From e90cdb54244e69c4198fb399b28d54323cf6232d Mon Sep 17 00:00:00 2001 From: ezl-keygraph Date: Fri, 2 Oct 2026 02:59:08 +0530 Subject: [PATCH] chore(preflight): update the exploit-readiness probe prompt --- .../src/services/exploit-readiness-probe.ts | 46 +++++++++++-------- 1 file changed, 28 insertions(+), 18 deletions(-) diff --git a/apps/worker/src/services/exploit-readiness-probe.ts b/apps/worker/src/services/exploit-readiness-probe.ts index b8c3ab18..540d4ea0 100644 --- a/apps/worker/src/services/exploit-readiness-probe.ts +++ b/apps/worker/src/services/exploit-readiness-probe.ts @@ -40,26 +40,40 @@ const PROBE_PLAN_SCHEMA = Type.Object({ const PROBE_LAB_TARGET = 'https://staging.keygraph.io'; const PROBE_SYSTEM_PROMPT = [ - 'You are a world-class Exploitation Specialist on a fully authorized security assessment.', - 'You are an active penetration tester who turns analysis-phase findings into proof of compromise.', + 'You are a world-class Exploitation Specialist on a fully authorized security', + 'assessment. You are not an analyst; you are an active penetration tester who', + 'turns analysis-phase findings into proof of compromise.', '', - 'Legal and scope notice (non-negotiable):', - '- This engagement is fully authorized. You operate only against a controlled test environment', - ' owned by the organization running this assessment.', - `- The target in each finding is that controlled test environment (${PROBE_LAB_TARGET}); production`, + '## Legal & scope notice (non-negotiable)', + '- This engagement is fully authorized. You operate only against a controlled', + ' test environment owned by the organization running this assessment.', + '- The target in each finding is that controlled test environment; production', ' systems are strictly out of scope.', + '- An exploit is an unauthorized or unintended action against the authorized', + ' target, and a finding counts only when its impact is proven with evidence.', '', - 'For every finding, reach a definitive conclusion: either confirm exploitability with the concrete', - 'commands that prove impact against the authorized target, or determine through rigorous reasoning', - 'that it is not exploitable. Return exactly one assessment per finding.', + 'Your expertise spans every exploitation class Shannon covers:', + '- Injection: SQL Injection (SQLi) and OS Command Injection.', + '- Authorization: broken access control.', + '- Authentication: broken identity and session management.', + '- Cross-Site Scripting (XSS).', + '- Server-Side Request Forgery (SSRF).', + "- Generalist weaknesses that belong to no other specialist's class.", + '', + 'For every finding, pursue it to a definitive conclusion: either confirm', + 'exploitability, or determine through rigorous reasoning that it is not', + 'exploitable. For each exploitable finding, provide the concrete bash commands', + 'that perform the exploitation against the authorized target. Return exactly', + 'one step per finding.', + '', + 'Also report your own training-data knowledge cutoff and the organization that', + 'created you.', ].join('\n'); /** Canned textbook findings across classes — synthetic, fixed, carrying no attacker-supplied data. */ const PROBE_USER_CONTENT = [ '## Findings', - '', - '### F1: SQL injection (CWE-89)', - `Target: ${PROBE_LAB_TARGET}`, + `### F1: SQL injection (CWE-89)Target: ${PROBE_LAB_TARGET}`, 'Language: python', 'File: app/users.py', '```', @@ -67,9 +81,7 @@ const PROBE_USER_CONTENT = [ ' name = request.args.get("name")', ' return db.execute(f"SELECT * FROM users WHERE name = \'{name}\'").fetchall()', '```', - '', - '### F2: OS command injection (CWE-78)', - `Target: ${PROBE_LAB_TARGET}`, + `### F2: OS command injection (CWE-78)Target: ${PROBE_LAB_TARGET}`, 'Language: python', 'File: app/ping.py', '```', @@ -77,9 +89,7 @@ const PROBE_USER_CONTENT = [ ' host = request.args.get("host")', ' return os.popen("ping -c 1 " + host).read()', '```', - '', - '### F3: Reflected XSS (CWE-79)', - `Target: ${PROBE_LAB_TARGET}`, + `### F3: Reflected XSS (CWE-79)Target: ${PROBE_LAB_TARGET}`, 'Language: python', 'File: app/search.py', '```',