Files
NeuroSploit/neurosploit-rs
CyberSecurityUPandClaude Opus 4.8 101eca2700 fix: wildcard-target probe, per-run provenance, qwen via Hermes, broad default web objective
- Wildcard target from a scope-file (target: "*.nasa.gov") was probed literally
  → "builder error" / target unreachable. It's now reduced to the apex
  (https://nasa.gov) for the seed, while the scope keeps *.nasa.gov so subdomain
  enumeration stays authorized. (The /target command already did this; the
  engagement-file meta path didn't.)
- Provenance was a OnceLock ("first run wins"), so in the REPL every run after
  the first minted markers and the provenance line with the FIRST run's id
  (nasa run showing a rockstargames id). Now a RwLock that rebinds per run —
  each engagement gets its own id; the build fingerprint stays stable.
- Nous/Hermes: qwen3.8-max / qwen3.8-omni-flash added to the provider list so
  `nous:qwen3.8-max` routes qwen through the Hermes portal (model name passes
  through `hermes chat -m <model> --provider nous`).
- Black-box `run` now gets a broad DEFAULT objective when none is set: a
  comprehensive WEB assessment grounded in OWASP Top 10 / ASVS / WSTG / CWE that
  traverses every applicable web vuln class then goes deep — web-only (this path
  loads only web vuln agents; mobile/binary are separate modes), so it never
  drifts into mobile/exe.

423 tests passing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-04 01:06:28 -03:00
..