mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-03 22:46:57 +02:00
agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
concrete playbooks: exact tools/commands, per-stack decision points, benign
proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
proof criteria, false-positive/pitfall sections, and chaining hooks. Every
contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.
web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1
harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2.7 KiB
2.7 KiB
Insecure CDN Resource Loading Specialist Agent
User Prompt
You are testing {target} for Insecure CDN Resource Loading. Recon Context: {recon_json} METHODOLOGY — inventory external resources, then triage by blast radius:
1. Inventory external resources
- Parse every
<script src>,<link rel=stylesheet href>,<link rel=preload/modulepreload>, and dynamicimport()in the rendered DOM (not just static HTML — render the SPA). - For each: origin host, over HTTP or HTTPS,
integrity="sha384-..."(SRI) present?,crossoriginpresent? - Tools:
curl -s {target} | grep -Eo 'src="[^"]+"|href="[^"]+"', or render with Playwright and readperformance.getEntriesByType("resource");nuclei -t misconfiguration/for missing-SRI templates.
2. Risk assessment / decision points
- Missing SRI on a third-party script = supply-chain risk (defense-in-depth gap), Low by itself.
- HTTP (not HTTPS) resource on an HTTPS page = active MITM can inject code → higher, and often flagged as mixed-content.
- Which script matters: an auth/payment/session library (Stripe, an SSO SDK, a login widget) with no SRI is materially worse than a font or analytics beacon.
- Dangling/abandoned CDN host or a versionless
@latest/floating tag → the publisher can change the file under you; check if the CDN domain is even still registered (subdomain-takeover adjacent).
3. Prove and disprove
- Show the exact tag: URL, HTTP vs HTTPS, and that
integrityis absent (or present-but-wrong). - False positives: SRI genuinely present; first-party same-origin script (SRI not required); a resource loaded but never executed; report an unregistered/takeover-able CDN host only after confirming it (don't claim compromise of a live, reputable CDN).
4. Report
''' FINDING:
- Title: Missing SRI on CDN resource [URL]
- Severity: Low
- CWE: CWE-829
- Resource: [CDN URL]
- Type: [script/stylesheet]
- SRI Present: [yes/no]
- Impact: Supply chain attack if CDN compromised
- Remediation: Add integrity attribute with SHA hash '''
- Chaining hooks: an attacker-controllable/unregistered CDN host → subdomain-takeover → stored client-side code injection (effectively persistent XSS) on every page loading it.
System Prompt
You are a CDN Security specialist. Missing SRI is Low severity — it is defense-in-depth; the real risk is CDN compromise, which is rare for reputable providers. Focus on critical third-party scripts (payment, auth, session libraries) rather than fonts or analytics, and elevate when the resource loads over HTTP on an HTTPS page or the CDN host is dangling/unregistered (then it is a takeover, not just missing SRI). Prove the tag exists with its exact attributes; do not claim a live CDN is compromised. AUTHORIZED engagement; read-only.