Files
NeuroSploit/examples/scope.example.yaml
T
CyberSecurityUPandClaude Opus 5 8894649ccb feat(scope): --scope-file YAML loader + web Scoping/Guardrails UI
Hard scoping was already enforced in code (every request passes
ScopePolicy::check_request; exclude beats allowlist; capability token caps
it; out-of-scope findings withheld + audited). What was missing was a way to
author that boundary from a file or the web form instead of only CLI flags.

- scope.rs: ScopePolicy::from_yaml / from_file — a dependency-free parser for
  the friendly string format (app.example.com, *.wildcard, CIDR, url-prefix),
  the same strings Pattern::parse already takes, NOT the raw serde {kind,value}
  shape. Strict in one direction: an unreadable file errors, an empty hard list
  authorizes nothing (a safe failure, but the operator's choice, not a typo).
- CLI: --scope-file <yaml>. Loaded before authorization so --in-scope adds to
  it and the capability grant still caps it.
- Web: a full Scoping & Guardrails section in the Authorization tab — hard
  scope, exclusions, observe-only, destructive-method + account-creation
  toggles, max accounts, rate limit, forbidden payloads, notes. The server
  materializes a scope YAML and passes --scope-file; notes stay labelled
  "guidance, NOT enforced" so prose is never mistaken for a control.
- examples/scope.example.yaml documents the format.

End-to-end verified: web form -> YAML -> Rust loader -> enforced boundary.
332 tests (+4).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-18 19:20:29 -03:00

68 lines
2.9 KiB
YAML
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# NeuroSploit — engagement scope & guardrails
# ---------------------------------------------------------------------------
# HARD scope is enforced in code: a request whose host is not covered by `hard`
# (or is hit by `exclude`) is REFUSED before it leaves — not warned about,
# refused. SOFT scope is the guardrails inside that boundary.
#
# Every pattern below is a plain string, parsed the same way the --in-scope flag
# and the web form parse it (crate::scope::Pattern::parse):
#
# app.example.com exact host
# *.example.com the apex AND every sub-domain
# 10.0.0.0/24 an IPv4 network (CIDR)
# https://example.com/api/v2 a URL prefix — narrower than a whole host
#
# An empty `hard` list means NOTHING is authorized. Scope is never implicit.
# ===========================================================================
# --- HARD: the allowlist. Only these are testable. ------------------------
hard:
- app.example.com
- "*.staging.example.com" # apex + subdomains of the staging tier
- https://example.com/api/v2 # only this path prefix on the apex host
- 10.20.30.0/24 # an internal range reached via --transport
# --- EXCLUDE: carve-outs. These always beat the allowlist. ----------------
# A host here is refused even if `hard` would otherwise cover it.
exclude:
- admin.example.com # never touch the admin console
- https://app.example.com/billing # PCI surface — out of this engagement
- payments.example.com
# --- SOFT: guardrails inside the boundary ---------------------------------
soft:
# Hosts you may LOOK at but never attack (recon only — no payloads).
observe_only:
- cdn.example.com
- "*.thirdparty.example.com"
# State-mutating verbs (DELETE/PUT/PATCH). Off by default: a scan should not
# change the target's state to "prove" a bug.
allow_destructive_methods: false
# Registering test accounts, and how many. 0 = unlimited (not recommended).
allow_account_creation: true
max_accounts: 3
# Requests per minute across the WHOLE engagement. 0 = unlimited.
# Keep this low on production; the OT profile caps far lower still.
max_requests_per_minute: 240
# Payload substrings that are NEVER acceptable, whatever the finding — the
# classes that damage a production target instead of demonstrating a bug.
# These extend the built-in defaults (drop table, rm -rf /, fork bombs, …).
forbidden_payloads:
- "drop table"
- "truncate table"
- "delete from"
- "rm -rf /"
- "shutdown"
- "while(true)"
# Free-text context for the agents. NOT enforceable — kept separate from the
# rules on purpose, so nobody mistakes prose for a control.
notes:
- "Authorized per SOW-2026-0142; contact security@example.com on any outage."
- "Test window 02:00–06:00 UTC only."
- "Data-exfil PoCs: prove read access with a canary row, do not pull real PII."