Uncensored AI for web app security testing
Payloads for the app you are paid to test
An appsec tester who has to argue with the model about whether XSS is allowed on example.com is not testing the app. They are testing the filter.
Why the mainstream APIs fail here
The API refuses a polyglot payload, a SSRF URL, or a mass-assignment body because it looks like an attack. It is an attack, on the staging host in the RoE.
How Wild West API is used for this
Describe the endpoint, the stack, the control you already tried. Ask for the next payload. Hit the in-scope host from your own tooling, not from Wild West API. Wild West API is the writer, not the scanner.
A working loop
- Stay on in-scope hosts.
- Generate payloads, send them from your proxy.
- Cap the tester's key so a fuzz loop has a ceiling.
Details are on the privacy page. Per-model prices are on /models and the pricing model is on /pricing.