- /scope-file now reads optional engagement keys from the SAME YAML (target,
models, focus, objective, authorization, classes) so one file defines the
whole engagement, not just scope. examples/scopes/nasa.yaml and
engagement.example.yaml show the keys.
- When importing a scope (/scope-file) or declaring one (/authorize), a target
left over from a previous session that falls OUTSIDE the new scope is reset to
a host inside it (was: silently kept, then denied on /run — the "nothing
changed" confusion). Added scope_seed_target() + in_hard_scope() check.
- UI/help strings are English; the natural-language REPL still accepts input in
any language (the two example lines are now English).
- README + TUTORIAL updated: new REPL commands (/authorize, /scope-file, /class,
/research, /quick, /authorization, /guardrail), a "Scope — three ways" section
with the one-file YAML, version/counts refreshed to 4.2.1 / 480 agents.
422 tests passing.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Hard scope stays the safety boundary (you must say what you're allowed to test),
but setting it is now frictionless for a normal client pentest where authorization
comes from a signed SOW/contract — no bug-bounty program or capability token.
- /authorize <host|*.dom|cidr|url> ... (aliases /grant, /inscope-set): set the
entire authorized scope in one line (multiple entries), pins it so /target
won't re-derive, and seeds the target so /run works immediately. The operator
asserts written authorization for the listed assets; guardrails (rate,
accounts, destructive) remain tunable via /guardrail.
- examples/scopes/engagement.example.yaml — neutral direct-engagement template
(no program framing): fill hard scope from the SOW, guardrails documented as
yours to tune (e.g. allow destructive in a staging env, raise rate for a lab).
The frictionless path already worked (/target x -> authorized against x); this
makes the multi-asset direct engagement a single clear command. 422 tests.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- /scope-file <path> (aliases /scopefile, /import-scope): import a ready scope
config (hard allowlist + exclusions + guardrails) in the REPL — one step to
"scope set correctly", instead of typing /inscope repeatedly. Pins the scope.
- scope_pinned: once scope is set explicitly (scope-file / /inscope / capability),
/target no longer re-derives the scope from the target, so an imported
allowlist is not clobbered by picking a target.
- examples/scopes/rockstargames.yaml and examples/scopes/nasa.yaml — ready
TEMPLATES scoped to *.rockstargames.com / *.nasa.gov with conservative,
bounty/VDP-safe guardrails (no destructive verbs, no mass accounts, low rate,
forbidden payloads) and a clear "verify the program's current in/out-of-scope
before running" banner. Both parse and enforce; subdomain enumeration happens
inside the wildcard boundary.
422 tests passing.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>