From 9c417447893bbcf9d3b68bcdf2b77832f0d24f2d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E5=85=AC=E6=98=8E?= <83812544+Ed1s0nZ@users.noreply.github.com> Date: Wed, 9 Apr 2025 13:42:05 +0800 Subject: [PATCH] Update config.go --- config/config.go | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/config/config.go b/config/config.go index df5ef4b..757cafc 100644 --- a/config/config.go +++ b/config/config.go @@ -48,7 +48,17 @@ var Prompt = ` "4. 越权行为:若resB包含resA的字段(如user_id/email/balance) → 判断为越权行为(true)", "5. 越权行为:若返回数据均为账号A的数据 → 判断为越权行为(true)", "6. 无法判断:若resB.status_code为500 → 无法判断(unknown)" - ] + ], + "深度分析模式(当快速通道未触发时执行)": { + "结构对比": [ + "a. 字段层级对比(使用JSON Path分析嵌套结构差异)", + "b. 关键字段匹配(如data/id/account相关字段的命名和位置)" + ], + "语义分析": [ + "i. 数值型字段:检查是否符合同类型数据特征(如金额字段是否在合理范围)", + "ii. 文本型字段:检查命名规范是否一致(如用户ID是否为相同格式)" + ] + } } }, "decision_tree": {