Use the Selection Agent + +If you're unsure which agent to use, start with the `selection_agent`: + +```bash +CAI> /agent selection_agent +CAI> I need to test a web application for SQL injection +``` + +The agent will recommend the best agent for your task. + +### Option 3: Choose Directly + +If you know which agent you need: + +```bash +CAI> /agent redteam_agent +``` + +### Common Agents and When to Use Them + +| Agent | Purpose | When to Use | +|-------|---------|-------------| +| `redteam_agent` | Offensive security testing | Default for penetration testing | +| `bug_bounter_agent` | Bug bounty hunting | Finding high-value vulnerabilities in web apps | +| `blueteam_agent` | Defensive security analysis | Security posture assessment and hardening | +| `one_tool_agent` | Single-tool execution | Quick scans with specific tools | +| `dfir_agent` | Digital forensics and incident response | Log analysis and forensic investigation | +| `reverse_engineering_agent` | Binary analysis | Malware analysis, firmware reversing | +| `network_security_analyzer_agent` | Network security assessment | Network scanning and traffic analysis | +| `wifi_security_agent` | WiFi security testing | Wireless penetration testing | +| `selection_agent` | Agent recommendation | **When unsure which agent to use** | + +> **πŸ’‘ Pro Tip**: Start with `selection_agent` if you're new to CAIβ€”it will guide you to the right agent for your task. + +## Step 5: Start Your First Interaction + +Now you're ready to interact with CAI! Simply type your prompt and press **Enter**. + +### Example 1: Basic Network Reconnaissance + +```bash +CAI> Scan 192.168.1.1 for open ports and services +``` + +The agent will: +- Process your request +- Select and execute appropriate tools (e.g., nmap) +- Display results in real-time +- Provide analysis and recommendations + +### Example 2: Web Application Testing + +```bash +CAI> /agent bug_bounter_agent +CAI> Test https://example.com for common web vulnerabilities +``` + +The agent will: +- Perform reconnaissance +- Test for OWASP Top 10 vulnerabilities +- Execute security tools +- Provide detailed findings + +### Example 3: CTF Challenge + +```bash +# Set up CTF environment +CAI> /config CTF_NAME=hackableii +CAI> /config CTF_CHALLENGE=web_challenge + +# Start the challenge +CAI> Analyze this CTF challenge and find the flag +``` + +### Understanding the Output + +As the agent works, you'll see: + +1. **Tool Execution**: Messages showing which tools are being launched +2. **Tool Output**: Real-time results from executed commands +3. **Agent Reasoning**: The agent's thought process (if `CAI_DEBUG=1`) +4. **Final Analysis**: Summary, findings, and recommendations +5. **Cost Tracking**: Updated costs in the navigation bar + +## Step 6: Essential Commands + +Here are the most important commands to know: + +### Getting Help + +```bash +# General help +CAI> /help + +# Help for specific command +CAI> /help agent + +# Quick reference guide +CAI> /quickstart +``` + +### Agent Management + +```bash +# List all agents +CAI> /agent list + +# Switch to a specific agent +CAI> /agent redteam_agent + +# Get info about current agent +CAI> /agent info +``` + +### Model Management + +```bash +# View current model +CAI> /model + +# Change model +CAI> /model gpt-4o + +# List all available models +CAI> /model-show +``` + +### Session Management + +```bash +# Save current conversation +CAI> /save pentest_session.json + +# Save as Markdown report +CAI> /save findings_report.md + +# Load previous conversation +CAI> /load pentest_session.json +``` + +### View History and Costs + +```bash +# View conversation history +CAI> /history + +# View last 20 messages +CAI> /history 20 + +# Check costs and token usage +CAI> /cost +``` + +### Clear and Reset + +```bash +# Clear terminal output (keeps history) +CAI> Ctrl+L + +# Flush conversation history +CAI> /flush + +# Exit CAI +CAI> /exit +# or press Ctrl+D +``` + +## Step 7: Shell Command Execution + +CAI allows you to execute shell commands directly: + +### Using /shell Command + +```bash +CAI> /shell nmap -sV 192.168.1.1 +``` + +### Using $ Shortcut + +```bash +CAI> $ whoami +CAI> $ ls -la +CAI> $ nmap -sV localhost +``` + +### Interactive Tools + +For interactive tools, the agent will handle them appropriately: + +```bash +CAI> Run a comprehensive port scan on 192.168.1.0/24 +# Agent will execute nmap with appropriate flags +``` + +## Step 8: Working with Configuration + +### View Current Configuration + +```bash +CAI> /config +``` + +This displays a panel with all environment variables and their current values. + +### Change Configuration at Runtime + +```bash +# Set a specific variable (use the number from /config output) +CAI> /config set 18 "5.0" + +# Or set by name +CAI> /config CAI_PRICE_LIMIT=5.0 +CAI> /config CAI_MAX_TURNS=50 +``` + +### Important Configuration Variables + +| Variable | Description | Example | +|----------|-------------|---------| +| `CAI_MODEL` | Default model to use | `alias1` | +| `CAI_AGENT_TYPE` | Default agent | `redteam_agent` | +| `CAI_DEBUG` | Debug level (0-2) | `1` | +| `CAI_PRICE_LIMIT` | Maximum cost in USD | `10.0` | +| `CAI_MAX_TURNS` | Maximum conversation turns | `50` | +| `CAI_MAX_INTERACTIONS` | Maximum tool interactions | `100` | +| `CAI_TRACING` | Enable OpenTelemetry tracing | `true` | +| `CAI_GUARDRAILS` | Enable security guardrails | `true` | + +See the complete [Configuration Guide](../cai/getting-started/configuration.md) for all options. + +## Step 9: Common Workflows + +### Workflow 1: Quick Security Scan + +```bash +# Launch with specific agent +CAI_AGENT_TYPE=redteam_agent cai + +# Execute scan +CAI> Perform a quick security assessment of 192.168.1.100 + +# Save results +CAI> /save quick_scan_results.md +``` + +### Workflow 2: Bug Bounty Reconnaissance + +```bash +# Start with bug bounty agent +CAI> /agent bug_bounter_agent + +# Reconnaissance +CAI> Perform full reconnaissance on target.com + +# Test specific vulnerability +CAI> Test the login form for SQL injection + +# Generate report +CAI> Generate a detailed bug bounty report + +# Save session +CAI> /save bugbounty_target_session.json +``` + +### Workflow 3: CTF Challenge + +```bash +# Configure CTF environment +export CTF_NAME="hackableii" +export CTF_CHALLENGE="web_app" +export CAI_AGENT_TYPE="redteam_agent" + +# Launch and solve +cai + +CAI> Analyze this CTF challenge and find the flag +``` + +### Workflow 4: Network Analysis + +```bash +CAI> /agent network_security_analyzer_agent + +# Analyze network +CAI> Scan the network 192.168.1.0/24 for security issues + +# Analyze captured traffic +CAI> Analyze this PCAP file for suspicious activity + +# View findings +CAI> /history +``` + +## Step 10: Keyboard Shortcuts + +Master these shortcuts for faster navigation: + +| Shortcut | Action | +|----------|--------| +| `Tab` | Autocomplete commands and arguments | +| `↑` / `↓` | Navigate through command history | +| `Ctrl+C` | Interrupt current execution | +| `Ctrl+L` | Clear terminal screen | +| `Ctrl+Z` | Suspend process (resume with `fg`) | +| `Ctrl+U` | Clear current input line | +| `Ctrl+A` | Move cursor to start of line | +| `Ctrl+E` | Move cursor to end of line | + +## Common First-Time Issues + +### Issue: API Key Not Valid + +**Solution**: +```bash +# Check your API key is set correctly +CAI> /env | grep ALIAS_API_KEY + +# If not set, add it to .env file +echo "ALIAS_API_KEY=your_key_here" >> .env +``` + +### Issue: Agent Not Responding + +**Solution**: +```bash +# Cancel current operation +Ctrl+C + +# Check agent is loaded +CAI> /agent + +# Switch to a different agent +CAI> /agent redteam_agent +``` + +### Issue: Command Not Found + +**Solution**: +```bash +# Get help for available commands +CAI> /help + +# Use Tab completion to see available commands +CAI> / + +# Check command syntax +CAI> /help +``` + +### Issue: Price Limit Reached + +**Solution**: +```bash +# Check current costs +CAI> /cost + +# Increase limit +CAI> /config CAI_PRICE_LIMIT=20.0 + +# Or set it before launching +CAI_PRICE_LIMIT=20.0 cai +``` + +### Issue: Max Turns Exceeded + +**Solution**: +```bash +# Increase turn limit +CAI> /config CAI_MAX_TURNS=100 + +# Or flush history and start fresh +CAI> /flush +``` + +## Next Steps + +Congratulations! You've completed the basics of CAI CLI. Here's what to explore next: + +### Learn More Commands +- πŸ“š [Commands Reference](commands_reference.md) - Complete command documentation +- πŸš€ [Advanced Usage](advanced_usage.md) - Automation, scripting, and advanced features + +### Explore Advanced Features +- **Queue System**: Batch process multiple prompts +- **Parallel Execution**: Run multiple agents simultaneously +- **Memory Management**: Persistent context across sessions +- **MCP Integration**: Connect external tools and services + +### Specialized Workflows +- **CTF Challenges**: Learn CTF-specific workflows +- **Bug Bounty**: Master bug bounty hunting techniques +- **Automation**: Script security assessments +- **CI/CD Integration**: Integrate CAI into your pipeline + +### Get Help +- ❓ [FAQ](../cai_faq.md) - Common questions +- πŸ’¬ [Discord](https://discord.gg/aliasrobotics) - Community support +- πŸ› [GitHub Issues](https://github.com/aliasrobotics/cai/issues) - Report bugs + +## Quick Reference Card + +### Most Used Commands + +```bash +/agent list # List all agents +/agent # Switch agent +/model # Change model +/config # View configuration +/help # Get help +/save # Save session +/load # Load session +/cost # Show costs +/history # View history +/shell # Run shell command +$ # Shell shortcut +/exit # Exit CAI +``` + +### Essential Workflows + +```bash +# Quick scan +cai --prompt "scan target.com for vulnerabilities" + +# CTF mode +CTF_NAME="challenge" cai + +# Bug bounty +CAI_AGENT_TYPE=bug_bounter_agent cai + +# With initial setup +CAI_MODEL=alias1 CAI_PRICE_LIMIT=10 cai +``` + +--- + +*Last updated: November 2025 | CAI CLI v0.6+* + diff --git a/docs/stylesheets/extra.css b/docs/stylesheets/extra.css index a8f19605..9e341537 100644 --- a/docs/stylesheets/extra.css +++ b/docs/stylesheets/extra.css @@ -514,3 +514,106 @@ grid-template-columns: 1fr; } } + +/* ==================== + Enhanced Navigation Styling - Refined & Professional + Only affects left sidebar navigation, not TOC + ==================== */ + +/* Target ONLY the primary (left) sidebar navigation */ +.md-sidebar--primary .md-sidebar__scrollwrap { + /* Main navigation sections - subtle but clear hierarchy */ +} + +/* Main sections (Getting Started, CAI PRO, User Interfaces, etc.) */ +.md-sidebar--primary .md-nav--primary > .md-nav__list > .md-nav__item > .md-nav__link { + color: #529d86 !important; + font-weight: 600 !important; + font-size: 0.75rem !important; + text-transform: uppercase; + letter-spacing: 0.03em; + padding-top: 0.6rem !important; + padding-bottom: 0.4rem !important; + margin-top: 0.3rem; + border-left: 2px solid transparent; + transition: all 0.15s ease; +} + +/* Hover effect for main sections - subtle */ +.md-sidebar--primary .md-nav--primary > .md-nav__list > .md-nav__item > .md-nav__link:hover { + border-left-color: #529d86; + background-color: rgba(82, 157, 134, 0.04); +} + +/* Active main section - slightly more visible */ +.md-sidebar--primary .md-nav--primary > .md-nav__list > .md-nav__item > .md-nav__link--active { + color: #428072 !important; + border-left-color: #529d86; + background-color: rgba(82, 157, 134, 0.06); + font-weight: 700 !important; +} + +/* Subsections (TUI, CLI, etc.) - keep normal weight */ +.md-sidebar--primary .md-nav__item--nested > .md-nav__link { + font-size: 0.7rem !important; + font-weight: 500 !important; +} + +/* Regular links - no changes to size */ +.md-sidebar--primary .md-nav__link { + font-size: 0.7rem; +} + +/* Active page in navigation - green highlight */ +.md-sidebar--primary .md-nav__link--active { + color: #529d86 !important; + font-weight: 500; +} + +/* Spacing between sections - subtle */ +.md-sidebar--primary .md-nav--primary > .md-nav__list > .md-nav__item { + margin-bottom: 0.2rem; +} + +/* Special styling for CAI PRO section - very subtle gradient */ +.md-sidebar--primary .md-nav__item > .md-nav__link[title*="CAI PRO"], +.md-sidebar--primary .md-nav__item > .md-nav__link[title*="πŸš€"] { + background: linear-gradient(90deg, rgba(82, 157, 134, 0.05) 0%, rgba(82, 157, 134, 0.01) 100%); + border-left-width: 3px; +} + +/* Table of Contents (right sidebar) - Apply color scheme, keep sizes */ +.md-sidebar--secondary .md-nav__link { + font-size: inherit !important; + text-transform: none !important; + transition: color 0.15s ease; +} + +/* TOC - Main headings (h1, h2) with green color */ +.md-sidebar--secondary .md-nav__list > .md-nav__item > .md-nav__link { + color: #529d86 !important; + font-weight: 600 !important; +} + +/* TOC - Sub-headings (h3, h4) with darker gray */ +.md-sidebar--secondary .md-nav__list .md-nav__item .md-nav__item > .md-nav__link { + color: #5a5a5a !important; + font-weight: 500 !important; +} + +/* TOC - Hover effect */ +.md-sidebar--secondary .md-nav__link:hover { + color: #428072 !important; +} + +/* TOC - Active/current section */ +.md-sidebar--secondary .md-nav__link--active { + color: #529d86 !important; + font-weight: 700 !important; +} + +/* Smooth transitions for better UX */ +.md-sidebar--primary .md-nav__link, +.md-sidebar--secondary .md-nav__link { + transition: color 0.15s ease, background-color 0.15s ease, border-color 0.15s ease; +} diff --git a/mkdocs.yml b/mkdocs.yml index b165726b..b5d24d14 100644 --- a/mkdocs.yml +++ b/mkdocs.yml @@ -23,18 +23,52 @@ theme: repo_url: https://github.com/aliasrobotics/cai repo_name: aliasrobotics/cai nav: + # ======================================== + # GETTING STARTED (Simplificado) + # ======================================== - Getting Started: - Welcome: index.md - Installation: cai_installation.md - Quickstart: cai_quickstart.md - - Available Models: cai_list_of_models.md - - Model Providers: - - OpenRouter: providers/openrouter.md - - Ollama: providers/ollama.md - - Azure OpenAI: providers/azure.md - - 'πŸš€ CAI PRO': cai_pro.md + # ======================================== + # CAI PRO (EXPANDIDO - COMERCIAL) ⭐ + # ======================================== + - 'πŸš€ CAI PRO - Professional Edition': + - Why CAI PRO?: cai_pro.md + - Alias1 Model: cai_pro_alias1.md + - Exclusive Features: cai_pro_features.md + - Pricing & Plans: cai_pro_pricing.md + - Get Started with PRO: cai_pro_quickstart.md + - Contact Sales: cai_pro_contact.md + # ======================================== + # USER INTERFACES (NUEVO AGRUPAMIENTO) + # ======================================== + - User Interfaces: + # Terminal UI (TUI) - SubsecciΓ³n + - Terminal UI (TUI): + - Overview: tui/tui_index.md + - Getting Started: tui/getting_started.md + - User Interface: tui/user_interface.md + - Terminals Management: tui/terminals_management.md + - Teams & Parallel Execution: tui/teams_and_parallel_execution.md + - Sidebar Features: tui/sidebar_features.md + - Keyboard Shortcuts: tui/keyboard_shortcuts.md + - Commands Reference: tui/commands_reference.md + - Advanced Features: tui/advanced_features.md + - Troubleshooting: tui/troubleshooting.md + + # Command Line Interface (CLI) - SubsecciΓ³n + - Command Line Interface (CLI): + - Overview: cli/cli_index.md + - Getting Started: cli/getting_started.md + - Commands Reference: cli/commands_reference.md + - Advanced Usage: cli/advanced_usage.md + + # ======================================== + # CORE CONCEPTS + # ======================================== - Core Concepts: - Architecture: cai_architecture.md - Agents: agents.md @@ -42,15 +76,21 @@ nav: - Handoffs: handoffs.md - Multi-Agent Systems: multi_agent.md - - Benchmarking: - - Overview: benchmarking/overview.md - - Running Benchmarks: benchmarking/running_benchmarks.md - - Attack & Defense CTFs: benchmarking/attack_defense.md - - Jeopardy CTFs: benchmarking/jeopardy_ctfs.md - - Cyber Ranges: benchmarking/cyber_ranges.md - - Knowledge Benchmarks: benchmarking/knowledge_benchmarks.md - - Privacy Benchmarks: benchmarking/privacy_benchmarks.md + # ======================================== + # MODELS & PROVIDERS (REORGANIZADO) + # ======================================== + - Models & Providers: + # TODO: Crear pΓ‘gina destacada para Alias Models + # - '⭐ Alias Models (CAI PRO)': cai_alias_models.md + - Available Models: cai_list_of_models.md + - Model Providers: + - OpenRouter: providers/openrouter.md + - Ollama: providers/ollama.md + - Azure OpenAI: providers/azure.md + # ======================================== + # GUIDES + # ======================================== - Guides: - Running Agents: running_agents.md - Working with Results: results.md @@ -60,18 +100,29 @@ nav: - Guardrails & Security: guardrails.md - Environment Variables: environment_variables.md - - Terminal UI (TUI): - - Overview: tui/tui_index.md - - Getting Started: tui/getting_started.md - - User Interface: tui/user_interface.md - - Terminals Management: tui/terminals_management.md - - Teams & Parallel Execution: tui/teams_and_parallel_execution.md - - Sidebar Features: tui/sidebar_features.md - - Keyboard Shortcuts: tui/keyboard_shortcuts.md - - Commands Reference: tui/commands_reference.md - - Advanced Features: tui/advanced_features.md - - Troubleshooting: tui/troubleshooting.md + # ======================================== + # BENCHMARKING (CREDIBILIDAD) + # ======================================== + - Benchmarking: + - Overview: benchmarking/overview.md + - Running Benchmarks: benchmarking/running_benchmarks.md + - Attack & Defense CTFs: benchmarking/attack_defense.md + - Jeopardy CTFs: benchmarking/jeopardy_ctfs.md + - Cyber Ranges: benchmarking/cyber_ranges.md + - Knowledge Benchmarks: benchmarking/knowledge_benchmarks.md + - Privacy Benchmarks: benchmarking/privacy_benchmarks.md + # ======================================== + # RESEARCH (CREDIBILIDAD CIENTÍFICA) + # ======================================== + - Research: + - Overview: research.md + # TODO: Opcional - expandir research + # - Publications: research_publications.md + + # ======================================== + # API REFERENCE (TΓ‰CNICO) + # ======================================== - API Reference: - Agents: - Agent: ref/agent.md @@ -97,13 +148,15 @@ nav: - Handoff Filters: ref/extensions/handoff_filters.md - Handoff Prompt: ref/extensions/handoff_prompt.md + # ======================================== + # ADVANCED + # ======================================== - Advanced: - # - Benchmarks: cai_benchmark.md - Development: cai_development.md - - Research: - - Overview: research.md - + # ======================================== + # RESOURCES + # ======================================== - Resources: - FAQ: cai_faq.md - Find Us: cai_find_us.md @@ -115,9 +168,8 @@ plugins: handlers: python: paths: ["src"] - selection: - docstring_style: google options: + docstring_style: google # Shows links to other members in signatures signature_crossrefs: true # Orders members by source order, rather than alphabetical