mirror of
https://github.com/Strategic-Automation/violin.git
synced 2026-08-14 12:33:37 +02:00
- Remove challenge_ids seeding (vulnerability-name leak) from scope; seed engagement.coverage_obligations (client-style in-scope endpoints) + generic engagement.audit_mode flag instead - plugins/violin_guard now contains zero benchmark/run-id references; gates are framework-owned and audit-mode-gated - Cross-engagement guard blocks ANY foreign engagement dir, not just benchmark-run-* - Anti-cheat regression test asserts no vuln names in generated scope