Files
NeuroSploit/neurosploit-rs
CyberSecurityUPandClaude Opus 5 d8ebe05507 feat(harness): replay engine — the harness re-runs the interaction itself
Validators decide from recorded artifacts, and the weakest link was who
recorded them: "the payload returned a 500" is still an agent's account of what
happened. Replay produces the part that matters most in practice —
reproducibility — by sending the request again through the harness's own
client, with the scope guard in front of it.

Three properties it is built around:
- every request passes ScopePolicy::check_request before a socket is opened, so
  replay cannot be the thing that wanders off-scope while verifying a finding;
- it never mutates: a finding proven with DELETE is not re-proven by deleting
  the record again, so non-idempotent verbs are refused and repeats of them are
  refused outright;
- bodies are truncated at 96KB and SAY they were truncated — a silently clipped
  body makes a length differential meaningless.

enrich() fills in repeats and re-measures a recorded baseline (comparing a
fresh attack against an hour-old baseline attributes ordinary drift to the
payload). It deliberately does NOT synthesize a baseline from an attack
request: removing "the payload" from an arbitrary URL is guesswork, and a
guessed baseline would silently decide the verdict.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-13 15:26:50 -03:00
..