Driven by the Arena Hockey engagement, where all 24 findings shipped with an
empty CVSS field and the PDF ran payloads off the page edge.
CVSS
- Derived deterministically from what the harness knows: the weakness class
sets the impact shape, the PROVEN exploitability sets attack complexity, and
the auth context sets privileges required. The vector is emitted with the
score, because a score without its vector cannot be checked and an unchecked
score is just a bigger adjective.
- The base equation is the v3.1 specification verbatim, including round-up and
the scope-changed privileges table. Tests anchor it against known values
(9.8 unauthenticated RCE, 10.0 with scope change, 6.1 reflected XSS, 0.0 for
no impact).
- An unknown weakness stays conservative — guessing high impact from a class
nobody mapped is how reports get inflated. An agent-supplied score is never
overwritten.
PDF
- Steps are passed as an ARRAY and rendered as a real numbered list, one command
per box. The previous template flattened them into a single `raw` block, which
rendered five separate commands as one run-on paragraph.
- Finding blocks are breakable, so a long evidence dump flows to the next page
instead of off the bottom of this one.
- `wrappable()` inserts zero-width breaks so encoded payloads wrap. The first
attempt broke prose mid-word ("rota ted", "lockoutOnFailu re=false") by
breaking every N characters regardless of context; it now works per token and
leaves anything that fits on a line exactly as it was.
- rebuild() re-enriches before rendering, so a run that finished before a
mapping existed picks it up instead of reprinting the gap forever.
Over-claimed findings are capped, not deleted
- The engagement rejected "no rate limiting on the password-reset flow" because
the agent claimed inbox flooding and only proved 25 unthrottled requests. The
claim was inflated; the measurement was real, and dropping it hid a genuine
gap. A unanimously rejected finding that still carries a checkable receipt is
now capped to Low and flagged for review, with the validator's reason
attached — the reader gets the fact without the story built on it.
- The agent contract now says impact must be what was MEASURED, and warns that
inflating it costs the whole finding.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
A live black-box engagement returned 21 "deduped" candidates for about ten
actual issues. One cookie problem came back five times and one missing header
four, because the key was `cwe|endpoint|title[..40]` and every agent writes
those differently: `CWE-614` vs `CWE-614 (Sensitive Cookie in HTTPS Session
Without Secure Attribute)`, `https://host/` vs `GET https://host/ (and
/Account/Login)`. Worse than the inflated count, the severities disagreed — the
same issue arrived Low from one agent and Medium from another, which is
indefensible in front of a client.
The key is now (CWE number, normalized endpoint) plus a title-similarity check,
because grouping on the first two alone over-merges: missing `nosniff`,
`Referrer-Policy` and `Permissions-Policy` are all CWE-693 on `/` and are three
separate fixes. Titles merge at Jaccard >= 0.4 over meaningful words —
calibrated on this run's real output, where two phrasings of the cookie issue
score 0.44 and the two header findings score 0.33.
The survivor keeps the HIGHEST severity with the fullest evidence, and inherits
whatever the duplicates knew that it did not (remediation, repro steps,
structured evidence). Agreement between independent agents is recorded as
"corroborated by …" and nudges confidence up: several agents reaching the same
conclusion separately is a reason to trust a finding, not a reason to print it
five times.
Tests use the actual titles, CWEs and endpoints from the engagement, including
the case that must NOT merge (three rate-limit findings on three different
endpoints — login spraying and reset-email flooding are different problems).
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Both bugs surfaced during a live black-box engagement.
1. extract_findings took the span from the first '[' to the last ']'. One
agent's reply opened with the prose line "[low] Antiforgery cookie missing
Secure flag" and put its real findings in a fenced ```json block further
down — so the span started inside prose, failed to parse, and every finding
that agent had proven was thrown away. Fenced blocks are now tried first
(last one wins: models narrate, then answer), with the span kept only as a
fallback and the trailing-comma salvage preserved.
2. "no findings" was reported as malformed JSON. The guard compared the raw
text to "[]", but models wrap the empty array in a fence, so every honest
negative result was logged as a parse failure — which teaches an operator to
ignore a warning that sometimes means a real one. reported_nothing() now
recognises a bare [], a fenced [], and {"findings": []}.
The second bug made the first one harder to see: the log was already full of
"malformed JSON" warnings for agents that had simply found nothing, so the one
warning that meant a genuine loss looked like more of the same.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
A PDF was only ever produced while a run was finishing. If `typst` was missing
at that moment — or the template improved afterwards — the operator had no way
to get one without re-running the whole engagement against the target.
report::rebuild() regenerates every artifact (md · json · html · pdf) from the
findings already on disk, exposed as `neurosploit rebuild <run-id|dir>` and as
POST /api/runs/:id/report with a "Generate report" button in the run view. The
endpoint shells out to the harness rather than reimplementing report generation
in JavaScript, so there is one implementation instead of two that drift, and it
says plainly when the PDF was skipped for want of `typst` instead of handing
back a link to a file that was never produced.
Also fixes write_all() to pass the run's pocs/ listing into the HTML report, so
a rebuilt report links the scripts each finding cites — the run-time path
already did this and the rebuild path silently did not.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The risk model, grants and hash-chained trail existed as modules nothing
called. Now every engagement runs under them.
Capability
- `neurosploit capability issue|verify` mints and inspects grants.
- `--capability-token` (global, so the REPL takes it too), `--in-scope`,
`--environment`, `--policy` on `run`; verification happens at the command
line, so an invalid grant fails with a readable message instead of halfway
through an engagement.
- The pipeline verifies before anything else and REFUSES to run on a token that
does not verify — proceeding would mean acting on an authorization nobody can
prove was issued. `effective_scope` then applies the grant as a ceiling.
- Web: an Authorization tab carrying the token, extra hosts, environment and
policy profile. The browser decodes the claims for display and says plainly
that it is not verifying them — a "valid" badge from a party without the key
would be the UI vouching for something it cannot check.
A hole the smoke test found: `/inscope evil.test` inside a session under a
grant WIDENED the scope past it — the one thing a capability token exists to
prevent. The run itself would still have been constrained (the pipeline
re-applies the grant), but `/policy` reported a boundary that was not real, and
a tool that misreports its own limits is worse than one with none. Scope
mutations now re-apply the ceiling and name what it refused. Session
authorization also arrives from argv rather than a `/`-command, because a
session that can widen its own grant is not constrained by one.
Audit
- One hash-chained record per action in `<run>/audit.jsonl`, in the specified
shape, covering engagement start/end, validator rejections, findings that
reach the report (with the hash of the evidence behind them) and findings
withheld for being out of scope.
- The run verifies its own chain at the end and says loudly if it is broken.
- `/audit [n]` tails the trail and verifies it; the web offers it as a download
next to the report, so "show me what the tool did" is a link.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Four pieces that together answer "may this action happen, under whose
authority, and can we prove afterwards what we did".
policy.rs — effective_risk per action, exactly as specified:
(action_risk + asset_criticality + protocol_risk + privilege_level
+ blast_radius) × environment_multiplier
Every term is named and kept on the result, so the number can be explained
rather than argued with. Three policies sit on it: SafetyPolicy (ceilings,
approval thresholds, hard prohibitions), ReasoningPolicy (baseline before
payload, bounded hypotheses, evidence before escalation, explicit stop
conditions) and ProofOfImpactPolicy (what a severity must carry before it may
be that severity).
OT/ICS/SCADA is treated as its own regime, not web testing on odd ports.
Industrial protocols authenticate nothing — a Modbus write is the protocol
working as intended, addressed to a device that may be holding a valve — and
scanners crash PLCs by sending unexpected data at line rate. So the OT profile
blocks writes, disruptive actions, fuzzing and exploit payloads outright, caps
the rate at ~1 req/s, and refuses the function codes that stop a CPU (Modbus
5/6/8/15/16/22/23/43, S7 start/stop, DNP3 restart/stop). Safety instrumented
systems are off limits in every profile.
A test caught a calibration error worth keeping: a plain READ of a critical PLC
scores 3.6 on this formula, so the obvious tight ceiling would have refused
exactly the observation OT findings come from. In an industrial environment it
is the KIND of action that is forbidden, not the arithmetic — the ceiling
catches extremes and the low approval threshold makes anything past trivial
observation a human's decision.
capability.rs — HMAC-signed grants: who authorized what, against which hosts,
in which environment, until when. The harness verifies the signature before
reading a single claim (a well-formed token from the wrong key must never get
to influence what the harness believes), refuses expired and not-yet-valid
tokens, and treats the grant as a CEILING: constrain() intersects it with local
configuration, so config can narrow authorization and never widen it. Tokens
carry no secrets — the payload is readable by anyone holding it.
audit.rs — one structured record per action, in the specified shape (timestamp,
agent, hypothesis, action, target, policy_decision, operator, tool, result,
evidence_hash, capability_token). Two things make it worth having: it is
hash-chained, so removing or editing an entry breaks every hash that follows
and verify() says which one; and it records REFUSALS, because a trail
containing only what happened cannot demonstrate restraint. Only the grant's
id is recorded, never the token — the trail gets shared.
Hard kill conditions end a run outright: target unresponsive after our traffic,
sustained 5xx, out-of-scope request, forbidden industrial function code, safety
system addressed, capability expired mid-run, repeated policy violations,
budget exhausted, operator stop. Failures BEFORE the target ever answered do
not count — nothing listening is not the same as knocked over. The OT switch
trips far sooner: a PLC missing two requests already warrants stopping.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
A finding is useful only if the reader can find the problem, see why it
matters, fix it, and reproduce it without trusting us. The report answered the
last one badly and the other three not at all: it printed a payload blob and an
evidence blob, and "payload: ' OR 1=1--" tells a developer nothing about WHERE
to look. A PoC script attached as a file is a black box unless you run it.
Findings are now rendered in the order a reader works through them — where the
problem is, what it means, how to fix it, then the proof — in the HTML report,
the Markdown, the Typst/PDF and the web console's finding modal.
The proof is numbered, pasteable steps: baseline request, attack request, how
to read the result, with the real URL and the real payload. They come from the
agent's `repro_steps` when it recorded them, and are derived from the
endpoint/payload/identity pair otherwise, so every finding carries something
runnable. The generated curl redacts Authorization/Cookie/API-key headers — a
report gets shared, and a live session cookie inside one is a new bug. A PoC
script is now offered as an extra artifact that automates the steps, never as
the proof itself.
Technical evidence is the measured difference, not a paraphrase: baseline vs
attack status, size, timing and delta; how many repeats reproduced it; the
controlled marker and whether a browser or a callback observed it; then each
recorded exchange with the headers that decide a class (Location, Set-Cookie,
Access-Control-*, X-Frame-Options, CSP, Retry-After) and a body excerpt.
Finding gains `location` (the parameter/field/flow step, not just the URL) and
`repro_steps`, and the agent contract now asks for them explicitly, along with
impact tied to this app's data and remediation that names the control rather
than saying "sanitise input".
The web console offers the run's PDF when Typst produced one — and only then,
since a dead download button is worse than none.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Validators decide from recorded artifacts, and the weakest link was who
recorded them: "the payload returned a 500" is still an agent's account of what
happened. Replay produces the part that matters most in practice —
reproducibility — by sending the request again through the harness's own
client, with the scope guard in front of it.
Three properties it is built around:
- every request passes ScopePolicy::check_request before a socket is opened, so
replay cannot be the thing that wanders off-scope while verifying a finding;
- it never mutates: a finding proven with DELETE is not re-proven by deleting
the record again, so non-idempotent verbs are refused and repeats of them are
refused outright;
- bodies are truncated at 96KB and SAY they were truncated — a silently clipped
body makes a length differential meaningless.
enrich() fills in repeats and re-measures a recorded baseline (comparing a
fresh attack against an hour-old baseline attributes ordinary drift to the
payload). It deliberately does NOT synthesize a baseline from an attack
request: removing "the payload" from an arbitrary URL is guesswork, and a
guessed baseline would silently decide the verdict.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Six classes had deterministic rules; the rest of a run still rested on models
voting. These thirteen cover the classes that produce the most false positives
in AI-driven testing, and each one is written around what *disproves* the
claim, because that is the part a language model skips:
SSTI an expression evaluated server-side whose result was never
sent — the payload echoing its own "result" is rejected
XXE entity content or an OOB callback; a parser error mentioning
entities shows the DTD was read, not that anything resolved
Open redirect 3xx WITH a Location off-site; a rendered link is not a redirect
CORS reflected Origin PLUS credentials; ACAO:* without credentials
exposes only what an anonymous client could already read, and
ACAO:* WITH credentials is refused by browsers anyway
Cookie flags fully decidable from Set-Cookie + scheme
Clickjacking neither X-Frame-Options nor CSP frame-ancestors
Auth bypass protected content with NO credentials sent — a "bypass" whose
request still carried a cookie is rejected, as is a redirect
to login
JWT forged token accepted AND privileged content returned
Rate limiting >= 20 attempts with no 429/Retry-After; five attempts prove
nothing about a limit that was never reached
Session fix. the session id surviving login unchanged
Mass assign. a read-back proving the field persisted — a 200 on the write
means nothing, APIs accept and ignore extra fields routinely
CSRF a cross-origin state change read back; a SameSite session
cookie means a browser would never attach it cross-site
Exposure a real secret/listing signature the baseline lacked; a
soft-404 mirroring the baseline page is rejected
Exchange gains response and request headers, because several of these classes
are decided by a header (Location, Set-Cookie, Access-Control-Allow-*) and the
body alone is not evidence for them.
A test asserts no two validators claim the same CWE — ambiguous ownership would
make routing depend on registration order, which is how a class silently gets
the wrong rule.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Two gaps this closes, both found by reading what the code actually did.
Scope was never enforced
------------------------
`out_of_scope` was rendered into the prompt as "HARD CONSTRAINT — do NOT test…"
and nothing checked it. That is a request to a model, not a control: an agent
that decided a discovered subdomain was interesting, or that followed a
redirect off-target, was free to act and the operator found out by reading the
report.
scope.rs adds a guard in code:
- Hard scope: allowlist of hosts, *.wildcards, IPv4 CIDRs, URL prefixes, with
exclusions that always win. Defaults to the engagement's own target, so
discovery cannot widen authorization — finding a host is not permission to
attack it. An unconfigured policy is closed, not open.
- Soft scope: observe-only zones, destructive verbs (off by default), an
account-creation cap, a rate guard that warns rather than silently dropping
requests (a dropped request reads as "target unreachable"), and payload
classes refused even in scope because they damage the target instead of
demonstrating a bug.
- Enforced at the harness's own chokepoint (probe) and as a post-run audit:
findings proven against an unauthorized host are withheld from the report and
written to out-of-scope-findings.json as an incident to disclose, because
shipping one would launder the mistake.
- REPL: /inscope, /observe, /guardrail, /policy; /scope-out now promotes
host-shaped entries into enforced rules immediately, and says plainly when an
entry is prose the guard cannot enforce.
Validation was models checking models
-------------------------------------
N-model voting plus an adversarial refute pass share the failure mode of the
thing they check — agreement is not evidence, and a confident hallucination
survives a vote by being confident. grounding.rs helps but matches keywords
("http/", "status", "alert(") and cannot tell a real response from a plausible
transcript of one.
validation.rs asks a different question — does the recorded evidence
demonstrate THIS class? — with per-CWE rules and no model in the loop:
SQLi baseline/attack difference that reproduces >= 2x
XSS a browser executed a harness-chosen marker; reflection is not proof
IDOR identity B reads A's resource AND the body matches (a 200 returning a
login page is rejected, which is the classic false positive)
SSRF controlled callback or canary retrieval
LFI controlled marker or a file signature the baseline lacked
RCE a unique nonce in output/callback; reflected input is rejected
Absent evidence is never a pass, and a class with no rule is never
auto-confirmed. NEUROSPLOIT_VALIDATION=advisory (default) rejects
contradictions without demoting voted findings for missing artifacts;
enforcing makes the verdict the status. The evidence contract is injected into
exploit prompts so agents collect the artifacts while they still hold the
target.
Finding gains evidence_data so agents can emit structured artifacts alongside
the finding JSON.
Two bugs the tests caught while writing this: the scope guard treated a SAST
`src/auth.rs:42` endpoint as a host and quarantined valid source findings, and
two canaries minted in the same clock tick came out identical — a marker that
repeats would let a stale token vouch for a new finding.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Backend
-------
- knowledge_graph.rs — the durable structure under attack_graph's per-run view:
typed entities (asset/endpoint/weakness/technique/finding/account/credential/
impact) joined by typed, weighted, provenance-carrying edges, accumulated
across runs in .neurosploit/graph.json plus a per-run copy the report and web
console can draw. Answers what a finding list can't: ranked attack paths, and
the frontier of entities observed but never proven — where chaining should
look next. Agents only sometimes fill chains_from, so progression is also
inferred between adjacent kill-chain stages; those edges are marked inferred,
weighted lower, and drawn dashed, because presenting a hypothesis as evidence
is the graph lying about itself. Secrets stay in the vault, never the graph.
- memory.rs — four tiers scoped by lifetime, not importance: working (one run),
engagement (one target), technique (one agent/CWE), reusable (generalized).
Promotion is evidence-gated and needs independent evidence at each step: a
claim repeated within a run becomes engagement knowledge; one confirmed
across runs becomes technique knowledge; one that held on two DIFFERENT
targets is generalized into a reusable lesson with host-specific tokens
stripped. Nothing is promoted on a single observation, which is exactly what
a hallucination looks like. Recall is scored (overlap × past success ×
recency) and injected into recon/exploit prompts as leads to verify. Recalled
memos are credited only when the run they informed actually found something.
- rectify.rs — a mistyped command cost a full round trip through /help, at the
worst possible moment during a live run. Accepted-as-typed wins over
everything (so the /url alias is never "corrected" to /ua), then unique
prefix, then Damerau-Levenshtein with a length-scaled budget, and a tie is
reported rather than resolved. Arguments too: a bare host gets its scheme, an
out-of-range count is clamped with a note instead of silently reverting, a
near-miss model id is matched against the live catalog.
- pool.rs — when every configured model is exhausted or its token is dead, try
whatever else this machine can actually reach (an installed CLI subscription,
or a provider whose key is in the environment) before parking. A run that
stops on a box with three other usable backends stopped for no reason.
- repl.rs — /memory, /forget, /graph; a recovered run resumes by itself where
nobody is watching (piped stdin — the web console — or NEUROSPLOIT_AUTO_RESUME),
since a `/continue` prompt there waits forever.
Web
---
- Attack path: the stage list was seven hardcoded values, so findings the
harness staged outside it were silently dropped — 5 of 27 on a real run.
Rewritten against the harness's own stage list with unknown stages kept,
two-line labels (every node used to read "SQL Injection Authent…"), stage
column headers, pan/zoom/fit, path highlighting, severity filter, and the
run's graph.json used when present.
- Dashboard: coverage, findings by severity, top weaknesses, and annualized
loss exposure via FAIR — frequency from exploitability × validation
confidence, magnitude from assumptions shown on screen and editable, reported
as a range. The posture score saturates instead of subtracting, so it keeps
discriminating past the first critical.
- Run history groups into one folder per target with a filter, instead of one
flat list that grows forever.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BvdGy9XtVWSdXDTa3FFLJv
/only <agent,...> (app/src/repl.rs): the REPL had no way to pin an exact
agent set the way the CLI's --only flag does - Session gained a `pinned`
field, wired into RunConfig in both start_background() (the live
background-run path) and the blocking run() fallback. Needed so the web
console's exploitation jobs can drive a real interactive REPL session
(for live input while a run streams) without losing lead-pinning, which
only existed as a CLI flag until now. Also usable directly from a
terminal REPL session.
HTML report (crates/harness/src/report.rs, html()): rebuilt to match the
Typst PDF template's design (templates/report.typ) instead of its own
inconsistent styling - violet brand accent, an asset table, a 5-box
executive-summary grid (all severities, zero-count included, matching
Typst's grid exactly), a Vulnerability Summary table, and severity-
left-bordered finding cards with a compact field grid (Criticality /
Status / OWASP-CWE / Confidence / Location / Agent / Auth context) before
Description-Impact / Proof of Concept / Evidence / Remediation - same
field order and labels as the Typst template. Dropped the Mermaid
attack-path/kill-chain section entirely (the web console's live
Generative Attack Path Chaining graph covers that now, interactively).
Also tidied two pre-existing formatting quirks while in there: OWASP/CWE
left a dangling " · " when CWE was empty, and the confidence cell said
"<votes-string> votes" even when the votes field already contained a
compound descriptor like "1/1 · receipt_missing".
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0129WdYHccPsH27k5GGuwijd
Real front-end bugs found and fixed:
- [hidden] never worked on any element whose class also sets 'display'
(every .btn, .chip, ...): the browser's built-in '[hidden]{display:none}'
rule and an author rule of equal specificity tie, and the later one in the
cascade wins — so 'Next' stayed visible on the Review step alongside
'Start Exploitation', and 'Open report'/'Stop' rendered during 'starting'.
Fixed with a single global '[hidden]{display:none!important}' override.
- Progress bar was functionally correct but easy to miss (thin, 0%-width,
low-contrast track) and gave no feedback while the agent count is still
unknown (recon phase). Added a border for visibility and an indeterminate
sliding-segment state for the 'agents: ?' window.
- A live run watched in the browser was lost on F5 (jumped back to the
wizard) even though the job keeps running server-side. The active job id
now persists in localStorage; on load the app reconnects the SSE stream
(the server replays its full event buffer) instead of losing the view.
New:
- Findings are now clickable — a detail modal shows every Finding field
(CWE/CVSS/OWASP/MITRE/stage/exploitability/confidence/votes/review status/
auth context/account/agent), endpoint+payload, evidence, impact, business
impact, remediation, and chains_from — in both the live run and past-run
detail views.
- PoC surfacing: the finding modal looks up any script the run wrote to
pocs/ that's cited in the finding's evidence (per the harness's own
doctrine — see pipeline.rs change below), fetches and previews it inline,
with a link to open the raw file. Live runs poll for new PoC files every
5s once the run id is known.
- Pinned-leads confirmation: the live run header now states plainly how
many leads were pinned (and their names) or that selection is auto
(recon-driven) — this was previously buried in the scrolling activity log
behind the harness's unconditional 'Loaded 435 agents' library-size line,
which describes the full agent library, not what will actually run.
Harness doctrine (crates/harness/src/pipeline.rs, pocs_line()):
PoC-writing for black-box findings was previously conditioned on 'when an
issue needs a custom multi-step exploit/script' — vague enough that a
straightforward finding (single-request XSS/SQLi/IDOR) often got no PoC
file at all. Now required for every confirmed Medium+ finding, one
standalone .py/.sh script per finding, and explicit about citing the exact
file name in the finding's evidence field (which is what the web UI now
matches on to link a PoC to its finding).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0129WdYHccPsH27k5GGuwijd
Add two new model providers, both usable via API key or --subscription
(local CLI login, no key):
- opencode: OpenCode Zen gateway (OPENCODE_API_KEY, opencode.ai/zen/v1).
Subscription mode drives the `opencode` CLI (`opencode run --auto`).
Supports the Playwright MCP (--mcp): our .mcp.json is converted to
OpenCode's own config schema and injected via OPENCODE_CONFIG.
- nous: Nous Research / Hermes models (NOUS_API_KEY,
inference-api.nousresearch.com/v1). Subscription mode drives the
`hermes` CLI (NousResearch/hermes-agent) on the user's Nous Portal
OAuth login (`hermes setup --portal`), via `hermes chat -q`. No
CLI-level MCP hook — falls back to Hermes's own built-in toolsets
(web/terminal/computer-use).
Both wired into cli_binary_for, installed_cli_backends, cli_login_status
(prompt passed as argv, not stdin — neither CLI reads stdin for this).
Bump version 3.6.8 -> 3.6.9 across Cargo.toml, README, TUTORIAL, setup.sh,
install.ps1, and in-binary version strings. README/.env.example updated
with the new provider rows and subscription-login table.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HHFAVCHMvRkTy9Wgw7SayG
- Add RECON_TOTAL_BUDGET_SECS (300s) total wall-clock cap across all rounds
- Per-round budget directive in prompt: 30-50 commands max, stop early if enough intel
- Elapsed time check between rounds: skip remaining if budget exhausted
- Remaining time communicated to follow-up rounds for self-pacing
- RELEASE.md updated with recon budget section
Previously: subscription CLI recon ran 150+ commands over 15 min, exploitation never started.
Now: recon caps at 5 min total, then proceeds to agent exploitation.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- models.rs: detect connection-refused and timeout on local providers
(ollama/litellm/llamacpp), show actionable error instead of raw reqwest
- pipeline.rs: findings with empty evidence skip adversarial vote (which
always rejects per 'default to rejected' prompt) and go straight to
needs-review for human triage
- pipeline.rs: warn when single-model panel + vote_n=1 (same model
validates its own findings = weaker validation)
- Bump version 3.6.7 → 3.6.8
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011739wMqPJJPttTLLX6YoQH
Version bump 3.6.5 -> 3.6.6.
Local & uncensored models
- New `llamacpp:` provider (llama-server, OpenAI-compatible, localhost:8080,
no API key, CPU-only or GPU-offloaded). Override via LLAMACPP_BASE_URL;
model name is the loaded gguf (pass-through). 15 -> 16 providers.
- README: local/uncensored highlight, provider table + key-less note, badges.
Quality
- clippy clean under `-D warnings`: clamp(), sort_by_key(Reverse), struct-literal
init, too_many_arguments allows, scoped await_holding_lock on the REPL blocking
fallback (guard intentionally held across run().await), plus clippy --fix set.
CI
- examples/github-actions/ci.yml: cargo build/test/clippy -D warnings for the
neurosploit-rs workspace (template, kept out of .github/workflows).
Claude-Session: https://claude.ai/code/session_01QDses7zTSa9YF7pPRjphvh
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
GitHub automation
- integrations: github_set_status (commit status), github_pr_review
(REQUEST_CHANGES/APPROVE), github_pr_head_sha, and a shared severity
gate (severity_rank / worst_confirmed_rank / gate_trips — confirmed
findings only).
- `neurosploit pr --fail-on <critical|high|medium|low>`: on a confirmed
finding at/above the threshold, sets a failing `neurosploit/security`
commit status, posts a REQUEST_CHANGES review, and exits 2 so a CI
check fails — branch protection then blocks the merge.
- Two ready GitHub Actions: neurosploit-pr-gate.yml (review + block every
PR) and neurosploit-mention.yml (writers comment @neurosploit <text> to
trigger a scan; any language; URL → black-box, else PR review).
Natural-language REPL
- Intent now also parses spoken toggles/knobs across PT/EN/ES: Burp/proxy,
browser/MCP, subscription, "N votos/votes", recon depth (number or
quick/deep/exhaustive), plus stop verbs. handle_nl returns the follow-up
command (/run or /stop).
Docs: README trimmed to features (version changelog stays in RELEASE.md),
new automations documented in README + TUTORIAL-INTEGRATION.
Tests: gate (3), NL toggles/stop (added). All green.
Claude-Session: https://claude.ai/code/session_018BGLy4j5qsqqid6CoovowC
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
* feat: embed proof screenshots in reports, correlated to findings
Define a convention that ties each proof image to its vulnerability and
renders it in every report format.
- Finding gains `screenshots: Vec<String>` (paths relative to the run
workdir, e.g. evidence/<finding-id>-1.png).
- Exploit prompt injects an EVIDENCE SCREENSHOTS doctrine: agents save
proof PNGs into the run's absolute evidence/ dir named by a vuln slug,
and list them in the finding JSON `screenshots` array.
- collect_evidence() resolves whatever the agent captured (absolute,
workdir-relative, evidence/, /tmp basename), copies it to a stable
evidence/<finding-id>-N.png, and rewrites the field; unresolved refs
are dropped so a report never embeds a missing image.
- Typst (image()), HTML (<img>) and Markdown (![]) render each finding's
screenshots beside its evidence.
Tests: slugify + collect_evidence resolution/rename; verified a real PDF
compiles with an embedded image.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018BGLy4j5qsqqid6CoovowC
* feat: source-able env.sh to activate neurosploit in the current shell
Add env.sh: `source` it to export NEUROSPLOIT (binary path),
NEUROSPLOIT_BASE (agents base) and prepend the binary dir to PATH —
no reinstall or new terminal needed. Auto-detects the install/repo dir,
honors NEUROSPLOIT_DIR, idempotent. setup.sh now writes a ready env.sh
into the install dir and points users at `source <dir>/env.sh`.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018BGLy4j5qsqqid6CoovowC
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Add two operator inputs that give agents more test context, both
funneled through operator_directives() so they reach every recon/
exploit prompt (web, host, ai, skills):
- objective: WHY the test runs and WHAT counts as impact — rendered
as high-priority ENGAGEMENT OBJECTIVE context.
- out_of_scope: hosts/paths/techniques to exclude — rendered as a
HARD CONSTRAINT the agents must skip and never report against.
REPL: /objective and /scope-out commands (accumulating), optional
onboarding prompts, /show + /help + Tab-complete, session.json
persistence (serde default for back-compat).
CLI: neurosploit run --objective --out-of-scope.
Version unchanged (3.6.5).
Claude-Session: https://claude.ai/code/session_018BGLy4j5qsqqid6CoovowC
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
- Preflight: abort a run early with '✗ target unreachable … is DOWN' when the
probe gets no HTTP response, instead of running agents against a dead host;
print '✓ target is UP' otherwise.
- When no --auth/creds are set on a web run, force account_registration_and_forms
to run first so the authenticated surface is always attempted and visible.
- Move the credential vault to <cwd>/.neurosploit/vault/<run-id>.json (persistent
project store) via new RunConfig.vault_dir; header now prints the vault path at
launch. engagement_ops + finish() resolve paths through vault_paths().
- New agent account_registration_and_forms (+1 → 430): analyzes the app's forms
and self-registers a benign test account (curl or Playwright) to reach the
authenticated surface when no creds are given.
- Probe extracts form details (action/method/fields/kind/CSRF) so form analysis is
grounded; shown in the probe summary and recon JSON.
- Hard anti-flood guardrail in SAFETY_DOCTRINE + the agent: at most 2 accounts per
engagement, never loop/script/batch the register endpoint or flood the DB; reuse
the account made; a test needing many sign-ups is a lead, not mass-creation.
- Credential vault: engagement_ops directive tells agents to append created
accounts to <run-dir>/vault.jsonl; finish() consolidates to vault.json, masks
secrets in the report, and adds a 'Test accounts created (DELETE after)' cleanup
finding listing each account and how it was created.
- Finding tagging: new auth_context (authenticated/unauthenticated) and account
fields, rendered per-finding in the HTML report.
- Opt-in disposable email (off by default): /tempmail on + RunConfig.temp_email;
agents may use the free mail.tm API to read a registration confirmation code.
- Tests: parse_forms unit tests; docs updated (README/TUTORIAL/RELEASE), counts 430.
- Add 12 technique/scenario LLM red-team agents (AI category 18 → 30, total 429):
jailbreaks — AdvPrefix, PAIR, TAP, Crescendo, many-shot, persona/DAN,
encoding/obfuscation, refusal-suppression; prompt-injection scenarios — direct,
indirect (RAG/web/email/tool output), goal hijacking, tool/function-call abuse,
system-prompt/secret exfiltration. Each runs an attacker→LLM-judge loop
(baseline refusal → technique across variants → verdict), proving the bypass
with a benign, redacted receipt. Generated by scripts/build_llm_redteam_v365.py.
- Add REDTEAM_DOCTRINE and inject it into run_ai so every AI test follows the
baseline→technique→judge method across scenarios.
- Models: add Claude Opus 5 and Sonnet 5 (Anthropic) and a new Moonshot AI (Kimi)
provider with Kimi K3/K2 (moonshot:kimi-k3, MOONSHOT_API_KEY) — 15 providers.
- Docs: README/TUTORIAL/RELEASE — new AI/LLM red-team engagement mode + section,
model/env-key tables, agent-library counts (429), badges.
Also includes the v3.6.4 grounding fix (#33) landing on main.
The grounding gate ran in empirical mode for every engagement, demoting
white-box (and skills/n8n audit) findings that had passed the n-model vote
because a file:line code citation isn't raw tool output. Grounding is now
mode-aware:
- Symbolic (white-box SAST / skills): a file:line reference into the reviewed
source, or a quote of code present in it, is the receipt — no live target.
- Empirical (black-box / host / AI): evidence must resemble tool output (as before).
- Either (grey-box): a source citation OR a tool receipt grounds a finding.
The symbolic check runs against the reviewed source corpus (not the transcript)
and falls back to a structural file:line + quote check when the corpus is
unavailable. Adds unit tests incl. a regression test for #33.
- /continue (and /resume) now relaunch a recovered interrupted run on the same
target, carrying its findings forward and steering agents to widen coverage /
chain from them instead of re-reporting. Offer shown at launch; a fresh /run
supersedes it. Findings merge (dedup by title+endpoint) across both runs.
- Opening /results, /finding or /report while a run streams no longer corrupts
the terminal: live background output is paused for the picker (still captured
in /logs) and restored on exit, so Ctrl-C in a picker can't take the process
down mid-run.
A missing or un-downloadable recon tool must never block the run. Both the recon
intensity directive and the general tool doctrine now instruct agents to:
- wrap every install in `timeout 90 <install> || echo skip` and run non-interactively
- try each tool install at most once; on failure/no-package/no-network/hang, skip
immediately and fall back to an installed alternative or curl/nc/dig/python3
- never wait on, retry, or block the whole recon for a single tool download
- Drive `codex exec --json` and parse its JSONL event stream into the same
categorized live feed as Claude Code (exec/edit/tool/net/tokens), so recon and
exploitation are visible as each command runs instead of a silent black box.
- Fix the activity feed to keep per-agent tool events (commands, network, files,
findings) and only filter model reasoning + token telemetry, so /logs shows the
real command trail and /status 'last:' is a true sign-of-life.
- Surface failed internal commands as 'exec: (exit N)'; keep Codex auth/rate
detection from stderr.
`codex exec` in --dangerously-bypass-approvals-and-sandbox mode exits non-zero
when a tool/command it ran internally (curl/nmap/etc.) returned non-zero — even
though it produced a valid final answer. chat_cli treated any non-zero exit as a
hard failure and dropped the output ("recon round 1 failed ... exit 1"). Now, on
non-zero exit WITH usable stdout and no auth/rate/quota keyword, we use the
output; only genuine auth/rate/quota errors (or empty output) fail hard.
Added the OpenAI GPT-5.6 line to the provider pool: gpt-5.6-sol (frontier/default),
gpt-5.6-terra (balanced), gpt-5.6-luna (fast/affordable). Version 3.6.0 -> 3.6.1.
Recon was a single quick model pass — now it's deep and iterative:
- deep_recon(): an initial deep enumeration pass then follow-up EXPANSION rounds
that chase discovered subdomains/hosts/endpoints/params, converging when a
round finds nothing new. Rounds scale with intensity.
- recon_intensity_directive(): tells the agent HOW hard to recon and to INSTALL
the tools it needs (apt/pip/go/npm/cargo) — subfinder/amass/httpx/gau/katana/
gf/arjun/ffuf/nuclei/nmap/dnsx/linkfinder/whatweb/nikto/testssl — chained
(subfinder->httpx->katana/gau->gf->ffuf); covers subdomains, crawl+wayback, JS,
content/param discovery, ports, versions, API, exposures, TLS/headers.
- RunConfig.recon_intensity (default 3) + REPL /recon <1-4> + CLI --recon <1-4>
(1 quick .. 4 exhaustive); shown in /show.
- DECISION_DOCTRINE injected into exploit/grey/chain prompts: analyse responses to
pick the technique; map & connect routes (endpoint output → next endpoint input);
hunt sensitive flows; mine parameters (incl. hidden from JS/source maps) and test
per-param; mock realistic (non-PII) data to reach deeper logic; exploit the
authenticated surface after login and compare roles; build PoCs when a proof
needs an artifact; bypass 401/403/redirect controls.
- REPL /auth now supports multiple named identities (/auth admin <hdr>, /auth user
<hdr>; bare token → Bearer). With >=2 roles the run gets the access-control
directive (IDOR/BOLA/BFLA/privesc, authorized-vs-unauthorized) and tests both.
- +6 decision agents (library 389): param_miner, endpoint_flow_linker,
authenticated_surface_exploit, clickjacking_poc (HTML PoC), csrf_poc (HTML PoC),
access_control_bypass.
- Docs: counts 383->389, RELEASE + /auth help updated.
- /results (interactive, no arg) now ALWAYS opens the run/test picker (target →
vuln → detail, Esc back) instead of jumping straight to the current run's vulns.
The live run (if any) appears at the top, past runs newest-first — so you can
browse every test, not only the active one.
- /validate [n]: re-run false-positive validation (N-model voting + adversarial
refute) on a recovered/past run's findings WITHOUT re-testing the target, then
rewrite that run's findings + report. Backed by new harness::pipeline::revalidate.
Use this after a crash/quit recovered raw findings into /runs.
- Ctrl-C at the prompt now CONFIRMS instead of silently cancelling: with a live
run it offers [s]top&validate / [q]uit(keep findings) / keep-running; otherwise
asks "exit? [y/N]" — so a stray Ctrl-C can't lose a running test.
- tool_doctrine: agents now actively DRIVE the browser on JS/SPA targets — use
the Playwright MCP (render, read live DOM, click client-side routes, watch the
network to find the real API, screenshot proof); when no MCP, use the Playwright
CLI (write+run a small script / npx playwright screenshot) to render and capture
XHR/fetch traffic — complementing curl (which only sees the empty shell).
- probe: detect SPAs (<app-root>, ng-version, near-empty body + linked scripts →
Angular/React/Vue/SPA) and note in recon that the browser is required, so the
SPA agents get selected.
- +8 SPA/API agents (library 383): spa_api_discovery, spa_hidden_admin,
login_sqli_bypass, dom_xss_spa, api_bola_numeric_ids,
register_privilege_mass_assign, jwt_forgery_spa, spa_business_logic.
- Docs: README/RELEASE/TUTORIAL counts + notes.
Why runs came back empty / "MCP didn't execute":
- Not logged in: a subscription CLI that isn't authenticated returns empty
instantly (the Juice Shop symptom — every agent 0 candidates, no tool activity).
Added models::cli_login_status + subscription_preflight(): before a run we check
the primary provider's CLI is installed AND logged in and warn clearly if not
(CLI run_mode + REPL start_background).
- Missing browser: ensure_playwright_mcp now also runs `npx playwright install
chromium` (best-effort; NEUROSPLOIT_SKIP_BROWSER_INSTALL=1 to skip) so the first
browser action doesn't fail/hang.
- Codex MCP was mis-wired (`--config mcp_config_file=` is not a codex key). Now
injects our .mcp.json servers via `-c mcp_servers.<name>.command/.args` TOML
overrides — MCP works on Codex, not only Claude. gemini/grok remain built-in-tools
only (no MCP flag).
- REPL diagnostic: subscription+MCP run with zero tool/browser events warns the
CLI likely isn't logged in / MCP didn't start.
New harness::probe runs a real request/response analysis of the target BEFORE
the model recon and injects the observed facts into recon, so agent-selection
and exploitation decisions are grounded in evidence (robust even when model
recon is weak):
- status & redirect, Server/X-Powered-By/content-type, 6 security headers,
cookie flags (HttpOnly/Secure/SameSite), CORS reflection test (arbitrary
Origin + credentials), tech fingerprint, linked scripts, form count, a 404
baseline for soft-404 differentials, and high-signal paths (/robots.txt,
/.git/config, /.env, /sitemap.xml, /.well-known/security.txt).
- Best-effort (never fatal — degrades to a note on network failure), honors the
identifying User-Agent and the Burp/ZAP proxy. Wired into black-box run() and
greybox recon. A one-line probe summary streams to the live feed.
Attribution (anti-plagiarism), multiple layers:
- Identifying User-Agent on every request (default NeuroSploit/<ver> + an
X-NeuroSploit-Scan header), overridable via /ua or NEUROSPLOIT_UA env; shown
in the run banner. RunConfig.user_agent + Session.user_agent wired through.
- Every finding is stamped "Identified and validated by NeuroSploit …" (in
finish() and the raw-report path) so provenance travels in the finding text,
findings.json and the report.
Multi-role authentication for access-control testing (IDOR/BOLA/BFLA/privesc):
- creds.yaml gains named identity blocks (admin:/user:/victim:/…), each with
jwt | header | cookie | apikey | login+username+password. With >=2 roles the
harness injects a cross-role access-control directive (authorized-vs-unauthorized
proof) and defaults the primary auth to the first role.
Also: /help now lists one command per line (fixes smushed OPTIONS/RUN columns);
/ua command + Session field; docs (README + RELEASE) updated.
REPL (v3.5.5):
- /timeout <min>: idle guardrail — if no NEW finding lands within the window the
run soft-stops and validates what was found (default 5 min; 0 disables).
- /target accepts a comma-separated list; /run tests them SEQUENTIALLY (a queue
auto-advances to the next target when the current run finishes; one report each).
- /results (no arg, interactive): navigation browser — pick target/run → pick
vulnerability → full detail; Esc steps back a level (vuln → target → session).
- /report (no arg, multiple runs): pick which report to open from a menu.
- /show now shows idle-stop; help updated.
Agent prompts:
- RECON_SYS deepened: crawl + params/headers/cookies, DOWNLOAD & analyze linked
JS (endpoints, hidden params, GraphQL, secrets, sourceMappingURL), fingerprint
exact versions, response-differential analysis; richer JSON schema.
- tool_doctrine adds JS-analysis and request/response-analysis guidance
(linkfinder/gau/katana, header/cookie/timing/length differentials).
Replaces the single-shot chain_round with attack_chain(): an iterative,
per-foothold pivot engine.
- Each round takes the newest confirmed footholds (best-first, capped) and, for
EACH one, an agent DECIDES which directions to expand — post-exploitation
(loot creds/keys/config/source), credential reuse, horizontal+vertical
privesc, lateral movement to adjacent services/hosts, data exfiltration, and
new attack surface the foothold exposes — proving each step with a receipt.
- LOOT (creds/tokens/hosts/endpoints) discovered in one round is carried forward
and reused by later rounds (parsed from a {"findings":[...],"loot":[...]} reply).
- New findings are validated each round (never pivot off a false positive) and
become the next round's footholds. Loop-until-dry or chain_depth rounds.
- New RunConfig.chain_depth (default 2) + --chain-depth flag on all engagement
commands (0 disables). CHAIN_SYS rewritten for decision/post-ex framing.
- Robust verdict parsing (pool::parse_verdict): whitespace-insensitive, checks
explicit rejection first, counts only explicit confirmations; ambiguous →
Unclear (not confirmed). Replaces the fragile exact-JSON / loose "yes" match.
- Severity-aware quorum (pool::quorum_confirmed): High/Critical now need ≥2
validators AND ≥2/3 agreement (a single vote can no longer confirm a
Critical); lower severities need a strict majority (>half, was ≥half). Single-
model panels fall back to majority so they aren't nuked.
- Adversarial refute pass (REFUTE_SYS): every confirmed High/Critical is
re-examined by a skeptical panel that assumes false-positive; findings that
can't withstand a majority of skeptics are dropped. Survives on infra failure.
- Strengthened VOTE_SYS with an explicit false-positive checklist (reflected-not-
executed, version/banner guesses, self-XSS, error-as-injection, thin evidence,
inflated severity); validator query now also includes impact.
- Unit tests for parse_verdict + quorum_confirmed.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>