mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-30 13:09:36 +02:00
feat(mcp,tooling): NeuroSploit as an MCP server; tool-discovery + CVE-PoC + headless doctrine
MCP server (app/src/mcp.rs): `neurosploit mcp` speaks Model Context Protocol over stdio (JSON-RPC 2.0), exposing run / list_runs / findings / report / rebuild / internal / compliance as tools. Each shells out to the same binary, so scope, safety and authorization match the CLI. Install with `claude mcp add neurosploit -- neurosploit mcp`. Handshake, tools/list and a live call verified. TUTORIAL section 8 + README document setup for Claude Code, Codex and Cursor. Tooling doctrine expanded so the agent researches and provisions the BEST tool for the context instead of being limited to a fixed list: - context toolboxes (AD: netexec/impacket/bloodhound-python/certipy/kerbrute/ responder/evil-winrm; web recon; cloud; exploitation frameworks incl. metasploit/msfvenom; cracking) — provision on demand. - CVE -> PoC sourcing as a core capability: on a fingerprinted version (WordPress/plugin/CMS/OS package/service) go to searchsploit, Exploit-DB, GitHub, PacketStorm/Vulners, wpscan; clone/fetch, compile (gcc/go/cargo) and run the PoC non-destructively, vetted and time-boxed. - headless-only rule for GUI tools: mobsf (REST/Docker), ghidra analyzeHeadless, jadx/apktool/frida, radare2 — never require an X display. 383 tests. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
56b2c80ae4
commit
a4afd784c7
6 files changed
+312
-2
No files matched your search
@@ -5,6 +5,7 @@ mod repl;
|
||||
mod tui;
|
||||
|
||||
use clap::{Parser, Subcommand};
|
||||
mod mcp;
|
||||
use harness::{agents, models::ModelRef, pool::ModelPool, types::RunConfig, RunOutput};
|
||||
use std::path::{Path, PathBuf};
|
||||
|
||||
@@ -187,6 +188,9 @@ enum Cmd {
|
||||
#[arg(short, long)]
|
||||
verbose: bool,
|
||||
},
|
||||
/// Run NeuroSploit as an MCP server (stdio) so Claude Code, Codex, Cursor
|
||||
/// and other MCP clients can drive it as a set of tools.
|
||||
Mcp,
|
||||
/// Rebuild a finished run's report artifacts (md · json · html · pdf) from
|
||||
/// its findings, without re-running the engagement.
|
||||
Rebuild {
|
||||
@@ -741,6 +745,7 @@ async fn main() -> anyhow::Result<()> {
|
||||
}
|
||||
}
|
||||
}
|
||||
Cmd::Mcp => { mcp::serve()?; }
|
||||
Cmd::Rebuild { run } => {
|
||||
// Accept either a path or a bare run id, resolved against the same
|
||||
// runs root the engagement wrote to.
|
||||
|
||||
Reference in new issue
Block a user