Skip to main content

RunConfig

Struct RunConfig 

Source
pub struct RunConfig {
Show 20 fields pub replay_stable_check: bool, pub allow_state_changing_live_probes: bool, pub browser_checks_enabled: bool, pub exploit_mode_enabled: bool, pub exploit_dry_run: bool, pub business_logic_templates_enabled: bool, pub research_mode_enabled: bool, pub unsafe_attack_agent_enabled: bool, pub business_logic_template_ids: Vec<String>, pub exploit_request_cap: Option<u32>, pub exploit_requests_per_second: Option<u32>, pub exploit_reset_after_state_changing: bool, pub enable_zap_baseline: bool, pub enable_nuclei: bool, pub enable_trivy: bool, pub enable_osv_scanner: bool, pub enable_secret_scanning: bool, pub enable_katana: bool, pub enable_httpx: bool, pub enable_aggressive_sqlmap: bool,
}
Expand description

[run] section: verifier knobs.

Fields§

§replay_stable_check: bool

When true, the deterministic payload runner re-executes each (vuln, benign) pair a second time and stamps replay_stable on the resulting VerifyResult. Adds ~2× cost per verify; default is false so the verifier stays fast on the happy path.

§allow_state_changing_live_probes: bool

Allow live verification plans to send methods that are likely to mutate target state (POST, PUT, PATCH, DELETE). Defaults to false so Nyx Agent only runs safe probes unless the operator explicitly opts in for their local app.

§browser_checks_enabled: bool

Opt in to browser-driven checks when a local Playwright runtime is available. When false, browser plans are recorded as skipped with an explicit reason.

§exploit_mode_enabled: bool

Master opt-in for exploit mode. Defaults to false; when false, live verification stays non-destructive even if an older config sets allow_state_changing_live_probes = true.

§exploit_dry_run: bool

Evaluate guarded live probes and write audit records without sending HTTP/browser traffic. Static analysis and source-only scanners still run normally.

§business_logic_templates_enabled: bool

Generate first-class business-logic pentest candidates from the route/auth model. The generated plans still pass through the normal live-verifier safety gates.

§research_mode_enabled: bool

Enable deeper authorized product-logic research. This adds invariant-focused candidate hypotheses and gives AI planning / exploration a broader product-logic brief. It does not relax live execution safety gates.

§unsafe_attack_agent_enabled: bool

Enable the pre-MVP unsafe local attack-agent phase. Once this final phase is invoked it does not route actions through the guarded live-verifier policy; it relies on the configured local development environment and CLI-backed sandbox boundary.

§business_logic_template_ids: Vec<String>

Optional allowlist of business-logic template ids. Empty means every registered template is considered.

§exploit_request_cap: Option<u32>

Per-candidate cap on guarded live HTTP/browser actions. None falls back to RunConfig::DEFAULT_EXPLOIT_REQUEST_CAP; a configured 0 is floored to 1.

§exploit_requests_per_second: Option<u32>

Per-candidate rate limit for guarded live requests/actions. None falls back to RunConfig::DEFAULT_EXPLOIT_REQUESTS_PER_SECOND; 0 floors to 1.

§exploit_reset_after_state_changing: bool

After an allowed state-changing probe, ask the environment orchestration layer to reset/rollback when it supports that operation. Defaults true so opt-in exploit runs clean up after themselves when docker-compose orchestration is available.

§enable_zap_baseline: bool

Optional passive ZAP baseline orchestration. Enabled by default, but the binary is only used when present on PATH; findings become candidates.

§enable_nuclei: bool

Optional Nuclei orchestration. Enabled by default, but the binary is only used when present on PATH; findings become candidates.

§enable_trivy: bool

Optional Trivy repository/filesystem scan. Enabled by default, but the binary is only used when present on PATH; findings become source-context candidates for AI exploration.

§enable_osv_scanner: bool

Optional OSV-Scanner dependency scan. Enabled by default, but the binary is only used when present on PATH; findings become source-context candidates for AI exploration.

§enable_secret_scanning: bool

Optional secret scanning. Enabled by default; Nyx Agent prefers gitleaks when present and falls back to detect-secrets.

§enable_katana: bool

Optional Katana crawler orchestration. Enabled by default, but the binary is only used when present on PATH; sensitive routes become live-test candidates.

§enable_httpx: bool

Optional ProjectDiscovery httpx probe orchestration. Enabled by default, but the binary is only used when present on PATH; interesting live metadata becomes candidates.

§enable_aggressive_sqlmap: bool

Aggressive external tooling is off unless this explicit gate is true. Nyx Agent does not run sqlmap by default.

Implementations§

Source§

impl RunConfig

Source

pub const DEFAULT_EXPLOIT_REQUEST_CAP: u32 = 10

Default request/action cap for one candidate live-verification attempt. This keeps malformed or model-generated workflows from fanning out indefinitely.

Source

pub const DEFAULT_EXPLOIT_REQUESTS_PER_SECOND: u32 = 5

Default per-candidate live request/action rate. Optional scanners have their own CLI-level throttles; this cap covers the built-in verifier.

Source

pub fn exploit_request_cap_resolved(&self) -> u32

Source

pub fn exploit_requests_per_second_resolved(&self) -> u32

Source

pub fn state_changing_live_probes_allowed(&self) -> bool

Trait Implementations§

Source§

impl Clone for RunConfig

Source§

fn clone(&self) -> RunConfig

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for RunConfig

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for RunConfig

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for RunConfig

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl PartialEq for RunConfig

Source§

fn eq(&self, other: &RunConfig) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl Serialize for RunConfig

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl Eq for RunConfig

Source§

impl StructuralPartialEq for RunConfig

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> Downcast for T
where T: Any,

Source§

fn into_any(self: Box<T>) -> Box<dyn Any>

Converts Box<dyn Trait> (where Trait: Downcast) to Box<dyn Any>, which can then be downcast into Box<dyn ConcreteType> where ConcreteType implements Trait.
Source§

fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>

Converts Rc<Trait> (where Trait: Downcast) to Rc<Any>, which can then be further downcast into Rc<ConcreteType> where ConcreteType implements Trait.
Source§

fn as_any(&self) -> &(dyn Any + 'static)

Converts &Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot generate &Any’s vtable from &Trait’s.
Source§

fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)

Converts &mut Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot generate &mut Any’s vtable from &mut Trait’s.
Source§

impl<T> DowncastSend for T
where T: Any + Send,

Source§

fn into_any_send(self: Box<T>) -> Box<dyn Any + Send>

Converts Box<Trait> (where Trait: DowncastSend) to Box<dyn Any + Send>, which can then be downcast into Box<ConcreteType> where ConcreteType implements Trait.
Source§

impl<T> DowncastSync for T
where T: Any + Send + Sync,

Source§

fn into_any_sync(self: Box<T>) -> Box<dyn Any + Sync + Send>

Converts Box<Trait> (where Trait: DowncastSync) to Box<dyn Any + Send + Sync>, which can then be downcast into Box<ConcreteType> where ConcreteType implements Trait.
Source§

fn into_any_arc(self: Arc<T>) -> Arc<dyn Any + Sync + Send>

Converts Arc<Trait> (where Trait: DowncastSync) to Arc<Any>, which can then be downcast into Arc<ConcreteType> where ConcreteType implements Trait.
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> NoneValue for T
where T: Default,

Source§

type NoneType = T

Source§

fn null_value() -> T

The none-equivalent value.
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> Serialize for T
where T: Serialize + ?Sized,

Source§

fn erased_serialize(&self, serializer: &mut dyn Serializer) -> Result<(), Error>

Source§

fn do_erased_serialize( &self, serializer: &mut dyn Serializer, ) -> Result<(), ErrorImpl>

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> Fruit for T
where T: Send + Downcast,