mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-29 12:31:43 +02:00
feat(decision): pluggable System One backend — TypeSafe (hosted) or Laya (local)
Laya (github.com/NandhaKishorM/laya) is the same System One abstraction as TypeSafe — identical choice/score/noul primitives — but local, open-source (Apache 2.0) and free. Added it as a swappable backend, entirely additively: the hosted TypeSafe path is byte-for-byte unchanged (key alone → same endpoint, model, bearer as before). - typesafe.rs: endpoint/model/bearer are now instance fields with env overrides (NEUROSPLOIT_DECISION_ENDPOINT / _MODEL). Defaults are the hosted TypeSafe API. from_env() now also activates when a local endpoint is configured (no key). backend_label() names the active backend in the run banner. - tools/laya_shim.py: a stdlib HTTP shim that loads Laya and exposes the exact POST /systemone contract the client already speaks. Model downloads on first use (HF cache); no key; evidence stays on the box. - CLI: --decision-backend typesafe|laya. `laya` installs laya if missing, starts the shim, waits for readiness, and points the client at it — all optional, only when the operator selects it. 383 tests; the hosted TypeSafe behaviour is untouched. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
d752e252e6
commit
56b2c80ae4
@@ -506,6 +506,19 @@ neurosploit run https://app --typesafe off # the identical pipeline, no TypeS
|
||||
records `"typesafe": true|false` — a clean with/without measurement you can run
|
||||
against your own target.
|
||||
|
||||
**Pluggable decision backend.** The calibrated System One layer runs against
|
||||
either backend, chosen with `--decision-backend`:
|
||||
|
||||
- `typesafe` — the hosted API (set `TYPESAFE_API_KEY`).
|
||||
- `laya` — [Laya](https://github.com/NandhaKishorM/laya), a local, open-source
|
||||
System One engine (Apache 2.0) with the same primitives. Picking it downloads
|
||||
the model on first use, runs it on this machine, needs no API key, and keeps
|
||||
the engagement's evidence on the box — the right choice for air-gapped or OT
|
||||
work. It starts a small local shim (`tools/laya_shim.py`) automatically.
|
||||
|
||||
Both speak the same contract, so adjudication, CVSS grading, agent pruning and
|
||||
the confirmation loop behave identically whichever you pick.
|
||||
|
||||
### Scope-evasion resistance, evidence integrity, untrusted output
|
||||
|
||||
Three hardening passes, all enforced in code:
|
||||
|
||||
Reference in New Issue
Block a user