mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-29 12:31:43 +02:00
A WAF breaks inference in both directions and agents make both mistakes: a 403 from Cloudflare read as "tested, not vulnerable" (the expensive one — the app may be wide open and simply never reached), and a block page that echoes the payload read as reflection (the embarrassing one). classify() answers one question: did the application see this request? Proxy markers and enforcement markers are separate lists, because cf-ray is on every response Cloudflare proxies — treating that as a block would discard every finding on every CDN-fronted site, including the ordinary authorization 403s that are often the finding itself. Coverage::summary() says how many probes actually reached the application, so a clean result on a WAF-fronted target cannot be read as a clean app. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>