feat(mcp,tooling): NeuroSploit as an MCP server; tool-discovery + CVE-PoC + headless doctrine

MCP server (app/src/mcp.rs): `neurosploit mcp` speaks Model Context Protocol
over stdio (JSON-RPC 2.0), exposing run / list_runs / findings / report /
rebuild / internal / compliance as tools. Each shells out to the same binary,
so scope, safety and authorization match the CLI. Install with
`claude mcp add neurosploit -- neurosploit mcp`. Handshake, tools/list and a
live call verified. TUTORIAL section 8 + README document setup for Claude Code,
Codex and Cursor.

Tooling doctrine expanded so the agent researches and provisions the BEST tool
for the context instead of being limited to a fixed list:
- context toolboxes (AD: netexec/impacket/bloodhound-python/certipy/kerbrute/
  responder/evil-winrm; web recon; cloud; exploitation frameworks incl.
  metasploit/msfvenom; cracking) — provision on demand.
- CVE -> PoC sourcing as a core capability: on a fingerprinted version
  (WordPress/plugin/CMS/OS package/service) go to searchsploit, Exploit-DB,
  GitHub, PacketStorm/Vulners, wpscan; clone/fetch, compile (gcc/go/cargo) and
  run the PoC non-destructively, vetted and time-boxed.
- headless-only rule for GUI tools: mobsf (REST/Docker), ghidra analyzeHeadless,
  jadx/apktool/frida, radare2 — never require an X display.

383 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 5 committed 2026-09-20 20:55:49 -03:00
1 parent 56b2c80ae4
commit a4afd784c7
6 files changed
+312 -2

No files matched your search

+5
View File
@@ -5,6 +5,7 @@ mod repl;
mod tui;
use clap::{Parser, Subcommand};
mod mcp;
use harness::{agents, models::ModelRef, pool::ModelPool, types::RunConfig, RunOutput};
use std::path::{Path, PathBuf};
@@ -187,6 +188,9 @@ enum Cmd {
#[arg(short, long)]
verbose: bool,
},
/// Run NeuroSploit as an MCP server (stdio) so Claude Code, Codex, Cursor
/// and other MCP clients can drive it as a set of tools.
Mcp,
/// Rebuild a finished run's report artifacts (md · json · html · pdf) from
/// its findings, without re-running the engagement.
Rebuild {
@@ -741,6 +745,7 @@ async fn main() -> anyhow::Result<()> {
}
}
}
Cmd::Mcp => { mcp::serve()?; }
Cmd::Rebuild { run } => {
// Accept either a path or a bare run id, resolved against the same
// runs root the engagement wrote to.