mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-05 23:47:19 +02:00
- Wildcard target from a scope-file (target: "*.nasa.gov") was probed literally → "builder error" / target unreachable. It's now reduced to the apex (https://nasa.gov) for the seed, while the scope keeps *.nasa.gov so subdomain enumeration stays authorized. (The /target command already did this; the engagement-file meta path didn't.) - Provenance was a OnceLock ("first run wins"), so in the REPL every run after the first minted markers and the provenance line with the FIRST run's id (nasa run showing a rockstargames id). Now a RwLock that rebinds per run — each engagement gets its own id; the build fingerprint stays stable. - Nous/Hermes: qwen3.8-max / qwen3.8-omni-flash added to the provider list so `nous:qwen3.8-max` routes qwen through the Hermes portal (model name passes through `hermes chat -m <model> --provider nous`). - Black-box `run` now gets a broad DEFAULT objective when none is set: a comprehensive WEB assessment grounded in OWASP Top 10 / ASVS / WSTG / CWE that traverses every applicable web vuln class then goes deep — web-only (this path loads only web vuln agents; mobile/binary are separate modes), so it never drifts into mobile/exe. 423 tests passing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>