mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-29 20:41:51 +02:00
Honesty audit found four modules written but not on the runtime path. Two mattered and are now wired; two are noted. cvss.rs — was NOT called; finding.cvss came from the old attack_graph ladder. Now attack_graph::cvss_graded() bridges the class shape + demonstrated rung into crate::cvss::grade (the FIRST-verbatim v3.1 equation), and enrich() sets finding.cvss from the demonstrated vector, recording the potential ceiling in the impact text. The class ladder remains only as a fallback for findings with no evidence to grade. waf.rs — the deterministic classifier was NOT run on any real exchange (only WAF_OPS prompt text reached the agent). Now poc.rs classifies each re-run: a PoC answered by a WAF/CDN is Unverifiable, not "gone" — closing a false-demotion where an edge block looked like a fix. TypeSafe (System One) extended per the build-with docs: - CVSS via System One: when impact_demonstrated < 0.5, the finding's CVSS is re-graded with impact receipts stripped — the calibrated judgment, not just the rung, decides the demonstrated number. - Agent selection: typesafe_prune_agents() asks one batched request (the fan-out pattern), a Noul per chosen agent, and drops only those it calibrates as clearly irrelevant (p < 0.25), never prunes to empty. Additive over the LLM selection; skipped without a key. Still shelf-ware, flagged honestly (not wired): inbox.rs (mail.tm/SMS happens via agent prompt instructions, the Rust client is unused) and pomdp.rs (redundant — belief.rs is the one on the path). 374 tests. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>