v4.2.2: validation keeps reproducible findings, /pocs command, version bump

Field feedback: real, reproducible findings (missing HSTS, insecure cookie flags,
internal IP leaked in a header) were being down-rated/dropped by the adversarial
opinion-vote. The user's rule: never discard something real; another person must
be able to reproduce the same finding.

Validation:
- has_http_receipt(): a finding whose proof is a captured HTTP response (status
  line / security headers / Set-Cookie / a header the class is proven by) or a
  file:line citation is REPRODUCIBLE by definition.
- validate(): a finding unanimously rejected by the vote but carrying such a
  receipt is NO LONGER dropped — it is kept as needs-review (capped to what the
  receipt alone proves), because "the response lacks HSTS" is a fact, not a
  story. grounded_receipt() now also recognizes an in-prose HTTP receipt.
- reproducibility: a kept finding at a URL with no explicit repro steps gets a
  minimal pasteable `curl -i` so anyone can reproduce the exact finding.

Also:
- /pocs (aliases /poc /evidence /artifacts): list a run's synthesized/written
  PoC + evidence files with their paths (was: "unknown command /pocs").
- version bumped to 4.2.2 across CLI/clap/web; stale v4.2.1/v4.1.0 labels fixed.

423 tests passing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 4.8 committed 2026-10-04 00:40:12 -03:00
1 parent 45ad7bf359
commit b55778d6f6
9 files changed
+141 -34

No files matched your search

+18 -3
View File
@@ -1,4 +1,4 @@
<h1 align="center">🧠 NeuroSploit v4.2.1</h1>
<h1 align="center">🧠 NeuroSploit v4.2.2</h1>
<p align="center">
<a href="https://github.com/JoasASantos/NeuroSploit/stargazers"><img src="https://img.shields.io/github/stars/JoasASantos/NeuroSploit?style=for-the-badge&logo=github&color=8b5cf6" alt="Stars"></a>
@@ -8,7 +8,7 @@
</p>
<p align="center">
<img src="https://img.shields.io/badge/Version-4.2.1-blue?style=flat-square">
<img src="https://img.shields.io/badge/Version-4.2.2-blue?style=flat-square">
<img src="https://img.shields.io/badge/Harness-Rust%20%7C%20tokio-e6b673?style=flat-square">
<img src="https://img.shields.io/badge/License-MIT-green?style=flat-square">
<img src="https://img.shields.io/badge/MD%20Agents-479-red?style=flat-square">
@@ -52,7 +52,22 @@ Control TUI**.
### Highlights
> **New in v4.2.1** — **SARIF 2.1.0 export**: every run now writes `report.sarif`
> **New in v4.2.2** — **free, LLM-directed exploration**: an exploit agent's named
> class is a starting point, not a cage — it maps what the app actually does and
> reports any class it can prove, with **authentication / identity** (login, signup,
> password reset, MFA, OAuth/OIDC/SAML, JWT, session) as a first-class target and
> business-logic / multi-step flows pursued on its own judgment; agent **selection**
> now covers the surface instead of collapsing into one family. **WAF-aware User-Agent**
> (`/ua browser`) uses a realistic browser UA for accuracy behind a CDN while keeping
> attribution in the `X-NeuroSploit-Scan` header. **Importable engagement configs**:
> `/authorize <hosts…>` sets the whole scope in one line (no bug-bounty program needed),
> `/scope-file <yaml>` imports scope **and** target/models/focus/classes from one file;
> `/class idor,sqli,xss,ssrf` focuses a run on vuln classes. Plus **PoC/evidence files
> synthesized from recorded evidence** even on the API-key path (empty `pocs/`·`evidence/`
> fixed), **model-refusal detection** (a declined technique is reported as such, not a
> parse error), and version strings read from the build so they never go stale.
>
> **Also in v4.2.x** — **SARIF 2.1.0 export**: every run now writes `report.sarif`
> next to the Markdown/JSON/HTML/PDF, and `neurosploit sarif <run>` (re)emits it
> on demand, so findings drop straight into GitHub / Azure DevOps code-scanning
> as severity-coloured, CWE-linked alerts (also exposed over MCP). Plus stronger