feat(mcp,tooling): NeuroSploit as an MCP server; tool-discovery + CVE-PoC + headless doctrine

MCP server (app/src/mcp.rs): `neurosploit mcp` speaks Model Context Protocol
over stdio (JSON-RPC 2.0), exposing run / list_runs / findings / report /
rebuild / internal / compliance as tools. Each shells out to the same binary,
so scope, safety and authorization match the CLI. Install with
`claude mcp add neurosploit -- neurosploit mcp`. Handshake, tools/list and a
live call verified. TUTORIAL section 8 + README document setup for Claude Code,
Codex and Cursor.

Tooling doctrine expanded so the agent researches and provisions the BEST tool
for the context instead of being limited to a fixed list:
- context toolboxes (AD: netexec/impacket/bloodhound-python/certipy/kerbrute/
  responder/evil-winrm; web recon; cloud; exploitation frameworks incl.
  metasploit/msfvenom; cracking) — provision on demand.
- CVE -> PoC sourcing as a core capability: on a fingerprinted version
  (WordPress/plugin/CMS/OS package/service) go to searchsploit, Exploit-DB,
  GitHub, PacketStorm/Vulners, wpscan; clone/fetch, compile (gcc/go/cargo) and
  run the PoC non-destructively, vetted and time-boxed.
- headless-only rule for GUI tools: mobsf (REST/Docker), ghidra analyzeHeadless,
  jadx/apktool/frida, radare2 — never require an X display.

383 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 5 committed 2026-09-20 20:55:49 -03:00
1 parent 56b2c80ae4
commit a4afd784c7
6 files changed
+312 -2

No files matched your search

+16
View File
@@ -681,6 +681,22 @@ Critical is not a Critical.
---
## 🔌 Run it as an MCP server
Drive NeuroSploit from Claude Code, Codex or Cursor as tools:
```bash
neurosploit mcp # MCP server over stdio
claude mcp add neurosploit -- neurosploit mcp
```
Exposes `neurosploit_run`, `neurosploit_findings`, `neurosploit_report`,
`neurosploit_rebuild`, `neurosploit_internal`, `neurosploit_compliance`,
`neurosploit_list_runs`. Each shells out to the same binary, so scope, safety
and authorization are identical to the CLI. See TUTORIAL section 8.
---
## 📊 How we compare
A rough, honest capability benchmark against Strix, Shannon, Penligent and the