feat(container,coverage): Strix-1.6.2-inspired capabilities

- Container image scanning: new `container` mode + 4 skills (vuln, secret,
  misconfig, SBOM) driving trivy/grype/syft headless, read-only. Scans an OCI
  ref / tar / Dockerfile for vulnerable packages (CVE/fixed-in/KEV), exposed
  secrets in any layer, Dockerfile+runtime misconfig, and writes an SBOM in
  both SPDX and CycloneDX to the run's sbom/. Also exposed as an MCP tool
  (neurosploit_container).
- Coverage report: every run writes coverage.md — which agents ran (tested
  surface), findings per agent, and the high-value classes NOT covered — so the
  reader sees the engagement's reach. Added to the assurance bundle.
- Login-verification evidence: doctrine now requires capturing the login
  request/response + a Playwright screenshot and recording success/failure
  before authenticated testing.
- HTTP traffic export: `neurosploit traffic <run>` turns the intercepted
  flows.jsonl into a traffic.http archive for external tools.

Not ported: Asset Discovery (enterprise-only, skipped per request).

383 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUP
2026-09-23 01:27:26 -03:00
co-authored by Claude Opus 5
parent 1adc882f6d
commit e49595b8bf
12 changed files with 318 additions and 7 deletions
+31 -1
View File
@@ -13,7 +13,7 @@
<img src="https://img.shields.io/badge/License-MIT-green?style=flat-square">
<img src="https://img.shields.io/badge/MD%20Agents-458-red?style=flat-square">
<img src="https://img.shields.io/badge/Models-18%20providers-success?style=flat-square">
<img src="https://img.shields.io/badge/Modes-Black%20%7C%20White%20%7C%20Grey%20%7C%20Host%20%7C%20AI%20%7C%20Mobile-9cf?style=flat-square">
<img src="https://img.shields.io/badge/Modes-Black%20%7C%20White%20%7C%20Grey%20%7C%20Host%20%7C%20AI%20%7C%20Mobile%20%7C%20Container-9cf?style=flat-square">
<img src="https://img.shields.io/badge/Auth-API%20key%20%7C%20Subscription-orange?style=flat-square">
</p>
@@ -46,6 +46,7 @@ Control TUI**.
| **AI / LLM red-team** | `neurosploit aitest <ai-url>` | jailbreaks & prompt injection + OWASP LLM Top 10 / MCP against a live AI agent |
| **AI Skills / n8n** | `neurosploit skills <file\|folder>` | white-box audit of Skill/plugin & n8n workflow definitions |
| **Mobile / Binary** | `neurosploit mobile <app.apk\|app.ipa\|binary>` | reverse-engineer a local artifact: RASP, root/JB, pinning, anti-debug, obfuscation, secrets (Ghidra headless / MobSF / Frida) |
| **Container** | `neurosploit container <image:tag>` | scan an OCI image for vulnerable packages, exposed secrets, misconfig + emit an SBOM (SPDX/CycloneDX) via trivy/grype/syft |
| **Mission Control** | `neurosploit tui <url>` | live TUI panels + composer during the run |
| **Interactive** | `neurosploit` | persistent REPL session (resumes per project) |
@@ -713,6 +714,35 @@ non-destructively.
---
## 📦 Container image scanning
```bash
neurosploit container myorg/app:1.4 --subscription --model anthropic:claude-opus-4-8 -v
neurosploit container ./image.tar
```
Scans an OCI image (registry ref, local tar, or Dockerfile) with trivy / grype /
syft headless: **vulnerable OS + language packages** (CVE, fixed-in, KEV),
**exposed secrets** in any layer, **Dockerfile/runtime misconfig** (root user,
unpinned base, curl-pipe-sh, secrets in ENV), and an **SBOM in both SPDX and
CycloneDX** written to the run's `sbom/` folder. Read-only — never pushes,
deletes or modifies a registry.
## 🧾 Coverage & traffic
Every run writes `coverage.md` — which agents ran (the tested surface), how many
findings each produced, and which high-value classes were **not** covered — so a
reader sees the engagement's reach, not just its findings. Login flows capture
verification evidence (the request/response + a Playwright screenshot) before
authenticated testing. With `--intercept own`, archived HTTP traffic exports to
a `.http` file:
```bash
neurosploit traffic <run> # flows.jsonl -> traffic.http
```
---
## 🔌 Run it as an MCP server
Drive NeuroSploit from Claude Code, Codex or Cursor as tools: