Files
NeuroSploit/neurosploit-rs
CyberSecurityUPandClaude Opus 4.8 999d9c2209 fix(pipeline): synthesize pocs/ and evidence/ from recorded evidence (#44)
The runs/evidence and pocs folders were always empty on the API-key path: there
the model only returns findings JSON and never executes a tool to write files,
so nothing populated them (they were only ever written by the subscription
agentic CLIs). The harness already holds the structured evidence (evidence_data:
baseline/attack/identity exchanges, marker) and the payload/endpoint.

synthesize_pocs_and_evidence() now writes, per finding and without overwriting
anything an agent already produced:
- evidence/<slug>.md  — the request/response proof (baseline/attack/identity
  pairs, marker, callback/browser flags, notes), or the prose receipt as fallback
- pocs/<slug>.md      — a runnable curl repro from the recorded request(s),
  incl. the cross-identity pair for BOLA/IDOR; falls back to endpoint+payload
and cites the PoC path back into the finding's evidence. Runs in the main
pipeline after evidence collection; idempotent. 421 tests passing.

Closes #44

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-10-03 01:08:57 -03:00
..