- Container image scanning: new `container` mode + 4 skills (vuln, secret,
misconfig, SBOM) driving trivy/grype/syft headless, read-only. Scans an OCI
ref / tar / Dockerfile for vulnerable packages (CVE/fixed-in/KEV), exposed
secrets in any layer, Dockerfile+runtime misconfig, and writes an SBOM in
both SPDX and CycloneDX to the run's sbom/. Also exposed as an MCP tool
(neurosploit_container).
- Coverage report: every run writes coverage.md — which agents ran (tested
surface), findings per agent, and the high-value classes NOT covered — so the
reader sees the engagement's reach. Added to the assurance bundle.
- Login-verification evidence: doctrine now requires capturing the login
request/response + a Playwright screenshot and recording success/failure
before authenticated testing.
- HTTP traffic export: `neurosploit traffic <run>` turns the intercepted
flows.jsonl into a traffic.http archive for external tools.
Not ported: Asset Discovery (enterprise-only, skipped per request).
383 tests.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
New `mobile` engagement mode: `neurosploit mobile <app.apk|app.ipa|binary>`
reverse-engineers a local artifact with a dedicated `mobile` agent set, all
headless and provisioned on demand (Ghidra analyzeHeadless, MobSF REST/Docker,
Frida, apktool/jadx, radare2).
Twelve original, generic skills (agents_md/mobile/, English): static binary
triage, APK static analysis, IPA static analysis, RASP & anti-tamper mapping,
root/jailbreak detection + bypass, TLS pinning detection + bypass, anti-debug
detection + bypass, obfuscation analysis & deobfuscation, code-integrity /
tamper-check bypass, hardcoded-secrets extraction, insecure local storage, and
mobile network traffic analysis. Findings are proven from the artifact
(decompilation or Frida trace), non-destructively.
- agents.rs: new `mobile` Library category (loaded, counted).
- pipeline.rs: run_mobile() mirroring the host pipeline with a mobile recon and
headless tooling doctrine; exported from the crate.
- CLI: `Cmd::Mobile` + `Mode::Mobile`, wired in main and the TUI.
- README + TUTORIAL document the new test type; engagement-modes badge + table
updated; "New in v4.2.0" note. Version bumped to 4.2.0 across the workspace.
383 tests.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Chaining:
- agents_md/chains/ (12 multi-stage exploitation playbooks): SQLi→RCE→LPE,
SSRF→AWS-creds, SSRF→RCE, upload→RCE, upload→LFI→RCE→LPE, XSS→ATO, IDOR→ATO,
SSTI→RCE→cloud, default-creds→domain, deserialization→RCE, exposed-git→RCE,
subdomain-takeover→trusted-abuse. Each stage proven by a tool receipt before
advancing; reports chains_from edges.
- Loaded as a `chains` category (→ 329 agents). chain_round now injects the chain
recipes as a menu so the LLM applies proven multi-stage paths.
Persistence (no DB — structured state):
- Per-project `<cwd>/.neurosploit/` holding session.json (config), runs.json
(history), history.txt (readline). REPL resumes target/repo/auth/focus/models
on reopen; saves on /run and /quit.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>