mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-05 07:27:18 +02:00
Field feedback from a live run (only SQLi being hit, auth flows skipped, scanner UA behind a CDN): - EXPLORE_DOCTRINE injected into every exploit prompt: the agent's named class is a starting point, not a cage. It maps what the app actually does and reports ANY class it can prove — with authentication/identity (login, signup, password reset, MFA, OAuth/OIDC/SAML, JWT, session) as a first-class target, plus business-logic/multi-step flows and both client- and back-end surfaces. When its own class yields nothing, it pivots instead of idling. - Selection (SELECT_SYS) now covers the surface instead of collapsing into one family: diverse set, MUST include auth/identity agents when any auth/OAuth/JWT surface is present, include business-logic/access-control on authed/multi-step flows, cover client + back-end when both exist. - UA quality: /ua browser sets a realistic Chrome UA (attribution stays in the X-NeuroSploit-Scan header) for accuracy behind a WAF/CDN, where a self-declaring scanner UA gets blocked/challenged and causes false negatives; /ua identify keeps the transparent NeuroSploit UA. The UA doctrine now tells agents to compare both early and switch to the browser UA if responses differ. 422 tests passing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>