zerodom_set_scope
Set allowed host globs, denied destructive actions, and max requests per second to keep an unattended agent inside authorized scope.
Instructions
Constrain the hunt to authorized targets — enforced in code, not on trust.
hosts: comma-separated in-scope host globs (app.example.com,*.example.com).
Navigation, replay and clicks to any other host are then refused. deny: a
regex of destructive URLs/labels to refuse (default covers logout/delete/
remove/deactivate/revoke) so an unattended agent can't take an irreversible
action. max_rps: throttle to at most N requests/second (program rate limits).
An operator can instead lock scope before the agent starts by setting the ZERODOM_SCOPE env var to a YAML file; a locked scope can't be widened here.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| deny | No | ||
| hosts | Yes | ||
| max_rps | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |