Commit Graph
2 Commits
Author SHA1 Message Date
CyberSecurityUPandClaude Opus 4.8 88255152fe docs: add a broad focus example (TUTORIAL 6.2 + engagement.example.yaml)
A copy-paste full-surface focus string (all web classes, prioritise authed
surface + subdomains, chain to impact, reproducible receipt) and an
objective-vs-focus note; the engagement template now carries the broad
focus/objective in its one-file config.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-04 07:43:45 -03:00
CyberSecurityUPandClaude Opus 4.8 c233da8b17 feat(repl): /authorize — declare the whole scope in one line for a direct engagement
Hard scope stays the safety boundary (you must say what you're allowed to test),
but setting it is now frictionless for a normal client pentest where authorization
comes from a signed SOW/contract — no bug-bounty program or capability token.

- /authorize <host|*.dom|cidr|url> ... (aliases /grant, /inscope-set): set the
  entire authorized scope in one line (multiple entries), pins it so /target
  won't re-derive, and seeds the target so /run works immediately. The operator
  asserts written authorization for the listed assets; guardrails (rate,
  accounts, destructive) remain tunable via /guardrail.
- examples/scopes/engagement.example.yaml — neutral direct-engagement template
  (no program framing): fill hard scope from the SOW, guardrails documented as
  yours to tune (e.g. allow destructive in a staging env, raise rate for a lab).

The frictionless path already worked (/target x -> authorized against x); this
makes the multi-asset direct engagement a single clear command. 422 tests.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-03 23:57:28 -03:00