Runtimes, models, MCP servers, agent frameworks, and a security & pentest tooling section — all links out to the real projects.
Add registry item
Local AI console
Talk to a model running on your own machine through Ollama or an OpenAI-compatible server — your prompts and the model's replies always go straight from your browser to your local model, never through a Reef server. Attach files for context, and pick up saved chats where you left off.
Type /image a prompt in the box below to generate
Not connected
Local AI hardware benchmark
A spec-based compatibility advisor — tells you which local models your hardware can run well, which will be slow, and which to skip. Connect to Ollama below for a real, measured speed test instead of an estimate.
1. Your hardware
⌕
2. Live check against your local model server (optional)
If a local model server is running, this cross-references the table above with what you've actually got loaded — and runs a real, measured speed test instead of an estimate.
AI Database
A browsable catalog of AI models across providers — context windows, pricing, and capabilities.
⌕
Loading…
Cyber threat feed
Latest threats pulled automatically every day from CISA's Known-Exploited-Vulnerabilities catalog and NVD — plus threat intel you post yourself.
Articles, guides and updates on pentesting, AI, and cybersecurity — with embedded video. Add your own, including YouTube.
New article
Written content plus an optional video. Paste a YouTube link and it embeds automatically.
Loading…
Posts
Loading…
New post
Stored in the platform database against your account.
⌕
Loading posts…
Forum
Questions, answers, and talk about running AI locally.
Start a thread
⌕
Loading forum…
GitHub repositories
Curated AI and security repos, plus your own pinned shelf.
Pin a repository
Pinned to your account.
Your shelf
⌕
Command board
One-liners, configs, and advice worth keeping — shared by everyone here.
⚠ Commands are shared with all users. Never include credentials, tokens, or internal hostnames. Review anything before you run it.
Share a command
⌕
Loading commands…
Skill packs
Starter files served from the API — AI agent scaffolds plus defensive security & VAPT reporting templates. Click to download.
⌕
Add skill pack
Add a downloadable skill pack. Filename is what users will save the file as.
Loading skills…
Threat Intelligence
Curated threat write-ups, advisories and analysis — with cover media.
⌕
New entry
Add a threat-intel write-up with an optional cover image or YouTube video.
Loading…
Tutorials
Step-by-step guides for running local AI, using the console, and tracking threats. Admins can add their own.
New tutorial
Step-by-step guide. Add an optional cover image or a YouTube video.
⌕
Loading…
Terms & Conditions
Loading…
Help & FAQ
Answers to common questions about Reef Sentinel, plus a formatting guide for posts, articles, and comments.
Formatting guide
Commands you can type into the body of a post, comment, or reply — no HTML needed. Comments and short replies only support bold, italic, and inline code.
Contact us
Questions, feedback, or a security disclosure? Reach us directly, or send a message and we'll get back to you by email.
Loading…
Send a message
VAPT Report Generator
Build an engagement, add findings with a live CVSS calculator, and generate a branded, print-ready report.
Recon Toolkit
Passive OSINT lookups for the recon phase of an engagement, plus offline hash identification and a payload cheatsheet.
Control panel
Manage everything shown on the site — news & videos, posts, homepage headlines, and subscribers. Admin only.
Overview
Content
Site
Account & Security
Email / SMTP settings
Send a test email
Save your settings first, then send a test to confirm delivery.
Contact page info card
Shown on the public Contact page. Leave a field blank to hide that row entirely.
Recon Toolkit — API keys
Optional third-party keys that unlock extra Recon Toolkit lookups. Everything else in Recon (subdomains, DNS, RDAP, email breach check, password exposure check, a free baseline host lookup) works with no key at all — these just add more depth. Provider names are only ever shown here in the admin panel; the public-facing Recon Toolkit UI never names which providers power it.
Upgrades Host Intel's primary scan-index lookup from the free InternetDB baseline to the full Shodan Host API — adds org/ISP/ASN/OS/geolocation, per-service banner data (product, version, TLS cert issuer, HTTP title), and richer verified CVE data. Get a key from account.shodan.io — a free account key works but is rate-limited; a paid membership raises the limit and query credits.
Adds a secondary, independently-sourced scan-index lookup (all 65,535 ports scanned) alongside the primary lookup in Host Intel — useful for services on non-standard ports. Free — create one at accounts.censys.io (My Account → API Access → Create New Token). No paid plan needed.
Raises the rate limit on Host Intel's IP-reputation check (is this IP a known internet-wide scanner, or a recognised benign service like a public DNS resolver?). Works keyless at a low rate limit already — a free key from viz.greynoise.io/signup raises it.
Enables the Domain Breach summary (org-wide breach exposure for a verified domain) in the Breach Check tab. Requires verifying domain ownership with XposedOrNot first — free key from your XposedOrNot dashboard after verification. The email and password exposure checks don't need this — only the domain-wide summary does.
Password recovery email
The one-time code for changing your password is emailed here. Default: hans.abraham@outlook.com. Change it if needed.
Change master password
For security, changing your password requires the one-time code sent to your recovery email. If SMTP isn't configured yet, the code is shown here for testing.
Database backup
Download a consistent snapshot of the entire site database (SQLite). Keep it safe — you can restore the site from it. Back up regularly.
To restore: stop the app, replace backend/reef.db with this file, then start the app again.
Add user
Create an account directly — it's pre-verified and can sign in immediately.
Audit log
Every action taken by any administrator — including the main administrator. Read-only.
Add ad
Normal ads are self-served image banners — add more than one to a placement and they rotate automatically with a small progress bar. A Google ad unit is shown once, statically, and never rotated by us (most ad networks require this).
Pasted as-is and executed on the page — only paste code from a source you trust, same as you would for any other admin-only content.
About page
Edit the public About us page. The body supports simple markdown: ## heading, - bullet, **bold**, > quote, and links.
Terms & Conditions
Edit the public Terms & Conditions page. The body supports simple markdown: ## heading, - bullet, **bold**, > quote, and links.
Add threat-intel entry
Manage threat-intelligence entries shown on the Threat → Threat Intelligence page. Photo or video cover supported.
Contact messages
Submissions from the Contact Us page. Viewing one marks it read; replies are emailed to the sender.
Add news / video
Add post
Posts submitted by regular members land here as "Pending review" — approve, reject, edit, or pin them from this list. Main admins and admins publish directly.
Add command
Snippets and configs shown on the Command board. Never include credentials or internal hostnames.
Add payload
Reference snippets shown on the Recon Toolkit's Payload Cheatsheet tab. Replace ATTACKER_IP / ports as placeholders — never include real targets or credentials.
Forum reports
Members' reports of threads or replies (e.g. abusive language). Deleting a reported item leaves a public notice with your reason in its place and emails the author; dismissing clears the report without touching the content.
News comment reports
Members' reports of comments (or replies) on news articles. Deleting a reported comment leaves a public notice with your reason in its place; dismissing clears the report without touching the comment.
Post comment reports
Members' reports of comments (or replies) on member posts. Deleting a reported comment leaves a public notice with your reason in its place; dismissing clears the report without touching the comment.
Add registry item
Runtimes, models, MCP servers, agent frameworks, and security tooling shown on the Registry page. Also editable directly from the front-end Registry page itself.
Formatting commands you can type into the body of a post, tutorial, news article, threat-intel entry, or the About page — no HTML needed. Comments and short replies only support bold, italic and inline code.
FAQ entries shown on the public Help page. Super admin only — same scope as About page / SMTP / API keys.
Add FAQ
Add headline
Add tutorial
Add skill pack
Send newsletter
We use essential cookies/local storage to keep you signed in and remember your preferences. We don't use tracking or advertising cookies. Learn more