mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-30 21:19:49 +02:00
feat(typesafe): confirmation-loop agent + --typesafe flag (on/off/auto) for A/B
TypeSafe cannot BE an LLM agent — System One does not generate text or call tools. But it can be the decision brain of a code-owned confirmation loop, and that is what typesafe_agent.rs is: an ADDITIONAL confirmation strategy. typesafe_agent.rs — for enumerable classes (XSS, SQLi, open-redirect, path traversal, SSRF, IDOR): code lists candidate payloads, a TypeSafe Choice picks the next one given what's been tried, the replay engine sends it for real, a TypeSafe Noul judges the response, loop until confirmed or exhausted. Edge/WAF answers are refused. Pure parts (class table, payload templating, id-swap, OAST substitution, query encoding) are unit-tested; the networked loop is integration. Wired as a pipeline pass that runs ONLY on findings the LLM path left unconfirmed or in needs-review (the recall lever) — it can raise a finding to confirmed with a calibrated probability, never downgrades (the deterministic layer owns that). --typesafe on|off|auto (global flag) resolves into the env the pipeline reads, governing adjudication, CVSS re-grade, agent pruning and this loop together. `off` runs the identical pipeline without TypeSafe; meta.json records "typesafe": true|false so a with/without pair is a clean A/B measurement. Web console gets the same toggle. 381 tests. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
48c38d4798
commit
8e84656f4f
8 files changed
+475
No files matched your search
@@ -77,6 +77,11 @@ struct Cli {
|
||||
/// uses the Kali image; give a value to override (e.g. --sandbox my/img).
|
||||
#[arg(long = "sandbox", global = true, num_args = 0..=1, default_missing_value = "")]
|
||||
sandbox: Option<String>,
|
||||
/// TypeSafe System One as an ADDITIONAL confirmation strategy: on · off ·
|
||||
/// auto (default: auto = on when TYPESAFE_API_KEY is set). `off` runs the
|
||||
/// exact same pipeline without it, so runs can be compared with/without.
|
||||
#[arg(long = "typesafe", global = true)]
|
||||
typesafe: Option<String>,
|
||||
}
|
||||
|
||||
#[derive(Subcommand)]
|
||||
@@ -542,6 +547,16 @@ async fn main() -> anyhow::Result<()> {
|
||||
let mut cli = Cli::parse();
|
||||
let base = find_base();
|
||||
|
||||
// Resolve the TypeSafe mode into the env var the pipeline reads, so every
|
||||
// run type (and the REPL) honours one control. `off` disables it entirely;
|
||||
// `on`/`auto` leave it to key presence. This is what makes with/without
|
||||
// TypeSafe an A/B a single flag flips.
|
||||
match cli.typesafe.as_deref().map(|s| s.trim().to_lowercase()) {
|
||||
Some(ref m) if m == "off" || m == "false" || m == "0" => std::env::set_var("NEUROSPLOIT_TYPESAFE", "off"),
|
||||
Some(ref m) if m == "on" || m == "true" || m == "1" || m == "auto" => std::env::set_var("NEUROSPLOIT_TYPESAFE", "on"),
|
||||
_ => {}
|
||||
}
|
||||
|
||||
// No subcommand → launch the Claude-Code-style interactive session.
|
||||
let cmd = match cli.cmd.take() {
|
||||
Some(c) => c,
|
||||
|
||||
Reference in new issue
Block a user