mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-05 07:27:18 +02:00
(1) Preflight now checks EVERY configured model, not just the primary — a 3-model jury that silently collapses to 1 (others not logged in / no key) is now shown: each model prints usable/needs-login/needs-key, with a '→ N/M models usable' summary. Fixes 'I set 3 models and only opus ran'. (qwen is API-only: use nous:qwen3.8-max for Hermes, or export DASHSCOPE_API_KEY.) (2) Wildcard engagement (*.domain in scope) now gets a deterministic subdomain fan-out before recon: enumerate via crt.sh + subfinder/amass (in the Kali sandbox when --sandbox, else host), keep only IN-SCOPE hosts, probe liveness, drop soft-404/parked catch-alls, rank (401/403 auth hosts first — flagged for bypass — then interesting names admin/api/dev/staging), and fold the live list into the test surface so the run tests the WHOLE authorized domain end-to-end, not just the seed host. Scope-respecting: one lightweight GET per host, no degradation. (3) recon_tool() runs a recon tool in the Kali sandbox or on the host — the basis for tool-powered recon. 423 tests passing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>