mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-05 07:27:18 +02:00
Field feedback: real, reproducible findings (missing HSTS, insecure cookie flags, internal IP leaked in a header) were being down-rated/dropped by the adversarial opinion-vote. The user's rule: never discard something real; another person must be able to reproduce the same finding. Validation: - has_http_receipt(): a finding whose proof is a captured HTTP response (status line / security headers / Set-Cookie / a header the class is proven by) or a file:line citation is REPRODUCIBLE by definition. - validate(): a finding unanimously rejected by the vote but carrying such a receipt is NO LONGER dropped — it is kept as needs-review (capped to what the receipt alone proves), because "the response lacks HSTS" is a fact, not a story. grounded_receipt() now also recognizes an in-prose HTTP receipt. - reproducibility: a kept finding at a URL with no explicit repro steps gets a minimal pasteable `curl -i` so anyone can reproduce the exact finding. Also: - /pocs (aliases /poc /evidence /artifacts): list a run's synthesized/written PoC + evidence files with their paths (was: "unknown command /pocs"). - version bumped to 4.2.2 across CLI/clap/web; stale v4.2.1/v4.1.0 labels fixed. 423 tests passing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>