mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-06-29 23:05:30 +02:00
a5badefc29
Engine:
- Fix: inject IS_SANDBOX=1 so Claude Code's --dangerously-skip-permissions
works under root (real backend runs were exiting rc=1 immediately)
- models: expand to 40 models / 13 providers, tagged CLI vs API
(NVIDIA NIM, DeepSeek, Mistral, Qwen/DashScope, Groq, Together, OpenRouter,
Ollama, Gemini) — Qwen/DeepSeek/Llama usable via API
- backends: on_start callback surfaces the exact argv ("what runs behind it")
- orchestrator: require a Playwright screenshot per confirmed finding; collect
results/activity.json; auto-generate reports after a run
- report.py: HTML always + PDF via Typst engine (.typ source emitted too)
Web dashboard (webgui/, stdlib only — no npm/build):
- Sidebar dashboard (PentAGI-style): Run / Agents / Insights / Reports / Settings
- Multi-target runs; live execution console + per-task activity; finding cards
with screenshots; backend+provider+model pickers (CLI & API)
- Agents tab: browse 213 + add new .md agents from the UI
- Insights: interactive RL-weight + severity charts
- Reports: download/preview PDF + HTML
- Settings/API: execution mode, per-provider API keys, orchestrator, verbosity
- Endpoints: /api/agents (GET/POST), /api/rl, /api/config, /api/reports,
/reports/* + /shots/* static serving
Cleanup: retire replaced web stack (frontend React, FastAPI backend, core
orchestration, old test) to legacy/. Active engine + GUI are fully standalone.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Legacy (pre-v3.3.0) Python orchestration
These files are the previous orchestration architecture, retired in NeuroSploit v3.3.0 when the pentest agent was re-modeled into an autonomous, markdown-driven engine that delegates execution to a local agentic CLI backend.
Kept for reference and migration only — not used by the v3.3.0 engine.
| Path | What it was |
|---|---|
neurosploit_legacy.py |
The 2,500-line monolithic CLI/orchestrator (NeuroSploitv2) |
agents_python/ |
Hand-coded Python agent classes (web/exploitation/lateral/privesc/persistence/recon) |
custom_agents/ |
Example custom Python agent |
core/ |
Old orchestration support (llm_manager, sandbox, report_generator, …) |
backend_fastapi/ |
Old FastAPI backend — replaced by webgui/server.py (stdlib) |
frontend_react/ |
Old React/Vite dashboard — replaced by the minimalist webgui/ |
test_agent_run.py |
Test harness for the old Python agents |
What replaced it
neurosploit+neurosploit_agent/— the lean autonomous engine (orchestrator,agent_loader,backends,rl,mcp,models,cli).agents_md/— 213 curated markdown agents (196 vuln specialists + 17 meta-agents) that the engine composes into a master prompt.- The engine runs Claude Code / Codex / Grok CLI (or a Claude subscription) as the autonomous runtime, with Playwright MCP for browser-based proof and a reinforcement-learning loop that adapts agent selection across runs.
Run ./neurosploit (interactive) or ./neurosploit run <url> to use the new engine.