feat: one-file engagement configs; scope-file reseeds stale target; English UI + any-language input; docs

- /scope-file now reads optional engagement keys from the SAME YAML (target,
  models, focus, objective, authorization, classes) so one file defines the
  whole engagement, not just scope. examples/scopes/nasa.yaml and
  engagement.example.yaml show the keys.
- When importing a scope (/scope-file) or declaring one (/authorize), a target
  left over from a previous session that falls OUTSIDE the new scope is reset to
  a host inside it (was: silently kept, then denied on /run — the "nothing
  changed" confusion). Added scope_seed_target() + in_hard_scope() check.
- UI/help strings are English; the natural-language REPL still accepts input in
  any language (the two example lines are now English).
- README + TUTORIAL updated: new REPL commands (/authorize, /scope-file, /class,
  /research, /quick, /authorization, /guardrail), a "Scope — three ways" section
  with the one-file YAML, version/counts refreshed to 4.2.1 / 480 agents.

422 tests passing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 4.8 committed 2026-10-04 00:03:50 -03:00
1 parent c233da8b17
commit 3a820f09e6
4 files changed
+218 -14

No files matched your search

+1 -1
View File
@@ -257,7 +257,7 @@ Zero npm dependencies (Node built-ins only).
flat list — click any node or row for the full finding detail, including any PoC script the
exploiting agent wrote to `pocs/`.
- **Real REPL underneath `run`/`whitebox`/`greybox`** — the wizard scripts an actual interactive
`neurosploit` session (`/target`, `/model`, `/only`, `/run`, …) instead of a one-shot CLI
`neurosploit` session (`/target`, `/authorize`, `/scope-file`, `/class`, `/model`, `/only`, `/research`, `/quick`, `/run`, …) instead of a one-shot CLI
invocation, so the session **keeps reading stdin while the engagement streams**. The Activity
log tab grows a prompt box (`❭`) to send `/status`, `/stop`, `/continue`, or a plain-language
instruction mid-run — same REPL described in [§6](TUTORIAL.md#6-the-interactive-repl). `host` /