This year seems to be the year of the agents harnesses. Last year was the year of agents. So what comes next? My guess is that agents start creating harnesses for themselves. So since I already had a lot of fun with shiftgrid for Pentesting I asked my local and trusted AI to create a new workflow.json for auditing Confluence. I have not uploaded it because it is such a trivial task to create one with AI that I did not bother.
I don't know why but seeing the AI create another workflow suited for Confluence made me have my 16th (or so) singularity moment. It immediately understood what to pay attention on in the workflow. It started the workflow with broader understanding of the whole Confluence and then added steps to search certain spaces of interest in detail using the endpoint list. It thought about creating query dictionaries first. Created runs for searches where the agents otherwise would not try-harder but quit too fast to save tokens.
Here is the workflow:
1. Scoping & Access
• Confirm Search Access
• Enumerate Spaces
• Understand the Landscape
• Register Spaces in ShiftGrid
2. Search-Term Planning
• Build Query Dictionaries + Ledger
3. Broad Search Sweeps (runs: 4)
• Run Broad Searches
4. Instance-Wide Checks
• Tune the Checklist
• Increase Check Runs
• Work the Global Checks
5. Per-Space Deep Dive
• Collect Spaces
• Group by Function
• Increase Space Runs
• Search All Spaces
6. Attachments & Non-Text (runs: 2)
• Search Attachments
7. Coverage Gap Review (runs: 3)
• Find Coverage Gaps
8. Verify & Prune
• Verify Real Exposure
• Prune False Positives
9. Finding Writing
• Write Up Findings
• Screenshot Medium+ Findings
ShiftGrid was created for Pentesting not for searching Confluence and yet this work incredibly well. The agent used the Confluence API to get a list of Spaces. Did some lighter searches to prioritize the +500 spaces and created a list of the in-scope spaces that he will do a deepdive on.
The agent did this in a couple of minutes. No subagents, no fancy scripts or permissions. Just the prompt engine from the workflow and the Confluence API.

Honestly, I cannot imagine that these searching tasks testers have to do during pentests or RTs will be done by humans anymore from now on. Everybody that has seen this once will get a weird feeling when searching Confluence, SMB shares or GitLab on their own.. slowly. Sure the heuristics of a experienced RT operator does matter. But speed and volume does too. Especially when the content is large.
Also, adapting the workflow.json/prompt engine was waaaay too easy and fast to not do this now for all kinds of tasks. And the ShiftGrid that gives such a nice overview of how the agent then works on it.
