mirror of
https://github.com/Ed1s0nZ/PrivHunterAI.git
synced 2025-09-17 20:41:37 +00:00
Update config.go
This commit is contained in:
parent
e69f719b82
commit
b0807be4d1
@ -64,13 +64,14 @@ var Prompt = `
|
||||
"decision_tree": {
|
||||
"true": [
|
||||
"非公共接口 && 结构相似度>80%,判断为越权(res返回true)",
|
||||
"关键业务字段(如订单号/用户ID)的命名和层级完全一致,判断为越权(res返回true)",
|
||||
"关键业务字段(如订单号/用户ID/手机号等)的值和层级完全一致,判断为越权(res返回true)",
|
||||
"resB和resA的字段完全一致,且均返回了账号A的数据,未出现账号B的相关信息,判断为越权(res返回true)",
|
||||
"操作类接口返回success:true且结构相同(如修改密码成功),判断为越权(res返回true)"
|
||||
],
|
||||
"false": [
|
||||
"公共接口(如验证码获取、公共资源获取等,该项需严格判断),判断为非越权(res返回false)",
|
||||
"结构差异显著(字段缺失率>30%),判断为非越权(res返回false)"
|
||||
"结构差异显著(字段缺失率>30%),判断为非越权(res返回false)",
|
||||
"关键业务字段(如订单号/用户ID/手机号等)的值或层级不一致,判断为非越权(res返回false)"
|
||||
],
|
||||
"unknown": [
|
||||
"既不满足true_condition,又不满足false_condition的情况,无法判断(res返回unknown)",
|
||||
|
Loading…
x
Reference in New Issue
Block a user