docs: deserialization skill switches (OOB/timing/scope/runtimes/exec/PHAR)
Document the seven project switches for the Insecure Deserialization skill, the
three confirmation channels they gate, and the regenerated settings + MCP pages.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
docs: serialized-object Jev ranking; the complete AI in Pipeline hook list
TypeSafe Jev gains its serialized-object ranking section and the five
Jev-only hooks everywhere the count appears. Serialized Object Detection
covers form fields, one candidate per format per value, the honest ceiling
of the in-memory corpus, and the Jev ranking. Screenshots regenerated: the AI
in Pipeline panel with every hook card, the Jev token card, and the
Serialized Object Scan card. MCP API reference and settings registry
regenerated.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs(mcp): 5,000 findings per mute or unmute call, no daily budget
MCP Server and the generated MCP API Reference follow the new limits: one
call names up to 5,000 findings, a token makes at most 200 mute or unmute
calls a minute, and the daily mute budget is gone.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs(jev): the four Jev-only hooks in shadow mode
- TypeSafe-Jev: page-type labels, FFuf base-path ranking, Hakrawler seed
order and tool health (what Jev is asked, the result, cache, on failure),
a Shadow mode section, the two-level switch, the data each sends to
TypeSafe, cost and limits, the preflight kinds, log tags and
troubleshooting; the refusal text and the preset rule corrected
- AI-in-the-Recon-Pipeline, Recon-Pipeline-Workflow, AI-Model-Providers,
Global-Settings and Home name the Jev-only hooks where they list Jev's
- screenshots retaken: the AI in Pipeline panel with the Jev-only cards,
and the TypeSafe AI (Jev) section with its new intro
- Project-Settings-Reference counts (726 stored, 659 settable);
Project-Settings-Registry and MCP-API-Reference regenerated
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs: TypeSafe AI (Jev) provider, the LLM | Jev engine on four recon AI hooks
- AI-in-the-Recon-Pipeline: engine choice, the four hooks and what each may do,
why the false-positive filter has no Jev option, the three-level model, how a
bad answer is contained, failure behaviour, and the third-party data note
- AI-Model-Providers: the TypeSafe AI (Jev) section (one token, pinned model,
not a chat model)
- Global-Settings: the Jev check spends a trace of credit
- generated: MCP API reference, settings registry and reference (4 new settable
fields, preflight aiHooks)
docs(settings): ffufSmartFuzzMaxBasePaths caps smart-fuzz base paths
Regenerated Project-Settings-Registry and MCP-API-Reference for the new
settable field (651 settable, 718 stored), and described the cap and the
random pick in the narrative Project-Settings-Reference FFuf section.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs(triage): hardening notes for reviews, verdicts, stops and Ask agent
get_finding_triage returns review text (fix lever included) only with
includeQuotes and separates host proof from finding proof; a proven finding
takes a raising review; evidence redacts credential headers and shows the
nuclei matcher and GVM port/solution type; an agent image older than the
webapp refuses MCP verdicts (agent_outdated); an agent's stop reaches every
open tab; Ask agent fences the node name as untrusted. MCP API reference
regenerated.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs: Multi mute, Models by feature and the three-layer Priority Board
Multi mute on Muted Nodes and the Red Zone, Models by feature in Global
Settings and on every feature page that asks for a model, the settings
that retire the per-project CypherFix model, and the Priority Board's
rules, review and decision layers with the MCP review and run tools.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs(mcp): schedule pause on rescope, live agent check, badge that follows
- update_project_scope: a batch that gains hosts pauses the project's
scheduled scans (pausedSchedules); resume them in the Scans tab
- an agent session counts as busy only while the agent confirms it
- the Preset applied badge follows a rename and is cleared by a delete;
badges from before presets dropped two switches show again
- regenerate MCP-API-Reference.md
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs(mcp): recon presets and project rescope over MCP
Document the preset tools (list, create, update, delete, apply) and
update_project_scope, their three permissions and profile ticks, the
settings-surface counts and compare-and-swap, the stale-form 409, the
agent-written preset badge and the presets no longer carrying the MCP
sandbox switch. Regenerate the MCP API reference and the settings
registry page from the committed code.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs(mcp): regenerate the API reference for the nodeId field
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
docs(mcp): disabled-server message, sandbox-off tool withdrawal; regenerate API reference
A disabled server now answers 404 with a message that names
MCP_SERVER_ENABLED, and MCP_KALI_EXEC_ENABLED=false withdraws
kali_toolbox, kali_exec, kali_output and kali_cancel from tools/list.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs: Mute Rules on the MCP surface, kali:exec defaults, regenerate MCP API reference
- MCP-Server: set_finding_verdict is refused on a muted finding; a Mute Rules
apply blocks start_recon and reads as agent_writing; kali:exec defaults.
- Mute-Rules: an MCP verdict cannot release a rule mute.
- MCP-API-Reference regenerated with `npm run docs:mcp`.
- Project-Settings-Registry refreshed.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
docs: Node Filters and Muted Nodes pages
Node-Filters covers denylist and allowlist rules, the live preview, applying
to the current graph, the scan-time sweep, the guards that keep a judged or
proven finding visible, and exemptions. Muted-Nodes covers the list of every
suppressed finding, who or which rule muted it, and batch unmute.
Priority-Board drops its muted section in favour of the new page, the
sidebar links both, and the MCP API reference is regenerated for the
muted-findings changes to list_muted.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs: split Rules of Engagement into limits and record
The engagement is two unrelated things, and the wiki described it as one.
Rules-of-Engagement.md is rewritten around the split: the LIMITS are ordinary
settings, reachable from the form and the API alike and enforced at scan start,
and the RECORD is the contract a person writes and no token can touch. The
"set once at creation, read-only afterwards" claim is gone; only the record is
creation-time.
Also updated:
- Recon-Presets: a preset never carries the engagement, at capture or at apply,
and the exclusion is a registry query rather than a name-prefix match
- MCP-Server: update_recon_settings reaches the limits in either direction, and
what keeps that safe is enforcement at scan start, not a write-time rule
- Creating-a-Project: tab 1 is the Engagement Record; the limits live elsewhere
and stay editable
- Origin-Discovery: the mechanism is unchanged, the field classification is not
- AI-Gauntlet: its RoE checkbox is a per-launch confirmation, distinct from the
project's engagement limits
- Project-Settings-Reference: an Engagement Limits section, and two checked
counts instead of one wrong one. "714 configurable parameters" overstated the
surface exactly as the "245+" it replaced understated it
- Project-Settings-Registry and MCP-API-Reference: regenerated
A test fails any page that still names tighten_engagement_roe, the tighten_only
disposition, or a roe* field as MCP-settable.
docs: generate the settings registry, and fix a count that was off by two thirds
Project-Settings-Reference.md opened by claiming "245+ configurable parameters"
against a model of 714. That is the failure mode of a hand-written exhaustive
reference: right on the day it is written, quietly wrong every day after, and
nobody notices because nobody counts.
The narrative page keeps its screenshots and its tour and now states the real
number, which a test checks against the registry. Beside it,
Project-Settings-Registry.md is generated from recon_settings/registry.yaml with
every parameter, its enforced bound, its default, whether an external agent may
write it, and what it means.
The rows that carry a warning carry it in the row: a rate whose zero means
unlimited, a value the engagement ceiling rewrites at scan start, a field fixed
at creation, and a column withheld from every read.
The MCP API reference picks up five new tools and the rewritten recon:settings
blurb, whose old wording broke in the direction that made the permission sound
safer than it was.
docs(mcp): agent onboarding, and kali:exec described as the shell it is
The API reference is regenerated from the live tools/list, so the kali:exec
permission row and the kali_exec tool now describe a shell rather than the
allowlist that no longer exists.
MCP-Server.md gains the Agent Profile table and the onboarding-pack section,
with screenshots for the profile picker, a profile change and the export.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
docs: the inbound MCP surface at thirty tools, and kali_exec
MCP-API-Reference is generated by `npm run docs:mcp` from the server's own
tools/list; a unit test compares it byte for byte, so it is never edited by
hand.
MCP-Server gains the kali_exec section: the four switches that gate it, the
per-tool flag allowlist and what it refuses, the 300s sandbox cap, and the
rate limits. Plus the Agent Profiles and onboarding screenshots.
docs(mcp): regenerate - build-not-deployment caveat, honest union types
docs(mcp): the verdict tool, the scanner status read, and triage:write
Tool table, permissions row, the write rate-limit row, and the permission count
(now nine). The "not exposed" paragraph now draws the distinction that matters:
an agent can record a VERDICT, which ranks a finding, and can never MUTE or
unmute one, which hides or reveals it.
MCP-API-Reference.md regenerated.
docs(mcp): seven more tools and the recon:queue permission
Tool table and heading, a permissions row, the rate-limit table (queue_recon
takes the per-project start window, not the write budget; run_graph_view and
the analytics views take the query one), and the permission count in the alt
text and in Global-Settings, now eight.
MCP-API-Reference.md regenerated from the live tools/list.
docs(mcp): eight new tools, the triage:read permission, regenerated reference
MCP-API-Reference.md is regenerated from the live tools/list, never hand-edited.
MCP-Server.md: the tool table and its heading, a permissions row, the
rate-limit table (its "Applies to" column enumerates tools per bucket, so every
row was wrong), the concurrency paragraph now that the findings path takes the
same ceiling, and the "not exposed" paragraph - the other scanners' findings
are readable while starting them is not.
Global-Settings.md and the MCP-Server alt text both said "five permissions",
which was already stale at six before this and is now seven.
docs: document the MCP Server surface, incl. kali_exec
Rename MCP-Access-Tokens to MCP-Server and cover the whole inbound
surface rather than just the token screen.
- MCP-Server: thirteen tools, the four switches guarding kali_exec, the
per-tool flag allowlist and what it refuses, rate limits and audit rows.
- MCP-API-Reference: generated by `npm run docs:mcp` from the server's own
tools/list. Never hand-edit; a unit test compares it byte for byte.
- Sidebar, Home and Global-Settings point at the new page name.