Skip to content

NFGuard v0.1.2

Pre-release
Pre-release

Choose a tag to compare

@dolutech dolutech released this 19 Feb 22:40
· 2 commits to main since this release
64f8efe

NFGuard v0.1.2 — Changelog

Fixes:

  • Fixed ffuf failing with "unknown flag" error (-silent replaced with correct -s flag)
  • Fixed gobuster failing due to status-codes vs status-codes-blacklist conflict (added -b "" to clear default blacklist)
  • Fixed wordlist-dependent tools (ffuf, gobuster, feroxbuster) crashing when /usr/share/wordlists/ does not exist (added resolve_wordlist() with fallback chain: system paths -> bundled wordlist)
  • Fixed webfetch failing on gov/corporate sites with self-signed or misconfigured SSL certificates (added verify_ssl parameter, default true)
  • Fixed sqlmap crashing silently when Python is built without sqlite3 module (added explicit detection and clear error message)
  • Fixed arjun running unnecessarily slowly due to --stable flag (removed) and timing out (timeout increased 300s -> 600s)
  • Fixed theharvester defaulting to "all" sources causing slow runs and API key errors (curated fast no-API-key default sources)

Context Window Protection:

  • Added output truncation (50K chars) in BaseTool._run_command() to prevent oversized tool output from crashing the context window
  • Added tool result truncation (50K chars) in AgentContext.add_tool_result() as defense-in-depth for in-process tools (webfetch, delegate_to_agent)
  • Added _trim_if_needed() call in OrchestratorAgent (was missing, causing max_tokens=-511444 crash)
  • Added post-trim safety check: if tokens still exceed 85% of context window after trim, truncates individual messages exceeding 30% of window

Retry Intelligence:

  • Added permanent error classification (_is_permanent_error) — errors like "unknown flag", "Binary not found", "Permission denied" now break the retry loop immediately instead of retrying uselessly
  • Error messages returned to LLM are now tagged as "PERMANENT" or "transient" so the LLM knows whether to retry
  • Sub-agent max_iterations_reached now returns success=True with partial results (prevents orchestrator from re-delegating the same task 3x, wasting 60+ tool calls)
  • Sub-agents now inherit max_tool_retries from config instead of using hardcoded default
  • Added "Error Handling Rules" to all 4 sub-agent system prompts (recon, web_testing, vuln_scanning, reporting)

New Files:

  • src/nfguard/tools/wordlist.py — Wordlist resolution with fallback chain (user path -> system paths -> bundled)
  • src/nfguard/_bundled/vendor/wordlists/common.txt — Minimal bundled wordlist (~900 entries)