mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-30 04:51:50 +02:00
- Container image scanning: new `container` mode + 4 skills (vuln, secret, misconfig, SBOM) driving trivy/grype/syft headless, read-only. Scans an OCI ref / tar / Dockerfile for vulnerable packages (CVE/fixed-in/KEV), exposed secrets in any layer, Dockerfile+runtime misconfig, and writes an SBOM in both SPDX and CycloneDX to the run's sbom/. Also exposed as an MCP tool (neurosploit_container). - Coverage report: every run writes coverage.md — which agents ran (tested surface), findings per agent, and the high-value classes NOT covered — so the reader sees the engagement's reach. Added to the assurance bundle. - Login-verification evidence: doctrine now requires capturing the login request/response + a Playwright screenshot and recording success/failure before authenticated testing. - HTTP traffic export: `neurosploit traffic <run>` turns the intercepted flows.jsonl into a traffic.http archive for external tools. Not ported: Asset Discovery (enterprise-only, skipped per request). 383 tests. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
94 lines
3.2 KiB
Rust
94 lines
3.2 KiB
Rust
use regex::Regex;
|
|
use serde::Serialize;
|
|
use std::path::Path;
|
|
use walkdir::WalkDir;
|
|
|
|
/// One markdown specialist/meta agent.
|
|
#[derive(Clone, Debug, Serialize)]
|
|
pub struct Agent {
|
|
pub name: String,
|
|
pub title: String,
|
|
pub cwe: String,
|
|
pub kind: String, // "vuln" | "meta"
|
|
#[serde(skip)]
|
|
pub system: String,
|
|
#[serde(skip)]
|
|
pub user: String,
|
|
}
|
|
|
|
/// The loaded `agents_md/` library.
|
|
#[derive(Default)]
|
|
pub struct Library {
|
|
pub vulns: Vec<Agent>,
|
|
pub meta: Vec<Agent>,
|
|
pub recon: Vec<Agent>,
|
|
pub code: Vec<Agent>,
|
|
pub infra: Vec<Agent>,
|
|
pub chains: Vec<Agent>,
|
|
/// AI/LLM/agent/MCP/skills security agents (OWASP LLM Top 10, MCP risks…).
|
|
pub ai: Vec<Agent>,
|
|
pub mobile: Vec<Agent>,
|
|
pub container: Vec<Agent>,
|
|
}
|
|
|
|
impl Library {
|
|
pub fn total(&self) -> usize {
|
|
self.vulns.len() + self.meta.len() + self.recon.len() + self.code.len()
|
|
+ self.infra.len() + self.chains.len() + self.ai.len() + self.mobile.len() + self.container.len()
|
|
}
|
|
}
|
|
|
|
/// Load `<base>/agents_md/{vulns,meta,recon,code,infra,chains,ai}/*.md`.
|
|
pub fn load(base: &Path) -> Library {
|
|
let root = base.join("agents_md");
|
|
Library {
|
|
vulns: load_dir(&root.join("vulns"), "vuln"),
|
|
meta: load_dir(&root.join("meta"), "meta"),
|
|
recon: load_dir(&root.join("recon"), "recon"),
|
|
code: load_dir(&root.join("code"), "code"),
|
|
infra: load_dir(&root.join("infra"), "infra"),
|
|
chains: load_dir(&root.join("chains"), "chain"),
|
|
ai: load_dir(&root.join("ai"), "ai"),
|
|
mobile: load_dir(&root.join("mobile"), "mobile"),
|
|
container: load_dir(&root.join("container"), "container"),
|
|
}
|
|
}
|
|
|
|
fn load_dir(dir: &Path, kind: &str) -> Vec<Agent> {
|
|
let title_re = Regex::new(r"(?m)^#\s+(.+?)\s*$").unwrap();
|
|
let cwe_re = Regex::new(r"CWE-\d+").unwrap();
|
|
let user_re = Regex::new(r"(?s)##\s*User Prompt\s*\n(.*?)(?:\n##\s|\z)").unwrap();
|
|
let sys_re = Regex::new(r"(?s)##\s*System Prompt\s*\n(.*?)(?:\n##\s|\z)").unwrap();
|
|
let mut out = Vec::new();
|
|
if !dir.is_dir() {
|
|
return out;
|
|
}
|
|
for entry in WalkDir::new(dir).max_depth(1).into_iter().flatten() {
|
|
let path = entry.path();
|
|
if path.extension().and_then(|e| e.to_str()) != Some("md") {
|
|
continue;
|
|
}
|
|
let text = std::fs::read_to_string(path).unwrap_or_default();
|
|
let name = path.file_stem().and_then(|s| s.to_str()).unwrap_or("").to_string();
|
|
let title = title_re
|
|
.captures(&text)
|
|
.and_then(|c| c.get(1))
|
|
.map(|m| m.as_str().trim().to_string())
|
|
.unwrap_or_else(|| name.clone());
|
|
let cwe = cwe_re.find(&text).map(|m| m.as_str().to_string()).unwrap_or_default();
|
|
let user = user_re
|
|
.captures(&text)
|
|
.and_then(|c| c.get(1))
|
|
.map(|m| m.as_str().trim().to_string())
|
|
.unwrap_or_default();
|
|
let system = sys_re
|
|
.captures(&text)
|
|
.and_then(|c| c.get(1))
|
|
.map(|m| m.as_str().trim().to_string())
|
|
.unwrap_or_default();
|
|
out.push(Agent { name, title, cwe, kind: kind.to_string(), system, user });
|
|
}
|
|
out.sort_by(|a, b| a.name.cmp(&b.name));
|
|
out
|
|
}
|