Files
NeuroSploit/neurosploit-rs/crates/harness/src/lib.rs
T
CyberSecurityUPandClaude Opus 5 c3de51d508 feat(typesafe): System One calibrated adjudication (RLCD tier)
Integrates TypeSafe's System One model (Jev) as an optional, calibrated
adjudicator — the RLCD (Reinforcement Learning for Calibrated Decisions) tier:
typed judgments with probabilities where the harness needs a number, not prose.

- typesafe.rs: HTTP client for POST /v1/systemone (Bearer TYPESAFE_API_KEY,
  model jev-latest), with Choice/Noul/Score primitives, retry on 429/529, and
  parsed answers exposing the probability distribution + confidence.
  adjudicate() asks a Choice {confirmed/needs-review/rejected} plus an
  impact-demonstrated Noul over a finding; calibrated_confidence() folds
  demonstrated impact into the number, wants_review() gates a split distribution.
- pipeline: an optional pass (runs when TYPESAFE_API_KEY is set, off with
  NEUROSPLOIT_TYPESAFE=off) adjudicates each finding over its EVIDENCE — never
  its narrative — refining confidence and the needs-review boundary. Additive:
  a deterministic validator still rules; TypeSafe can only lower confidence or
  flag for review, never resurrect a rejected claim. Audited per finding.
- env.example + README document it; the web console inherits the key via env.

Where the model stack maps in NeuroSploit: LM/BERT ≈ the deterministic
validators (no model), RLHF chat ≈ the exploit/recon agents, RLVR reasoning ≈
the DeepReasoning budget tier, RLCD ≈ this calibrated adjudication.

373 tests (+5).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-19 17:56:34 -03:00

78 lines
2.5 KiB
Rust

//! NeuroSploit v3.6.5 harness — a robust multi-model runtime for the
//! markdown-driven autonomous pentest engine.
//!
//! The harness loads the `agents_md/` library, drives a *pool* of LLM models
//! (any OpenAI-compatible provider) with concurrency + provider failover, runs
//! the specialist agents in parallel, then validates every candidate finding by
//! **N-model voting** before scoring and reporting.
pub mod agents;
pub mod assurance;
pub mod attack_graph;
pub mod audit;
pub mod belief;
pub mod browser;
pub mod budget;
pub mod capability;
pub mod chain;
pub mod claims;
pub mod compliance;
pub mod creds;
pub mod cvss;
pub mod grounding;
pub mod hygiene;
pub mod inbox;
pub mod integrations;
pub mod integrity;
pub mod internal;
pub mod knowledge_graph;
pub mod memory;
pub mod policy;
pub mod poc;
pub mod pomdp;
pub mod proxy;
pub mod prosecutor;
pub mod provenance;
pub mod models;
pub mod netguard;
pub mod oob;
pub mod pipeline;
pub mod pool;
pub mod probe;
pub mod replay;
pub mod report;
pub mod rl;
pub mod sandbox;
pub mod scope;
pub mod taint;
pub mod transport;
pub mod types;
pub mod typesafe;
pub mod uncertainty;
pub mod validation;
pub mod waf;
pub use agents::{Agent, Library};
pub use models::{
cli_binary_for, ensure_playwright_mcp, installed_cli_backends, mcp_supported, provider_for,
providers, write_mcp_config, ChatClient, ModelRef, Provider,
};
pub use pipeline::{run_greybox, run_host, run_whitebox, RunOutput};
pub use pipeline::run;
pub use knowledge_graph::{EdgeKind, KnowledgeGraph, NodeKind};
pub use memory::{Memory, Query as MemoryQuery, Tier as MemoryTier};
pub use pool::{ModelPool, Task};
pub use audit::{AuditLog, AuditRecord, KillReason, KillSwitch};
pub use capability::{Capability, TokenError};
pub use browser::{BrowserProbe, BrowserResult};
pub use budget::{Budget, Effort, Governor, Mode as BudgetMode, Order as BudgetOrder, Phase as BudgetPhase};
pub use chain::{AttackPath, Capability as ChainCapability, Link};
pub use claims::{Claim, ClaimSet, ClaimStatus, Decision, EvidenceLedger};
pub use policy::{Act, ActionKind, BlastRadius, EngagementPolicy, Environment, Protocol, Risk, RiskDecision, SafetyPolicy};
pub use prosecutor::{ProsecutorVerdict, PROSECUTOR_SYS};
pub use replay::{ReplayEngine, ReqSpec};
pub use scope::{Action as ScopeAction, Decision as ScopeDecision, ScopePolicy};
pub use types::{Finding, RunConfig};
pub use uncertainty::{assess as assess_uncertainty, Assessment, Gap, Rounds};
pub use validation::{judge as judge_finding, CweValidator, Evidence, Verdict};