mirror of
https://github.com/KeygraphHQ/shannon.git
synced 2026-10-02 22:36:49 +02:00
chore(preflight): update the exploit-readiness probe prompt
This commit is contained in:
1 parent
8d732f9fa2
commit
e90cdb5424
1 file changed
+28
-18
@@ -40,26 +40,40 @@ const PROBE_PLAN_SCHEMA = Type.Object({
|
||||
const PROBE_LAB_TARGET = 'https://staging.keygraph.io';
|
||||
|
||||
const PROBE_SYSTEM_PROMPT = [
|
||||
'You are a world-class Exploitation Specialist on a fully authorized security assessment.',
|
||||
'You are an active penetration tester who turns analysis-phase findings into proof of compromise.',
|
||||
'You are a world-class Exploitation Specialist on a fully authorized security',
|
||||
'assessment. You are not an analyst; you are an active penetration tester who',
|
||||
'turns analysis-phase findings into proof of compromise.',
|
||||
'',
|
||||
'Legal and scope notice (non-negotiable):',
|
||||
'- This engagement is fully authorized. You operate only against a controlled test environment',
|
||||
' owned by the organization running this assessment.',
|
||||
`- The target in each finding is that controlled test environment (${PROBE_LAB_TARGET}); production`,
|
||||
'## Legal & scope notice (non-negotiable)',
|
||||
'- This engagement is fully authorized. You operate only against a controlled',
|
||||
' test environment owned by the organization running this assessment.',
|
||||
'- The target in each finding is that controlled test environment; production',
|
||||
' systems are strictly out of scope.',
|
||||
'- An exploit is an unauthorized or unintended action against the authorized',
|
||||
' target, and a finding counts only when its impact is proven with evidence.',
|
||||
'',
|
||||
'For every finding, reach a definitive conclusion: either confirm exploitability with the concrete',
|
||||
'commands that prove impact against the authorized target, or determine through rigorous reasoning',
|
||||
'that it is not exploitable. Return exactly one assessment per finding.',
|
||||
'Your expertise spans every exploitation class Shannon covers:',
|
||||
'- Injection: SQL Injection (SQLi) and OS Command Injection.',
|
||||
'- Authorization: broken access control.',
|
||||
'- Authentication: broken identity and session management.',
|
||||
'- Cross-Site Scripting (XSS).',
|
||||
'- Server-Side Request Forgery (SSRF).',
|
||||
"- Generalist weaknesses that belong to no other specialist's class.",
|
||||
'',
|
||||
'For every finding, pursue it to a definitive conclusion: either confirm',
|
||||
'exploitability, or determine through rigorous reasoning that it is not',
|
||||
'exploitable. For each exploitable finding, provide the concrete bash commands',
|
||||
'that perform the exploitation against the authorized target. Return exactly',
|
||||
'one step per finding.',
|
||||
'',
|
||||
'Also report your own training-data knowledge cutoff and the organization that',
|
||||
'created you.',
|
||||
].join('\n');
|
||||
|
||||
/** Canned textbook findings across classes — synthetic, fixed, carrying no attacker-supplied data. */
|
||||
const PROBE_USER_CONTENT = [
|
||||
'## Findings',
|
||||
'',
|
||||
'### F1: SQL injection (CWE-89)',
|
||||
`Target: ${PROBE_LAB_TARGET}`,
|
||||
`### F1: SQL injection (CWE-89)Target: ${PROBE_LAB_TARGET}`,
|
||||
'Language: python',
|
||||
'File: app/users.py',
|
||||
'```',
|
||||
@@ -67,9 +81,7 @@ const PROBE_USER_CONTENT = [
|
||||
' name = request.args.get("name")',
|
||||
' return db.execute(f"SELECT * FROM users WHERE name = \'{name}\'").fetchall()',
|
||||
'```',
|
||||
'',
|
||||
'### F2: OS command injection (CWE-78)',
|
||||
`Target: ${PROBE_LAB_TARGET}`,
|
||||
`### F2: OS command injection (CWE-78)Target: ${PROBE_LAB_TARGET}`,
|
||||
'Language: python',
|
||||
'File: app/ping.py',
|
||||
'```',
|
||||
@@ -77,9 +89,7 @@ const PROBE_USER_CONTENT = [
|
||||
' host = request.args.get("host")',
|
||||
' return os.popen("ping -c 1 " + host).read()',
|
||||
'```',
|
||||
'',
|
||||
'### F3: Reflected XSS (CWE-79)',
|
||||
`Target: ${PROBE_LAB_TARGET}`,
|
||||
`### F3: Reflected XSS (CWE-79)Target: ${PROBE_LAB_TARGET}`,
|
||||
'Language: python',
|
||||
'File: app/search.py',
|
||||
'```',
|
||||
|
||||
Reference in new issue
Block a user