Strix•Katana 用法 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Strix•Katana 用法 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Official docs:
Canonical syntax: katana [flags]
High-signal flags:
-u, -list <url|file> target URL(s)-d, -depth <n> crawl depth-jc, -js-crawl parse JavaScript-discovered endpoints-jsl, -jsluice deeper JS parsing (memory intensive)-kf, -known-files <all|robotstxt|sitemapxml> known-file crawling mode-proxy <http|socks5 proxy> explicit proxy setting-c, -concurrency <n> concurrent fetchers-p, -parallelism <n> concurrent input targets-rl, -rate-limit <n> request rate limit-timeout <seconds> request timeout-retry <n> retry count-ef, -extension-filter <list> extension exclusions-tlsi, -tls-impersonate experimental JA3/TLS impersonation-hl, -headless enable hybrid headless crawling-sc, -system-chrome use local Chrome for headless mode-ho, -headless-options <csv> extra Chrome options (for example proxy-server)-nos, -no-sandbox run Chrome headless with no-sandbox-noi, -no-incognito disable incognito in headless mode-cdd, -chrome-data-dir <dir> persist browser profile/session-xhr, -xhr-extraction include XHR endpoints in JSONL output-silent, -j, -jsonl, -o <file> output controlsAgent-safe baseline for automation: mkdir -p crawl && katana -u https://target.tld -d 3 -jc -kf robotstxt -c 10 -p 10 -rl 50 -timeout 10 -retry 1 -ef png,jpg,jpeg,gif,svg,css,woff,woff2,ttf,eot,map -silent -j -o crawl/katana.jsonl
Common patterns:
katana -u https://target.tld -d 3 -jc -silent
katana -u https://target.tld -d 5 -jc -jsl -kf all -c 10 -p 10 -rl 50 -o katana_urls.txt
katana -list urls.txt -d 3 -jc -silent -j -o katana.jsonl
katana -u https://target.tld -hl -sc -nos -xhr -j -o crawl/katana_headless.jsonl
katana -u https://target.tld -hl -sc -ho proxy-server=http://127.0.0.1:48080 -j -o crawl/katana_proxy.jsonl
Critical correctness rules:
-kf must be followed by one of all, robotstxt, or sitemapxml.-hl for headless mode.-proxy expects a single proxy URL string (for example http://127.0.0.1:8080).-ho expects comma-separated Chrome options (example: -ho --disable-gpu,proxy-server=http://127.0.0.1:8080).-kf, keep depth at least -d 3 so known files are fully covered.-o.Usage rules:
-d, -c, -p, and -rl explicit for reproducible runs.-ef early to reduce static-file noise before fuzzing.-proxy over environment proxy variables when proxying only Katana traffic.-hc only for one-time diagnostics, not routine crawling loops.-h/--help for routine runs unless absolutely necessary.Failure recovery:
-d and optionally add -ct.-jsl and lower -c/-p.-sc or install system Chrome.-ef filters.If uncertain, query web_search with: site:docs.projectdiscovery.io katana <flag> usage
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.