Files
NeuroSploit/neurosploit-rs/templates
CyberSecurityUPandClaude Opus 5 53a6a45448 feat(report): CVSS v3.1 with vectors, a PDF that survives long payloads, capped over-claims
Driven by the Arena Hockey engagement, where all 24 findings shipped with an
empty CVSS field and the PDF ran payloads off the page edge.

CVSS
- Derived deterministically from what the harness knows: the weakness class
  sets the impact shape, the PROVEN exploitability sets attack complexity, and
  the auth context sets privileges required. The vector is emitted with the
  score, because a score without its vector cannot be checked and an unchecked
  score is just a bigger adjective.
- The base equation is the v3.1 specification verbatim, including round-up and
  the scope-changed privileges table. Tests anchor it against known values
  (9.8 unauthenticated RCE, 10.0 with scope change, 6.1 reflected XSS, 0.0 for
  no impact).
- An unknown weakness stays conservative — guessing high impact from a class
  nobody mapped is how reports get inflated. An agent-supplied score is never
  overwritten.

PDF
- Steps are passed as an ARRAY and rendered as a real numbered list, one command
  per box. The previous template flattened them into a single `raw` block, which
  rendered five separate commands as one run-on paragraph.
- Finding blocks are breakable, so a long evidence dump flows to the next page
  instead of off the bottom of this one.
- `wrappable()` inserts zero-width breaks so encoded payloads wrap. The first
  attempt broke prose mid-word ("rota ted", "lockoutOnFailu re=false") by
  breaking every N characters regardless of context; it now works per token and
  leaves anything that fits on a line exactly as it was.
- rebuild() re-enriches before rendering, so a run that finished before a
  mapping existed picks it up instead of reprinting the gap forever.

Over-claimed findings are capped, not deleted
- The engagement rejected "no rate limiting on the password-reset flow" because
  the agent claimed inbox flooding and only proved 25 unthrottled requests. The
  claim was inflated; the measurement was real, and dropping it hid a genuine
  gap. A unanimously rejected finding that still carries a checkable receipt is
  now capped to Low and flagged for review, with the validator's reason
  attached — the reader gets the fact without the story built on it.
- The agent contract now says impact must be what was MEASURED, and warns that
  inflating it costs the whole finding.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-14 00:22:10 -03:00
..