NFGuard v0.1.2
Pre-release
Pre-release
NFGuard v0.1.2 — Changelog
Fixes:
- Fixed ffuf failing with "unknown flag" error (-silent replaced with correct -s flag)
- Fixed gobuster failing due to status-codes vs status-codes-blacklist conflict (added -b "" to clear default blacklist)
- Fixed wordlist-dependent tools (ffuf, gobuster, feroxbuster) crashing when /usr/share/wordlists/ does not exist (added resolve_wordlist() with fallback chain: system paths -> bundled wordlist)
- Fixed webfetch failing on gov/corporate sites with self-signed or misconfigured SSL certificates (added verify_ssl parameter, default true)
- Fixed sqlmap crashing silently when Python is built without sqlite3 module (added explicit detection and clear error message)
- Fixed arjun running unnecessarily slowly due to --stable flag (removed) and timing out (timeout increased 300s -> 600s)
- Fixed theharvester defaulting to "all" sources causing slow runs and API key errors (curated fast no-API-key default sources)
Context Window Protection:
- Added output truncation (50K chars) in BaseTool._run_command() to prevent oversized tool output from crashing the context window
- Added tool result truncation (50K chars) in AgentContext.add_tool_result() as defense-in-depth for in-process tools (webfetch, delegate_to_agent)
- Added _trim_if_needed() call in OrchestratorAgent (was missing, causing max_tokens=-511444 crash)
- Added post-trim safety check: if tokens still exceed 85% of context window after trim, truncates individual messages exceeding 30% of window
Retry Intelligence:
- Added permanent error classification (_is_permanent_error) — errors like "unknown flag", "Binary not found", "Permission denied" now break the retry loop immediately instead of retrying uselessly
- Error messages returned to LLM are now tagged as "PERMANENT" or "transient" so the LLM knows whether to retry
- Sub-agent max_iterations_reached now returns success=True with partial results (prevents orchestrator from re-delegating the same task 3x, wasting 60+ tool calls)
- Sub-agents now inherit max_tool_retries from config instead of using hardcoded default
- Added "Error Handling Rules" to all 4 sub-agent system prompts (recon, web_testing, vuln_scanning, reporting)
New Files:
- src/nfguard/tools/wordlist.py — Wordlist resolution with fallback chain (user path -> system paths -> bundled)
- src/nfguard/_bundled/vendor/wordlists/common.txt — Minimal bundled wordlist (~900 entries)