mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-05 23:47:19 +02:00
Hard scope stays the safety boundary (you must say what you're allowed to test), but setting it is now frictionless for a normal client pentest where authorization comes from a signed SOW/contract — no bug-bounty program or capability token. - /authorize <host|*.dom|cidr|url> ... (aliases /grant, /inscope-set): set the entire authorized scope in one line (multiple entries), pins it so /target won't re-derive, and seeds the target so /run works immediately. The operator asserts written authorization for the listed assets; guardrails (rate, accounts, destructive) remain tunable via /guardrail. - examples/scopes/engagement.example.yaml — neutral direct-engagement template (no program framing): fill hard scope from the SOW, guardrails documented as yours to tune (e.g. allow destructive in a staging env, raise rate for a lab). The frictionless path already worked (/target x -> authorized against x); this makes the multi-asset direct engagement a single clear command. 422 tests. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>