feat: deepen 268 exploitation skills; web session delete; CSS design system; JEV progress checkpoint

agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
  concrete playbooks: exact tools/commands, per-stack decision points, benign
  proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
  proof criteria, false-positive/pitfall sections, and chaining hooks. Every
  contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
  block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.

web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
  a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
  scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
  fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1

harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
  continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
  early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 4.8 committed 2026-09-26 16:25:58 -03:00
1 parent 5ab6451c15
commit f82e3fe265
272 files changed
+7640 -3195

No files matched your search

+42 -4
View File
@@ -1,7 +1,7 @@
#!/usr/bin/env node
'use strict';
/**
* NeuroSploit v4.2.0 — web console backend.
* NeuroSploit v4.2.1 — web console backend.
*
* Zero-dependency Node HTTP server that:
* - serves the static SPA in ./public
@@ -506,10 +506,36 @@ async function runDetail(id) {
function safeRunDir(id) {
if (!/^[a-zA-Z0-9_.-]+$/.test(id)) return null;
const dir = path.join(RUNS_DIR, id);
if (!dir.startsWith(RUNS_DIR)) return null;
// Contain the delete to RUNS_DIR: reject anything that resolves out of it
// (defence in depth on top of the charset check, which already forbids `/`).
if (dir !== RUNS_DIR && !dir.startsWith(RUNS_DIR + path.sep)) return null;
return dir;
}
/// Permanently delete one run: its whole directory (findings, evidence, PoCs,
/// every report artifact) and its remembered engagement name. Returns false if
/// the id is unsafe or the directory does not exist.
async function deleteRun(id) {
const dir = safeRunDir(id);
if (!dir || dir === RUNS_DIR || !fs.existsSync(dir)) return false;
await fsp.rm(dir, { recursive: true, force: true });
if (engagementNames.delete(id)) {
await fsp.mkdir(path.dirname(NAMES_FILE), { recursive: true })
.then(() => fsp.writeFile(NAMES_FILE, JSON.stringify(Object.fromEntries(engagementNames), null, 2)))
.catch(() => {});
}
return true;
}
/// Delete every run under RUNS_DIR (ns-* directories only). Returns the count.
async function deleteAllRuns() {
let ids = [];
try { ids = (await fsp.readdir(RUNS_DIR)).filter((d) => d.startsWith('ns-')); } catch { return 0; }
let n = 0;
for (const id of ids) { if (await deleteRun(id)) n += 1; }
return n;
}
// ---------------------------------------------------------------------------
// Exploitation jobs — spawn `neurosploit <mode> <target> --only ... -v`
// and parse its stdout into structured live state (mirrors app/src/repl.rs
@@ -1014,6 +1040,18 @@ const server = http.createServer(async (req, res) => {
if (req.method === 'GET' && m) {
return serveRunAsset(req, res, decodeURIComponent(m[1]), decodeURIComponent(m[2]));
}
// Delete ALL runs (must come before the single-run matcher below).
if (req.method === 'DELETE' && p === '/api/runs') {
const n = await deleteAllRuns();
return sendJson(res, 200, { ok: true, deleted: n });
}
m = p.match(/^\/api\/runs\/([^/]+)$/);
if (req.method === 'DELETE' && m) {
const id = decodeURIComponent(m[1]);
const ok = await deleteRun(id);
if (!ok) return sendJson(res, 404, { error: 'run not found' });
return sendJson(res, 200, { ok: true, deleted: 1, id });
}
// ---- exploitation jobs ----
if (req.method === 'GET' && p === '/api/exploit') {
@@ -1191,7 +1229,7 @@ const server = http.createServer(async (req, res) => {
}
if (req.method === 'GET' && p === '/api/meta') {
return sendJson(res, 200, { version: '4.0.0', binary: BIN, root: ROOT });
return sendJson(res, 200, { version: '4.2.1', binary: BIN, root: ROOT });
}
// ---- providers / API keys (in-memory only, never persisted) ----
@@ -1223,7 +1261,7 @@ const server = http.createServer(async (req, res) => {
});
server.listen(PORT, () => {
console.log(`NeuroSploit v4.2.0 web console → http://localhost:${PORT}`);
console.log(`NeuroSploit v4.2.1 web console → http://localhost:${PORT}`);
console.log(` binary : ${BIN || '(not found — build neurosploit-rs first)'}`);
console.log(` agents : ${AGENTS_DIR}`);
console.log(` runs : ${RUNS_DIR}`);