Commit Graph
8 Commits
Author SHA1 Message Date
CyberSecurityUPandClaude Opus 4.8 88255152fe docs: add a broad focus example (TUTORIAL 6.2 + engagement.example.yaml)
A copy-paste full-surface focus string (all web classes, prioritise authed
surface + subdomains, chain to impact, reproducible receipt) and an
objective-vs-focus note; the engagement template now carries the broad
focus/objective in its one-file config.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-04 07:43:45 -03:00
CyberSecurityUPandClaude Opus 4.8 3a820f09e6 feat: one-file engagement configs; scope-file reseeds stale target; English UI + any-language input; docs
- /scope-file now reads optional engagement keys from the SAME YAML (target,
  models, focus, objective, authorization, classes) so one file defines the
  whole engagement, not just scope. examples/scopes/nasa.yaml and
  engagement.example.yaml show the keys.
- When importing a scope (/scope-file) or declaring one (/authorize), a target
  left over from a previous session that falls OUTSIDE the new scope is reset to
  a host inside it (was: silently kept, then denied on /run — the "nothing
  changed" confusion). Added scope_seed_target() + in_hard_scope() check.
- UI/help strings are English; the natural-language REPL still accepts input in
  any language (the two example lines are now English).
- README + TUTORIAL updated: new REPL commands (/authorize, /scope-file, /class,
  /research, /quick, /authorization, /guardrail), a "Scope — three ways" section
  with the one-file YAML, version/counts refreshed to 4.2.1 / 480 agents.

422 tests passing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-04 00:03:50 -03:00
CyberSecurityUPandClaude Opus 4.8 c233da8b17 feat(repl): /authorize — declare the whole scope in one line for a direct engagement
Hard scope stays the safety boundary (you must say what you're allowed to test),
but setting it is now frictionless for a normal client pentest where authorization
comes from a signed SOW/contract — no bug-bounty program or capability token.

- /authorize <host|*.dom|cidr|url> ... (aliases /grant, /inscope-set): set the
  entire authorized scope in one line (multiple entries), pins it so /target
  won't re-derive, and seeds the target so /run works immediately. The operator
  asserts written authorization for the listed assets; guardrails (rate,
  accounts, destructive) remain tunable via /guardrail.
- examples/scopes/engagement.example.yaml — neutral direct-engagement template
  (no program framing): fill hard scope from the SOW, guardrails documented as
  yours to tune (e.g. allow destructive in a staging env, raise rate for a lab).

The frictionless path already worked (/target x -> authorized against x); this
makes the multi-asset direct engagement a single clear command. 422 tests.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-03 23:57:28 -03:00
CyberSecurityUPandClaude Opus 4.8 8354a85cb7 chore: keep Rockstar scope config local-only (untrack + gitignore); NASA stays
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-03 23:54:32 -03:00
CyberSecurityUPandClaude Opus 4.8 4ef1c9cada feat: importable scope configs + /scope-file REPL command; Rockstar & NASA templates
- /scope-file <path> (aliases /scopefile, /import-scope): import a ready scope
  config (hard allowlist + exclusions + guardrails) in the REPL — one step to
  "scope set correctly", instead of typing /inscope repeatedly. Pins the scope.
- scope_pinned: once scope is set explicitly (scope-file / /inscope / capability),
  /target no longer re-derives the scope from the target, so an imported
  allowlist is not clobbered by picking a target.
- examples/scopes/rockstargames.yaml and examples/scopes/nasa.yaml — ready
  TEMPLATES scoped to *.rockstargames.com / *.nasa.gov with conservative,
  bounty/VDP-safe guardrails (no destructive verbs, no mass accounts, low rate,
  forbidden payloads) and a clear "verify the program's current in/out-of-scope
  before running" banner. Both parse and enforce; subdomain enumeration happens
  inside the wildcard boundary.

422 tests passing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-03 23:53:53 -03:00
CyberSecurityUPandClaude Opus 5 8894649ccb feat(scope): --scope-file YAML loader + web Scoping/Guardrails UI
Hard scoping was already enforced in code (every request passes
ScopePolicy::check_request; exclude beats allowlist; capability token caps
it; out-of-scope findings withheld + audited). What was missing was a way to
author that boundary from a file or the web form instead of only CLI flags.

- scope.rs: ScopePolicy::from_yaml / from_file — a dependency-free parser for
  the friendly string format (app.example.com, *.wildcard, CIDR, url-prefix),
  the same strings Pattern::parse already takes, NOT the raw serde {kind,value}
  shape. Strict in one direction: an unreadable file errors, an empty hard list
  authorizes nothing (a safe failure, but the operator's choice, not a typo).
- CLI: --scope-file <yaml>. Loaded before authorization so --in-scope adds to
  it and the capability grant still caps it.
- Web: a full Scoping & Guardrails section in the Authorization tab — hard
  scope, exclusions, observe-only, destructive-method + account-creation
  toggles, max accounts, rate limit, forbidden payloads, notes. The server
  materializes a scope YAML and passes --scope-file; notes stay labelled
  "guidance, NOT enforced" so prose is never mistaken for a control.
- examples/scope.example.yaml documents the format.

End-to-end verified: web form -> YAML -> Rust loader -> enforced boundary.
332 tests (+4).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-18 19:20:29 -03:00
Joas A SantosandClaude Fable 5 f913af211d feat(3.6.6): local/uncensored llama.cpp provider, clippy clean, CI (#40)
Version bump 3.6.5 -> 3.6.6.

Local & uncensored models
- New `llamacpp:` provider (llama-server, OpenAI-compatible, localhost:8080,
  no API key, CPU-only or GPU-offloaded). Override via LLAMACPP_BASE_URL;
  model name is the loaded gguf (pass-through). 15 -> 16 providers.
- README: local/uncensored highlight, provider table + key-less note, badges.

Quality
- clippy clean under `-D warnings`: clamp(), sort_by_key(Reverse), struct-literal
  init, too_many_arguments allows, scoped await_holding_lock on the REPL blocking
  fallback (guard intentionally held across run().await), plus clippy --fix set.

CI
- examples/github-actions/ci.yml: cargo build/test/clippy -D warnings for the
  neurosploit-rs workspace (template, kept out of .github/workflows).


Claude-Session: https://claude.ai/code/session_01QDses7zTSa9YF7pPRjphvh

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-03 23:48:08 -03:00
Joas A SantosandClaude Opus 4.8 3786d7c559 feat: PR security gate, @neurosploit bot, richer NL REPL (#39)
GitHub automation
- integrations: github_set_status (commit status), github_pr_review
  (REQUEST_CHANGES/APPROVE), github_pr_head_sha, and a shared severity
  gate (severity_rank / worst_confirmed_rank / gate_trips — confirmed
  findings only).
- `neurosploit pr --fail-on <critical|high|medium|low>`: on a confirmed
  finding at/above the threshold, sets a failing `neurosploit/security`
  commit status, posts a REQUEST_CHANGES review, and exits 2 so a CI
  check fails — branch protection then blocks the merge.
- Two ready GitHub Actions: neurosploit-pr-gate.yml (review + block every
  PR) and neurosploit-mention.yml (writers comment @neurosploit <text> to
  trigger a scan; any language; URL → black-box, else PR review).

Natural-language REPL
- Intent now also parses spoken toggles/knobs across PT/EN/ES: Burp/proxy,
  browser/MCP, subscription, "N votos/votes", recon depth (number or
  quick/deep/exhaustive), plus stop verbs. handle_nl returns the follow-up
  command (/run or /stop).

Docs: README trimmed to features (version changelog stays in RELEASE.md),
new automations documented in README + TUTORIAL-INTEGRATION.

Tests: gate (3), NL toggles/stop (added). All green.


Claude-Session: https://claude.ai/code/session_018BGLy4j5qsqqid6CoovowC

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-02 19:12:18 -03:00