mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-04 23:16:50 +02:00
Three improvements prompted by a real bug-bounty run: 1. /class idor,sqli,xss,ssrf — focus a run on specific vulnerability CLASSES. Expands each class to the matching library agents (by name/title/CWE) and pins them, so /run tests exactly those classes and skips recon-based selection. Friendlier than naming each agent via /only. Known aliases cover idor/bola, sqli, xss, ssrf, csrf, ssti, xxe, rce, lfi, auth/jwt, graphql, race, upload, cors, prototype-pollution, smuggling, and more. 2. /authorization <url> (aliases /authz, /program) — declare the engagement's authorization (e.g. https://hackerone.com/<program>). Recorded and added to the rules-of-engagement context so the run is framed as the authorized test it is, which reduces false model refusals on in-scope bounty targets. It does NOT widen scope — the grant still comes from /target, /scope-file or a capability — and the RoE context tells agents to keep within the program's rules (no DoS/mass-account-creation/out-of-scope; report those as leads). 3. Model-refusal detection: when an agent DECLINES a technique (safety/RoE pushback, e.g. "can't run mass account creation at a production service"), the harness now says so plainly instead of hiding it as "0 parseable findings (malformed JSON)". The operator sees WHY an agent found nothing. 422 tests passing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>