mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-07-24 19:50:53 +02:00
v3.6.0 — AI/LLM/Agent/MCP/Skills security, n8n audit, onboarding wizard
- New `ai` agent category (agents_md/ai/, +18): OWASP LLM Top 10 (2025) — prompt injection (direct+indirect), jailbreak, system-prompt leak, sensitive-info disclosure, improper output handling, excessive agency, RAG/embedding, unbounded consumption, supply chain, misinformation — plus MCP risks (tool poisoning, excessive permissions/confused-deputy, unsafe tool execution) and Skills/plugin + n8n workflow audits (incl. an AI/LLM-node audit). Library 417. - Pipeline: run_ai (live AI/LLM/MCP red-team) + run_skills_audit (white-box .md/ .json/folder for skills & exported n8n flows), AI_DOCTRINE + AI_RECON_SYS. Mode enum gains Ai/Skills; wired in CLI + TUI. - CLI: `aitest <url>` and `skills <path>` subcommands. `agents` JSON now reports ai. - REPL onboarding wizard (/onboard, auto on first launch): pick scope — web / infra / cloud / ai / skills — then guided setup; Session.scope drives dispatch; shown in /show. - Models: +claude-sonnet-5, +grok-4.5. - Version 3.5.6 -> 3.6.0; docs/counts (417) + RELEASE section.
This commit is contained in:
+49
@@ -1,3 +1,52 @@
|
||||
# NeuroSploit v3.6.0 — Release Notes
|
||||
|
||||
**Release Date:** July 2026
|
||||
**Codename:** AI / LLM / Agent / MCP / Skills Security
|
||||
**License:** MIT
|
||||
**Credits:** Joas A Santos & Red Team Leaders
|
||||
|
||||
---
|
||||
|
||||
## TL;DR
|
||||
|
||||
v3.6.0 turns NeuroSploit into an **AI-security** platform: red-team live AI
|
||||
agents / LLM apps / MCP endpoints against the **OWASP Top 10 for LLM Apps (2025)**
|
||||
+ MCP threats, audit **AI Skills/plugins and exported n8n workflows** white-box,
|
||||
and pick your engagement type up front in a new **onboarding wizard**. Library
|
||||
**417** agents. Adds **Claude Sonnet 5** and **Grok 4.5**.
|
||||
|
||||
## AI / LLM / Agent / MCP / Skills testing (+18 agents, `agents_md/ai/`)
|
||||
|
||||
- **Live AI red-team** — `neurosploit aitest <url>` (or the `ai` scope in the
|
||||
REPL). Point it at an AI agent / LLM chat or API / MCP endpoint; agents cover
|
||||
the full **OWASP LLM Top 10 (2025)**: prompt injection (direct + indirect),
|
||||
jailbreaks, system-prompt leakage, sensitive-info disclosure, improper output
|
||||
handling, excessive agency, RAG/embedding weaknesses, unbounded consumption,
|
||||
supply chain, misinformation — hackagent.dev-style, with the exact prompt +
|
||||
the model's response as proof. Plus **MCP risks**: tool poisoning / description
|
||||
injection, excessive permissions & confused-deputy, unsafe tool execution.
|
||||
- **Skills / plugins / n8n audit (white-box)** — `neurosploit skills <file|dir>`
|
||||
(or the `skills` scope). Audit a single `.md`/`.json` or a whole folder:
|
||||
- **Skills/plugins**: insecure design, secrets in manifests, over-broad tools,
|
||||
injection surface, missing human-in-the-loop.
|
||||
- **n8n exported workflows**: hardcoded credentials, unsafe Code/Function
|
||||
nodes (RCE/SSRF), unauthenticated webhooks, expression injection, over-scoped
|
||||
credentials — **and a dedicated AI/LLM-node audit** (prompt injection, data
|
||||
leakage to the provider, excessive agency, insecure output handling).
|
||||
|
||||
## Onboarding wizard
|
||||
|
||||
- On first launch (or `/onboard`), a guided menu asks **what you're testing** —
|
||||
**Web & API · Infrastructure & Networks · Cloud · AI Agents & LLMs · AI
|
||||
Skills/Plugins/n8n** — then the box type (black/white/grey for web) and the
|
||||
minimal setup, so a plain `/run` does the right thing. Scope shown in `/show`.
|
||||
|
||||
## Models
|
||||
|
||||
- Added **`anthropic:claude-sonnet-5`** and **`xai:grok-4.5`**.
|
||||
|
||||
---
|
||||
|
||||
# NeuroSploit v3.5.6 — Release Notes
|
||||
|
||||
**Release Date:** July 2026
|
||||
|
||||
Reference in New Issue
Block a user