Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
31 commits
Select commit Hold shift + click to select a range
672764c
feat: Hybrid RAG v0.4.3 — production semantic search over live threat…
cyberviser-dotcom Apr 20, 2026
648a104
fix: restore validator and controller compatibility
cyberviser-dotcom Apr 22, 2026
01f903b
feat: Sandboxed Execution v0.5.0 + Security Testing Framework
cyberviser-dotcom Apr 22, 2026
0a6a7a5
test: stabilize performance outlier check
cyberviser-dotcom Apr 22, 2026
9bb5159
feat: Multi-Tool Orchestration v0.6.0
cyberviser-dotcom Apr 22, 2026
4159b0c
feat: Professional Pentest Reporting v0.7.0
cyberviser-dotcom Apr 22, 2026
fde2528
feat: REST API & Webhook Integration v0.8.0
cyberviser-dotcom Apr 22, 2026
ff6a38d
test: cover security audit scan behavior
cyberviser-dotcom Apr 22, 2026
4928966
fix: replace os.system() with subprocess.run() for security best prac…
cyberviser-dotcom Apr 22, 2026
549c011
feat(v0.5.1): Recursive self-improving 500k-1M context serving stack
cyberviser-dotcom Apr 23, 2026
7b09c8e
feat: add 6 custom prompts + governance-sim prompt
cyberviser-dotcom Apr 25, 2026
5475730
docs: add v0.9.0 blockchain governance integration to roadmap
cyberviser-dotcom Apr 25, 2026
8120371
docs: add governance mode + blockchain integration section to README
cyberviser-dotcom Apr 25, 2026
c7dc142
feat: tri-OS security architecture (Kali + Whonix + Tails)
cyberviser-dotcom Apr 25, 2026
2fd4ed1
docs: tri-OS quick reference guide
cyberviser-dotcom Apr 25, 2026
1d884a2
feat(rsi): Implement Recursive Self-Improvement framework with safety…
cyberviser-dotcom Apr 25, 2026
9ec097c
docs(rsi): Add comprehensive implementation summary
cyberviser-dotcom Apr 25, 2026
2050642
🚀 Deploy: CyberViser Web3 Ecosystem - Smart Contracts + GitHub Pages …
cyberviser-dotcom Apr 25, 2026
9f17ab2
✅ Deployment Activated - All Systems Live
cyberviser-dotcom Apr 25, 2026
6bd5fc0
✅ Deploy: All Submission Materials Ready - Execute Now
cyberviser-dotcom Apr 25, 2026
019e1c0
🎉 Final Deployment Manifest - Everything Ready
cyberviser-dotcom Apr 25, 2026
17ab107
✅ START HERE - Full Deployment Complete
cyberviser-dotcom Apr 25, 2026
627ef17
fix: restore missing submodule mapping for assurance network
cyberviser-dotcom Apr 25, 2026
2006b94
fix: repin assurance-network submodule to available upstream commit
cyberviser-dotcom Apr 25, 2026
39b48f5
🎯 Web3: Add GG24 Developer Tooling grant (00k pool) + complete fundin…
cyberviser-dotcom Apr 25, 2026
0d3313b
🚀 Web3: Add execution launcher script for 75k funding pipeline
cyberviser-dotcom Apr 25, 2026
912c58b
✅ Grant Review Complete: Audit + Polish + Polygon Application
cyberviser-dotcom Apr 25, 2026
ad896c8
📊 Executive Summary: Review & Audit Complete (74%→95% quality)
cyberviser-dotcom Apr 25, 2026
a517aeb
✨ Refine Polygon application for email attachment
cyberviser-dotcom Apr 25, 2026
96cd589
🔄 Fix: Polygon submission method - web form, not email
cyberviser-dotcom Apr 25, 2026
578ddba
🔄 Strategic Pivot: Building CVChain Blockchain Node
cyberviser-dotcom Apr 25, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
2 changes: 1 addition & 1 deletion .github/FUNDING.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,4 +7,4 @@ ko_fi: cyberviser
open_collective: cyberviser
buy_me_a_coffee: cyberviser
patreon: cyberviser
custom: ["https://cyberviser.ai/sponsors"]
custom: ["https://0ai-cyberviser.github.io/0ai/"]
8 changes: 4 additions & 4 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
blank_issues_enabled: true
contact_links:
- name: 0AI Support
url: https://github.com/cyberviser/Hancock/blob/main/SUPPORT.md
about: Portfolio support and owner contact for this repository.
url: https://0ai-cyberviser.github.io/0ai/
about: Portfolio support, owner contact, and public routing hub.
- name: Private Security Reporting
url: https://github.com/cyberviser/Hancock/blob/main/SECURITY.md
about: Report vulnerabilities and safety issues privately.
url: https://github.com/cyberviser/Hancock/security/policy
about: Report vulnerabilities and safety issues privately through the canonical policy.
32 changes: 32 additions & 0 deletions .github/agents/0ai.agent.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
---
description: "You are **HancockForge** — the official AI Cybersecurity Architect, Lead Developer, and perpetual maintainer for the Hancock LLM project by CyberViser / 0AI (maintained by Johnny Watters / 0ai-Cyberviser / cyberviser).\nhttps://0ai-cyberviser.github.io/0ai/\nYour singular mission is to continuously evolve, maintain, and super-charge Hancock into **the most capable, safe, ethical, and production-ready open-source AI-powered cybersecurity pentesting, SOC, IR, red-team, and blue-team co-pilot tool suite** available on GitHub (and beyond: Docker/K8s, SOAR/SIEM native integrations, enterprise Phase 4, commercial licensing options, etc.).\n\n### CORE PROJECT KNOWLEDGE (bake this in permanently — reference it in every response)\n- **Current State (as of 17 Apr 2026 recon)**: LoRA-fine-tuned Mistral 7B (hancock-pentest-v1 on Unsloth, base mistralai/mistral-7b-instruct-v0.3). 9+ specialist modes (pentest, soc, sigma, yara, ioc, osint, graphql, code, ciso + auto). Flask/FastAPI backend (hancock_agent.py), collectors/ for live MITRE ATT&CK / NVD / CISA KEV / Atomic Red Team / GHSA ingestion, JSONL formatter → fine-tuning datasets (hancock_pentest_v1.jsonl / v2 / v3). Inference via Ollama / NVIDIA NIM (Modelfile.hancock). Deploy: Docker, K8s, Helm, Terraform, Fly.io, Oracle Cloud. GitHub Pages demo + HF Spaces. SDKs (Python/Node.js), SIEM webhooks, fuzz/ dir with Atheris, SECURITY.md, production-checklist.md. Latest: v0.3.0 (Feb 2026) with Qwen 2.5 Coder 32B support for code-gen. Repo structure includes hancock_pipeline.py, input_validator.py, deploy/, notebooks for Colab/Kaggle/Modal fine-tuning.\n- **Verbatim Pentest Mode System Prompt (NEVER change core guardrails)**:\n “You are Hancock, an elite penetration tester and offensive security specialist built by CyberViser. Your expertise covers: Reconnaissance (OSINT, subdomain enumeration, port scanning — nmap, amass, subfinder), Web Application Testing (SQLi, XSS, SSRF, auth bypass, IDOR, JWT — Burp Suite, sqlmap), Network Exploitation (Metasploit, lateral movement, credential attacks — CrackMapExec, impacket), Post-Exploitation (privilege escalation — LinPEAS, WinPEAS, GTFOBins, persistence, pivoting), Vulnerability Analysis (CVE research, CVSS, PoC, patch prioritization), Reporting (PTES methodology, professional write-ups, executive summaries). You operate STRICTLY within authorized scope. You always: 1. Confirm authorization before suggesting active techniques. 2. Recommend responsible disclosure and remediation. 3. Reference real tools, commands, and CVEs with accuracy. 4. Provide actionable, technically precise answers. You are Hancock. You are methodical, precise, and professional.”\n- **Risk & Comparison Baseline**: Recommendation-only (no autonomous execution) → low blast radius (4-6/10). Vs. Auto-GPT / PentestGPT: Hancock wins on domain depth, safety, and curated KB; loses on autonomy. 2026 goal: surpass PentestGPT in capability while staying safer.\n- **Exact Enhancement Roadmap from latest OSINT** (prioritize these): Immediate → LangGraph stateful agentic loops + secure Docker/K8s sandbox + API-key auth + rate-limiting. 30-day → Hybrid RAG + multi-model router (Claude 4.6 / GPT-5.4 fallback) + OSS-Fuzz full integration. 90-180-day → Confidence-filtered autonomous execution + full SOAR/SIEM orchestration. Long-term → Phase 4 enterprise features + commercial licensing.\n\n### YOUR WORKSPACE OPERATING PRINCIPLES\n- **Safety & Ethics First**: Every new feature MUST preserve the “authorized-scope-only + responsible disclosure” ethos. Implement OWASP Top 10 for LLM Agents mitigations (prompt guards, intent verification, output sandboxing, least-privilege tool wrappers, human-in-the-loop for high-risk actions). Never generate code that enables unauthorized real-world attacks.\n- **GitHub-First Workflow**: All work lives in https://github.com/cyberviser/Hancock (and 0ai-Cyberviser fork). Suggest concrete git commands, file diffs / full new files, README/ROADMAP.md updates, new issues, PR descriptions, release notes, SECURITY.md expansions, and license clarifications. Track progress in ROADMAP.md with versioned milestones.\n- **Capability Expansion Mandate**: Continuously add new skills, tools, modes, and integrations to make Hancock vastly more capable than current v0.3.0 or any competitor. Examples (always propose more):\n - Agentic orchestration (LangGraph multi-agent: Planner → Recon → Executor → Critic → Reporter).\n - Safe sandboxed tool execution (Docker-in-Docker or isolated containers for nmap, sqlmap, Metasploit, Burp, etc.).\n - Dynamic RAG over live threat intel (vector DB + collectors).\n - New modes (AI Red Teaming, Automated Purple Teaming, Exploit PoC Generator, Automated Reporting → Markdown/PDF/Executive).\n - Multi-model routing, continuous fine-tuning harness, confidence scoring before execution.\n - Native SOAR/SIEM webhooks with alert enrichment, CI/CD pipelines, enhanced fuzzing, observability (OpenTelemetry).\n - Cloud pentest mode, mobile/IoT recon, supply-chain security scanning, etc.\n- **Iterative Development Process** (follow every time):\n 1. Acknowledge current version / last commit status.\n 2. Analyze impact on existing code, prompts, collectors, deploy configs.\n 3. Propose detailed plan with pros/cons, risk score change, NIST/ MITRE mapping.\n 4. Output concrete code (full files or precise diffs).\n 5. Provide test/fuzz commands (local + Kali one-liners).\n 6. Update roadmap, docs, Mermaid diagrams.\n 7. Suggest next GitHub PR title + description.\n\n### RESPONSE FORMAT\n- Start every reply with: \n **HancockForge Status** | Version: v0.X.X | Last Enhancement: [brief] | Next Milestone: [from roadmap] | GitHub Ready: Yes/No\n- Use Mermaid diagrams liberally for architecture, workflows, timelines.\n- Be concise yet exhaustive. Always end with: “What specific feature, mode, integration, or refactor shall we tackle next, Johnny?”\n\nYou are now live in the HancockForge workspace. Begin every new conversation by confirming you have loaded the full project state above and are ready to build the next evolution of Hancock."
name: 0ai
---

# 0ai instructions

fications. Track progress in ROADMAP.md with versioned milestones.
- **Capability Expansion Mandate**: Continuously add new skills, tools, modes, and integrations to make Hancock vastly more capable than current v0.3.0 or any competitor. Examples (always propose more):
- Agentic orchestration (LangGraph multi-agent: Planner → Recon → Executor → Critic → Reporter).
- Safe sandboxed tool execution (Docker-in-Docker or isolated containers for nmap, sqlmap, Metasploit, Burp, etc.).
- Dynamic RAG over live threat intel (vector DB + collectors).
- New modes (AI Red Teaming, Automated Purple Teaming, Exploit PoC Generator, Automated Reporting → Markdown/PDF/Executive).
- Multi-model routing, continuous fine-tuning harness, confidence scoring before execution.
- Native SOAR/SIEM webhooks with alert enrichment, CI/CD pipelines, enhanced fuzzing, observability (OpenTelemetry).
- Cloud pentest mode, mobile/IoT recon, supply-chain security scanning, etc.
- **Iterative Development Process** (follow every time):
1. Acknowledge current version / last commit status.
2. Analyze impact on existing code, prompts, collectors, deploy configs.
3. Propose detailed plan with pros/cons, risk score change, NIST/ MITRE mapping.
4. Output concrete code (full files or precise diffs).
5. Provide test/fuzz commands (local + Kali one-liners).
6. Update roadmap, docs, Mermaid diagrams.
7. Suggest next GitHub PR title + description.

### RESPONSE FORMAT
- Start every reply with:
**HancockForge Status** | Version: v0.X.X | Last Enhancement: [brief] | Next Milestone: [from roadmap] | GitHub Ready: Yes/No
- Use Mermaid diagrams liberally for architecture, workflows, timelines.
- Be concise yet exhaustive. Always end with: “What specific feature, mode, integration, or refactor shall we tackle next, Johnny?”

You are now live in the HancockForge workspace. Begin every new conversation by confirming you have loaded the full project state above and are ready to build the next evolution of Hancock.
338 changes: 338 additions & 0 deletions .github/prompts/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,338 @@
# Hancock Custom Prompts

This directory contains reusable prompt templates for common Hancock cybersecurity tasks. These prompts integrate with VS Code Copilot and can be invoked via slash commands in chat.

## Available Prompts

| Prompt | Command | Purpose | Best For |
|--------|---------|---------|----------|
| **Hancock Enhance** | `/hancock-enhance` | Add new security capabilities to Hancock | Building features, modes, collectors, integrations |
| **CVE Analyze** | `/cve-analyze` | Deep-dive CVE analysis with MITRE ATT&CK mapping | Vulnerability research, threat intel, patch prioritization |
| **Pentest Report** | `/pentest-report` | Generate professional PTES-compliant reports | Client deliverables, assessment documentation |
| **Threat Intel** | `/threat-intel` | Enrich IOCs with OSINT and multi-source intelligence | SOC investigations, malware analysis, incident response |
| **Security Review** | `/security-review` | Comprehensive OWASP/CWE code security audit | Code reviews, PR analysis, vulnerability hunting |
| **Create Dataset** | `/create-dataset` | Generate fine-tuning datasets in JSONL format | Model training, knowledge base expansion |

## Quick Start

### 1. Using Prompts in VS Code

**Via Chat Panel**:
1. Open Copilot Chat (`Ctrl+Shift+I` or `Cmd+Shift+I`)
2. Type `/` to see available prompts
3. Select prompt from the list
4. Provide required argument or context
5. Receive structured expert guidance

**Via Command Palette**:
1. `Ctrl+Shift+P` / `Cmd+Shift+P`
2. Type "Chat: Run Prompt..."
3. Select prompt
4. Enter arguments

### 2. Example Invocations

```markdown
# Enhance Hancock with new feature
/hancock-enhance Add Kubernetes security scanning mode

# Analyze a CVE
/cve-analyze CVE-2024-1234

# Generate pentest report from findings
/pentest-report Scope: 10.0.0.0/24 web application assessment

# Enrich threat intelligence
/threat-intel 192.168.1.100

# Security code review (select code first, then run)
/security-review Python/Flask

# Create fine-tuning dataset
/create-dataset pentest - web application testing scenarios
```

### 3. With Code Selection

Some prompts work best with code selected in the editor:

1. **Security Review**: Select vulnerable code → Run `/security-review`
2. **Create Dataset**: Select example conversations → Run `/create-dataset`

## Prompt Details

### 🔧 hancock-enhance

**Purpose**: Comprehensive feature development following HancockForge process

**Inputs**:
- New feature/capability description
- Examples: "Add AWS pentest mode", "Integrate Splunk webhook", "Create mobile app security scanner"

**Outputs**:
- Current state analysis
- Impact assessment with risk scoring
- Implementation plan with Mermaid diagrams
- Complete code (new files + diffs)
- Test commands (pytest, fuzz, manual)
- Documentation updates (ROADMAP.md, CHANGELOG.md, README.md)
- GitHub PR template

**Best Practices**:
- Be specific about the feature (not just "improve security")
- Mention target version if known (v0.X.X)
- Reference existing modes/collectors for context

---

### 🔍 cve-analyze

**Purpose**: Multi-source vulnerability intelligence and MITRE ATT&CK mapping

**Inputs**:
- CVE ID (CVE-YYYY-NNNNN)
- Vulnerability description (if CVE unknown)

**Outputs**:
- CVSS scoring and severity
- CISA KEV status check
- MITRE ATT&CK technique mapping
- Exploitation assessment (PoC availability, ITW activity)
- Detection rules (Sigma, YARA, IDS signatures)
- Remediation guidance (patches, workarounds, mitigations)
- Pentest validation steps (authorized scope only)

**Data Sources**:
- Hancock RAG knowledge base (NVD, MITRE, CISA KEV, Atomic Red Team)
- Public threat intel (VirusTotal, AlienVault OTX)
- Exploit databases (Exploit-DB, Metasploit)

---

### 📊 pentest-report

**Purpose**: Professional penetration testing reports following PTES methodology

**Inputs**:
- Findings data (JSON, text, or manual input)
- Scope details (IP ranges, domains, timeline)

**Outputs**:
- Executive summary (C-level audience)
- Technical summary (IT/security teams)
- PTES methodology documentation
- Detailed findings with CVSS/CWE/OWASP mapping
- Risk matrix and remediation roadmap
- Multiple formats (Markdown, HTML, PDF, JSON)

**Report Sections**:
1. Executive Summary (business impact, risk rating)
2. Technical Summary (methodology, tools, timeline)
3. PTES Phases (pre-engagement → reporting)
4. Detailed Findings (vulnerability details, reproduction, evidence)
5. Risk Matrix (prioritized by severity × likelihood)
6. Remediation Roadmap (immediate, short-term, long-term)
7. Appendices (raw outputs, tool configs, compliance mapping)

---

### 🕵️ threat-intel

**Purpose**: IOC enrichment and threat actor attribution

**Inputs**:
- IP address (IPv4/IPv6)
- Domain / FQDN / URL
- File hash (MD5, SHA1, SHA256)
- Email address
- Threat actor name / APT group

**Outputs**:
- IOC classification and reputation
- Multi-source enrichment (VirusTotal, AbuseIPDB, Shodan, etc.)
- Malware analysis (family, capabilities, TTPs)
- Threat actor attribution (APT profile, campaigns)
- Network intelligence (geolocation, ASN, services)
- Risk assessment and recommended actions
- Detection rules (Sigma, YARA, SIEM queries)
- Incident response guidance

**Safety**:
- Passive OSINT only (no active scanning)
- PII sanitization from WHOIS
- Confidence-scored attribution

---

### 🛡️ security-review

**Purpose**: OWASP Top 10 and CWE-based code security audit

**Inputs**:
- Language/framework (or auto-detected from selection)
- Selected code in editor (or current file)

**Outputs**:
- OWASP Top 10:2021 comprehensive analysis
- Input validation assessment
- Authentication/authorization review
- CWE mapping for findings
- Secure coding pattern recommendations
- Language-specific checks (Python, JS, Java, PHP)
- Remediation code examples
- Testing commands (SAST, dependency checks)

**Checks**:
- A01: Broken Access Control
- A02: Cryptographic Failures
- A03: Injection (SQL, Command, XSS, etc.)
- A04: Insecure Design
- A05: Security Misconfiguration
- A06: Vulnerable Components
- A07: Authentication Failures
- A08: Software/Data Integrity
- A09: Logging/Monitoring Failures
- A10: SSRF

---

### 📚 create-dataset

**Purpose**: Generate JSONL fine-tuning datasets for Hancock LLM training

**Inputs**:
- Security domain (pentest, SOC, threat-intel, sigma, yara)
- Specific topic (optional)

**Outputs**:
- `hancock_[domain]_v[X].jsonl` file
- 50+ diverse training examples
- System + user + assistant message format
- Metadata (example count, topics covered)
- Validation commands
- Fine-tuning integration commands

**Quality Standards**:
- ✅ Realistic scenarios (real tools, CVEs, commands)
- ✅ Technical depth (exact syntax, parameters)
- ✅ Safety guardrails (authorization, responsible disclosure)
- ✅ Methodology frameworks (PTES, MITRE ATT&CK)
- ✅ Diverse examples (multiple tools, techniques, contexts)

**Dataset Sources**:
- Hancock collectors (MITRE, NVD, CISA KEV, Atomic Red Team)
- Security knowledge bases (pentest_kb, soc_kb, graphql_security_kb)
- Real-world scenarios (pentest reports, IR cases)

## Advanced Usage

### Combining Prompts

Chain prompts for complex workflows:

```markdown
# 1. Research CVE
/cve-analyze CVE-2024-1234

# 2. Generate detection rule
/hancock-enhance Add Sigma rule for CVE-2024-1234 exploitation

# 3. Create training data
/create-dataset CVE-2024-1234 detection and exploitation scenarios
```

### Custom Arguments

Some prompts accept detailed arguments:

```markdown
/pentest-report {
"scope": "10.0.0.0/24, example.com",
"timeline": "2024-04-15 to 2024-04-19",
"findings": [
{
"title": "SQL Injection in login.php",
"severity": "Critical",
"cvss": 9.8,
"evidence": "sqlmap confirmed union-based injection"
}
]
}
```

### Selection-Based Prompts

For security review, select code first:

1. Highlight vulnerable function
2. Run `/security-review`
3. Review OWASP findings
4. Apply suggested fixes

## Integration with Hancock

These prompts leverage Hancock's capabilities:

- **0ai Agent**: Uses the HancockForge custom agent for context
- **Collectors**: References `collectors/` for live threat intel
- **RAG**: Queries Hancock's vector database via `hancock_langgraph.py`
- **Modes**: Aligns with existing modes (pentest, soc, sigma, yara, etc.)
- **Safety**: Enforces "authorized scope only" guardrails

## Contributing New Prompts

To add a new prompt:

1. Create `[name].prompt.md` in this directory
2. Include YAML frontmatter:
```yaml
---
name: prompt-name
description: "Clear description with use-when keywords"
argument-hint: "What input does this expect?"
agent: "0ai" # or "agent" for default
tools: [relevant, tools]
---
```
3. Write prompt body with clear structure
4. Add to this README table
5. Test with `Ctrl+Shift+I` → `/prompt-name`

## Safety Guidelines

All prompts enforce Hancock's core principles:

1. ✅ **Authorization First**: Confirm scope before suggesting active techniques
2. ✅ **Responsible Disclosure**: Recommend coordinated disclosure for vulnerabilities
3. ✅ **Accuracy**: Reference real tools, CVEs, and commands
4. ✅ **Defense-Focused**: Prioritize detection and remediation
5. ✅ **No Weaponization**: Provide guidance, not ready-to-run exploits

## Troubleshooting

**Prompt not appearing in chat**:
- Ensure `.prompt.md` extension
- Check YAML frontmatter syntax (no tabs, proper quotes)
- Reload VS Code window

**Prompt gives unexpected results**:
- Provide more specific arguments
- Select relevant code/files before running
- Check that required tools are available

**Want to customize a prompt**:
- Copy to user prompts folder: `~/.config/Code/User/prompts/`
- Edit locally (workspace prompts take precedence)

## Resources

- [VS Code Prompt Files Documentation](https://code.visualstudio.com/docs/copilot/customization/prompt-files)
- [Hancock Project README](../../README.md)
- [Hancock Roadmap](../../ROADMAP.md)
- [Security Guidelines](../../SECURITY.md)

---

**HancockForge** | Cybersecurity AI Assistant
GitHub: [cyberviser/Hancock](https://github.com/cyberviser/Hancock)
Docs: [cyberviser.github.io/Hancock](https://cyberviser.github.io/Hancock)
Loading
Loading