mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-03 22:46:57 +02:00
The runs/evidence and pocs folders were always empty on the API-key path: there the model only returns findings JSON and never executes a tool to write files, so nothing populated them (they were only ever written by the subscription agentic CLIs). The harness already holds the structured evidence (evidence_data: baseline/attack/identity exchanges, marker) and the payload/endpoint. synthesize_pocs_and_evidence() now writes, per finding and without overwriting anything an agent already produced: - evidence/<slug>.md — the request/response proof (baseline/attack/identity pairs, marker, callback/browser flags, notes), or the prose receipt as fallback - pocs/<slug>.md — a runnable curl repro from the recorded request(s), incl. the cross-identity pair for BOLA/IDOR; falls back to endpoint+payload and cites the PoC path back into the finding's evidence. Runs in the main pipeline after evidence collection; idempotent. 421 tests passing. Closes #44 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>