New --research mode for whitebox/greybox (REPL /research, web 🔬 checkbox, or
auto-detected from natural-language focus/objective in PT/EN). Steers the source
review to find a NOVEL, CVE-reportable issue instead of a known one:
- WHITEBOX_RESEARCH_DOCTRINE: pin version/commit; research known CVEs/advisories
(SECURITY.md, CHANGELOG, GHSA, NVD, git history) to de-duplicate; patch-diff /
n-day->0-day variant analysis (incomplete fixes, bypasses of a new check,
sibling sinks, reintroductions); strict novelty gate (each finding states
novel-why + checked-against); benign PoC + dynamic confirm on greybox.
- RunConfig.research + is_research_intent(); injected in run_whitebox and the
greybox code-review half.
- 6 research skills (code/): known_cve_dedup, patch_diff_variant,
attack_surface_map, source_to_sink_taint, logic_authz_flaw,
dependency_nday_reachability.
- Methodology modeled on a real AppSec-research workflow (no specifics copied).
479 agents, 421 tests.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>