agentspec
=========

This product includes software developed as part of the oauth-hunter project
(https://github.com/cyberark/oauth-hunter), pinned at upstream commit
67f91ddc054b6c9f0897fd789cdea9fc0bba0f25 (2025-02-20).

  Copyright (c) 2025 CyberArk Software Ltd. All rights reserved.

What was incorporated: the curated `redirect_uri` parser-confusion scenario
taxonomy (`REDIRECT_URI_SCENARIOS`, 1 control + 26 bypass scenarios) and the
`Scenario` descriptor, lifted verbatim from
`oauth_hunter/engine/scenarios.py`. This is the research-backed artifact; the
replay engine, response classifier, report format, CLI, and HTTP transport
were authored independently for agentspec (see ATTRIBUTION.md for the split).

Licensed under the Apache License, Version 2.0 (the "License"); you may not
use this incorporated material except in compliance with the License. You may
obtain a copy of the License at:

    http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
License for the specific language governing permissions and limitations
under the License.
