Files
NeuroSploit/neurosploit-rs
CyberSecurityUPandClaude Opus 5 1adc882f6d feat(decision): wire 3 high-value System One decisions (backend = TypeSafe or Laya)
The three fragile heuristics now get a calibrated second opinion when a decision
backend is configured. All go through TypeSafe::from_env(), so they work
identically with hosted TypeSafe or local Laya (--decision-backend), and the run
banner names the active backend. Deterministic behaviour is unchanged when no
backend is set or --typesafe off.

- typesafe.rs: three helpers — same_finding (Noul), response_origin (Choice) and
  is_prompt_injection (Noul).
- Dedup grey zone (pipeline finish): a fixed 0.4 Jaccard cannot settle
  near-duplicates; merge_grey_zone_dupes asks a calibrated Noul on every
  same-endpoint/CWE pair scoring in the 0.25..0.40 band and merges the ones it
  calls the same bug.
- WAF origin (poc.rs): header signatures are ambiguous; before dropping a PoC as
  edge-answered, the backend gets the deciding vote — only bail if it also judges
  p(application) < 0.5, so a real finding is not discarded on a false edge.
- Prompt-injection (pipeline probe): the keyword matcher over-flags legit pages
  that merely mention "ignore instructions"; a calibrated Noul confirms real
  manipulation before raising the neutralised-injection notice.

383 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-23 01:18:14 -03:00
..