feat: one-file engagement configs; scope-file reseeds stale target; English UI + any-language input; docs

- /scope-file now reads optional engagement keys from the SAME YAML (target,
  models, focus, objective, authorization, classes) so one file defines the
  whole engagement, not just scope. examples/scopes/nasa.yaml and
  engagement.example.yaml show the keys.
- When importing a scope (/scope-file) or declaring one (/authorize), a target
  left over from a previous session that falls OUTSIDE the new scope is reset to
  a host inside it (was: silently kept, then denied on /run — the "nothing
  changed" confusion). Added scope_seed_target() + in_hard_scope() check.
- UI/help strings are English; the natural-language REPL still accepts input in
  any language (the two example lines are now English).
- README + TUTORIAL updated: new REPL commands (/authorize, /scope-file, /class,
  /research, /quick, /authorization, /guardrail), a "Scope — three ways" section
  with the one-file YAML, version/counts refreshed to 4.2.1 / 480 agents.

422 tests passing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 4.8 committed 2026-10-04 00:03:50 -03:00
1 parent c233da8b17
commit 3a820f09e6
4 files changed
+218 -14

No files matched your search

+10
View File
@@ -21,6 +21,16 @@
# /run
# ===========================================================================
# --- Optional: define the whole engagement in this one file -----------------
# These top-level keys are read by `/scope-file` (and ignored by the CLI's
# --scope-file, which only reads scope). All optional.
target: "*.nasa.gov" # seed; must fall inside `hard` below
# models: # provider:model list (uncomment to pin)
# - anthropic:claude-opus-5-5
# classes: idor, ssrf, xss # focus the run on these vuln classes
focus: "prioritize auth, access control and SSRF on in-scope subdomains"
authorization: "https://www.nasa.gov/nasa-vulnerability-disclosure-policy/"
# --- HARD: the allowlist. Only these are testable. ------------------------
hard:
- "*.nasa.gov" # apex + every subdomain (VERIFY against the VDP)