UNLIMITED AI · PROMPT LIBRARY

500 Bug Bounty Prompts. Built for Real Research.

Search 500 original bug bounty prompts across 20 categories: recon, authorization, APIs, code review, validation and reporting. Find a task and copy its prompt.

Browse 500 original bug bounty prompts for mapping attack surfaces, reviewing code, validating findings and writing clear vulnerability reports.

500 distinct prompts20 research categoriesSearch · filter · copy

Pick a task. Bring the evidence.

Choose a prompt, then attach the relevant sanitized brief, source code, captures or notes you are permitted to share. Each prompt specifies a concrete review task and expected output. These are research instructions, not prevalidated exploits or claims that a vulnerability exists.

Use only within your program’s authorization and data-sharing rules. Copy buttons include a short context instruction to preserve scope, distinguish facts from assumptions and avoid invented results. No API key or account is needed to browse this library.

500 prompts across 20 categories

Scope & planning · 25 prompts
PROMPT 001

Program brief extraction

Convert the supplied program brief into allowed assets, excluded assets, prohibited methods, account requirements and disclosure conditions. Quote the supporting passage for each entry; flag ambiguity.

PROMPT 002

Wildcard scope review

Compare this hostname inventory against the written wildcard rules. Separate explicit matches, exclusions and uncertain ownership; do not infer authorization from a shared parent company.

PROMPT 003

Testing budget

Build a research schedule from my allowed hours and program restrictions. Allocate time to mapping, focused validation and evidence review, with stopping criteria for each phase.

PROMPT 004

Account preparation

Design the minimum test-account set for these roles and tenant boundaries. Identify which accounts and permissions I must obtain before comparing behavior.

PROMPT 005

Scope change review

Compare these two dated program briefs. List changes to assets, permitted methods, exclusions and reporting requirements, with a suggested update to my research checklist.

PROMPT 006

Third-party boundary

Review the supplied dependency and domain map. Distinguish first-party assets from hosted vendors and integrations; list ownership questions that must be resolved before active testing.

PROMPT 007

Automation constraints

Extract automation and traffic restrictions from this brief. Turn them into explicit concurrency, delay, retry and stop settings, leaving unspecified values unresolved.

PROMPT 008

Research question selection

Rank these research questions by clarity, available evidence, authorized access and validation effort. Explain the ranking without guessing payout or severity.

PROMPT 009

Test-data plan

Propose synthetic records for this workflow that cover relevant roles and object states. Explain how each record supports a specific authorization or integrity check.

PROMPT 010

Session objective

Turn these scattered notes into one bounded research objective. State the security property, required observations, disconfirming evidence and what would end the investigation.

PROMPT 011

Dependency map

Map the supplied application workflow into services and trust boundaries. Mark which connections are observed, inferred or unknown and identify evidence needed to resolve uncertainty.

PROMPT 012

Permission clarification draft

Draft a concise scope clarification from these conflicting rules. Ask only the questions necessary to determine whether the proposed test is permitted; do not send it.

PROMPT 013

Evidence handling plan

Create a handling plan for these evidence types. Specify redaction, access controls, retention and deletion checkpoints consistent with the supplied program requirements.

PROMPT 014

Local lab conversion

Translate this risky production hypothesis into a local laboratory experiment. Preserve the suspected security property while replacing real accounts, secrets and services with synthetic equivalents.

PROMPT 015

Research stop conditions

Define explicit stop conditions for the proposed test, including unexpected access, service errors and data exposure. Connect each condition to a concrete observation.

PROMPT 016

Feature inventory

Organize these screenshots and notes into user-facing features, account roles and sensitive transitions. Highlight unobserved areas without inventing endpoints.

PROMPT 017

Assumption register

Extract every assumption from this research plan. For each, explain how it affects validity and identify the smallest observation that could confirm or reject it.

PROMPT 018

Allowed-method checklist

Compare my proposed steps with the provided rules. Mark each permitted, prohibited or unclear, citing the relevant rule and suggesting a permitted alternative where possible.

PROMPT 019

Duplicate research planning

Compare my idea with these public disclosed reports. Identify shared prerequisites and root causes; explain what evidence would demonstrate a distinct issue.

PROMPT 020

Read-only first pass

Design a first-pass review using supplied documentation and captures only. Prioritize unanswered security questions without initiating requests to the application.

PROMPT 021

Access prerequisite review

List the prerequisites behind this hypothesis: role, tenant, object state, feature flag and session condition. Separate normal user capabilities from administrative privileges.

PROMPT 022

Research handoff

Turn my session notes into a handoff with scope, completed observations, unresolved hypotheses, artifact locations and next steps. Preserve failed attempts and uncertainty.

PROMPT 023

Observation ledger

Build a chronological ledger from these notes. Separate actions, responses, interpretations and questions so later reviewers can reconstruct what actually happened.

PROMPT 024

Sensitive-operation map

Identify operations in this workflow that create commitments, delete records or affect other users. Propose harmless substitutes for research where feasible.

PROMPT 025

One-hour review plan

Create a one-hour plan for this single feature using the supplied materials. Limit the scope to three hypotheses and state what evidence each requires.

Asset discovery & recon · 25 prompts
PROMPT 026

Passive inventory merge

Merge these passive hostname exports, normalize names and preserve source attribution. Flag wildcard entries and stale observations instead of treating every name as a live asset.

PROMPT 027

DNS evidence comparison

Compare the supplied DNS snapshots. Identify changed records and unresolved names, separating configuration changes from evidence of a security issue.

PROMPT 028

Certificate inventory review

Group certificate names by domain and observation date. Identify names worth checking against scope; do not infer current ownership or availability from a certificate alone.

PROMPT 029

HTTP fingerprint grouping

Cluster these permitted HTTP probe results by title, status, technology clues and response similarity. Explain uncertainty where shared infrastructure could create misleading matches.

PROMPT 030

Redirect destination audit

Inspect this collected redirect chain inventory. Identify cross-domain hops and ownership questions while preserving each original URL and final destination.

PROMPT 031

Wildcard response detection

Analyze these baseline and candidate responses for wildcard behavior. Recommend comparison features beyond status code, including normalized body structure and headers.

PROMPT 032

Historical asset delta

Compare historical and current inventories. Mark newly observed, no-longer-observed and unchanged assets; distinguish absence of evidence from confirmed decommissioning.

PROMPT 033

Service ownership dossier

Organize these public ownership clues into a dossier per host. Separate direct evidence from naming conventions and list unanswered scope questions.

PROMPT 034

Technology confidence

Review the supplied technology fingerprints. Assign confidence from observed headers and content, and flag versions inferred solely from scanner heuristics.

PROMPT 035

Environment grouping

Classify these assets as likely production, staging, development or unknown using supplied evidence. Explain why naming alone is insufficient to establish environment or authorization.

PROMPT 036

Dangling DNS triage

Review the supplied DNS and HTTP evidence for potentially dangling services. Identify missing ownership proof; do not provision or claim third-party resources.

PROMPT 037

Host prioritization

Prioritize this in-scope host list by exposed application features and evidence gaps. Avoid treating an unusual port or product banner as a confirmed vulnerability.

PROMPT 038

Screenshot inventory

Turn these application screenshots into a searchable inventory of functions, login boundaries and visible integrations. Retain the source URL for every observation.

PROMPT 039

Port result interpretation

Interpret these authorized scan results, distinguishing open services, filtered responses and uncertain fingerprints. Suggest low-impact verification questions rather than exploit attempts.

PROMPT 040

CDN versus origin

Review this architecture evidence for possible CDN and origin roles. List observations needed to distinguish them without probing unapproved infrastructure.

PROMPT 041

Domain normalization

Normalize this mixed URL and hostname list while preserving internationalized names, ports and original values. Explain collisions introduced by normalization.

PROMPT 042

Recon provenance

Audit my recon dataset for missing timestamps, sources and scope decisions. Produce a repair checklist so each asset can be traced to its evidence.

PROMPT 043

Duplicate host grouping

Group hosts that appear to serve the same application using the supplied captures. Preserve separate tenancy and ownership boundaries even when page content matches.

PROMPT 044

Robots and sitemap review

Extract paths from these supplied robots and sitemap files. Group by function, and explain why listing or exclusion does not establish authorization or sensitivity.

PROMPT 045

Public documentation inventory

Map documented products and services to the supplied asset list. Flag undocumented relationships as hypotheses rather than expanding testing scope automatically.

PROMPT 046

Response anomaly triage

Compare anomalous responses with their baselines. Identify likely login redirects, maintenance pages, bot challenges and genuinely different application content.

PROMPT 047

Recon noise reduction

Review this candidate inventory and define explainable filters for duplicates, generic errors and irrelevant third-party assets. Preserve raw records for auditability.

PROMPT 048

Asset lifecycle timeline

Build a timeline from these dated DNS, certificate and HTTP records. Highlight where conclusions depend on gaps in observation.

PROMPT 049

Shared hosting caution

Analyze these shared-IP observations. Explain what can and cannot be inferred about ownership, isolation and scope from co-location alone.

PROMPT 050

Recon summary for review

Summarize the supplied recon results into confirmed inventory, unresolved ownership and next authorized observations. Include counts with definitions and avoid inflated findings.

URLs, parameters & JavaScript · 25 prompts
PROMPT 051

Endpoint extraction review

Extract endpoint references from the supplied JavaScript source. Preserve the containing function and distinguish literal routes, constructed paths and third-party URLs.

PROMPT 052

Parameter inventory

Build a parameter inventory from these captured requests. Record location, observed type, example shape and apparent purpose without exposing credential values.

PROMPT 053

Route deduplication

Normalize these application routes for comparison while retaining method, version and parameter structure. Explain which routes must remain distinct for authorization analysis.

PROMPT 054

Source-map assessment

Review the supplied source-map contents for disclosed source structure and sensitive configuration references. Report exact locations with secrets redacted; do not use discovered credentials.

PROMPT 055

Client server mismatch

Compare client-side validation with the provided server handler. Identify rules enforced only in the client and the missing server evidence needed to assess impact.

PROMPT 056

Feature flag analysis

Trace these feature flags through the supplied bundle. Distinguish presentation controls from server-side entitlements and identify the endpoint that enforces each permission.

PROMPT 057

API version comparison

Compare captured routes across API versions. Highlight changed authentication, fields and response structures without assuming an older version is insecure.

PROMPT 058

Hidden field inventory

List fields referenced by the client but absent from the visible form. Explain their likely role and what server-side validation must be checked.

PROMPT 059

Request construction trace

Trace how this function builds its URL, headers and body. Identify controllable inputs and encoding boundaries with line references.

PROMPT 060

Sensitive data in URLs

Review these sanitized request URLs for data that should not appear in query strings or paths. Explain possible exposure surfaces without claiming observed leakage.

PROMPT 061

Error route classification

Classify these endpoint responses as application errors, gateway errors, authentication redirects or unknown. State which response details support each classification.

PROMPT 062

Pagination parameter review

Inspect captured pagination requests for cursor, offset and limit semantics. Propose a small test-account comparison to verify consistent access boundaries across pages.

PROMPT 063

Sorting and filtering map

Map supplied filter and sort parameters to their server handlers. Identify validation and authorization questions for each supported operator.

PROMPT 064

Endpoint method matrix

Build a method-by-route matrix from the supplied API captures. Flag undocumented methods and missing captures rather than inventing supported operations.

PROMPT 065

Client storage inventory

Inventory local storage, session storage and IndexedDB usage visible in this source. Classify stored data and trace which code reads or writes it.

PROMPT 066

Bundle change review

Compare these two JavaScript versions for new endpoints, permissions and sensitive flows. Focus on semantic changes rather than minification differences.

PROMPT 067

Third-party script map

Map the scripts in this captured page to their origins and loaded functions. Identify data access questions and uncertainty about dynamically loaded code.

PROMPT 068

WebSocket message catalog

Organize these sanitized WebSocket frames by action and object identifier. Identify session establishment and per-message authorization questions.

PROMPT 069

Service worker route map

Explain the supplied service worker's fetch handlers, caches and scope. Identify which authenticated responses could enter a shared or persistent cache.

PROMPT 070

GraphQL operation inventory

Extract named operations and variables from these client files. Group by object and privilege boundary while keeping queries separate from mutations.

PROMPT 071

File URL lifecycle

Trace upload, preview, download and deletion URLs from the provided captures. Identify differences in authentication and expiration across the lifecycle.

PROMPT 072

Client-side secrets triage

Classify suspected keys in this permitted source sample as public identifiers, test values or potentially sensitive credentials. Redact values and identify verification that does not use them.

PROMPT 073

URL parser comparison

Compare how these supplied URL parsing functions handle scheme, host, port and relative paths. Identify disagreements using synthetic examples only.

PROMPT 074

Endpoint documentation gaps

Compare the API specification with observed client requests. List missing routes, fields and security descriptions, with evidence references.

PROMPT 075

JavaScript review queue

Turn these bundle findings into a short review queue ranked by reachable trust boundaries. Require a source reference and falsifiable question for every item.

Authentication & sessions · 25 prompts
PROMPT 076

Login flow map

Diagram the supplied login sequence from initial request to authenticated session. Identify where identity is verified, state is created and errors are returned.

PROMPT 077

Session rotation review

Compare session identifiers before and after login in my test-account captures. Check rotation and invalidation evidence without exposing raw token values.

PROMPT 078

Logout validation

Design a bounded test using my own account to verify logout behavior across browser tabs and an existing API session. Define expected results per session type.

PROMPT 079

Password reset lifecycle

Review the supplied reset flow for token issuance, expiration, single use and account binding. Identify missing evidence without attempting other users' resets.

PROMPT 080

Email change workflow

Map verification and session effects around an email change using supplied captures. Identify which address authorizes the transition and when the new identity becomes active.

PROMPT 081

MFA state transitions

Analyze this MFA enrollment and removal sequence. Identify required reauthentication, recovery handling and session-state changes from the evidence provided.

PROMPT 082

Recovery code review

Review this recovery-code design for single use, storage and regeneration semantics. Propose controlled tests with codes generated for my test account.

PROMPT 083

Remember-me token review

Compare normal and persistent-login sessions using the supplied documentation and captures. Identify expiration, revocation and device-binding questions.

PROMPT 084

Cookie attribute analysis

Review these redacted Set-Cookie headers against the described deployment. Explain the purpose and limitations of each flag in this specific flow.

PROMPT 085

Session timeout matrix

Create a matrix for idle timeout, absolute lifetime and renewal based on these test observations. Distinguish frontend logout from server-side invalidation.

PROMPT 086

Concurrent session policy

Compare stated session policy with my own-device observations. Identify whether logout and password changes revoke the expected sessions.

PROMPT 087

Reauthentication boundary

Locate sensitive operations in this workflow and identify evidence of recent-authentication checks. Separate a missing prompt from a demonstrated authorization failure.

PROMPT 088

Account enumeration assessment

Compare supplied login and recovery responses for observable differences. Identify benign explanations and the controlled evidence needed before claiming enumeration.

PROMPT 089

Credential handling review

Trace how the supplied client and server code handle passwords. Identify logging, transport and storage concerns without retaining or displaying actual credentials.

PROMPT 090

Invitation acceptance

Review how an invitation is bound to an account, organization and role. Check expiration and reuse semantics using only the supplied test-account evidence.

PROMPT 091

Account linking analysis

Map the identity checks used to link two login methods. Identify where email verification, existing-session ownership and explicit consent are required.

PROMPT 092

SSO logout mapping

Explain the supplied application and identity-provider logout flows. Distinguish application session termination from upstream identity-provider session termination.

PROMPT 093

Device approval flow

Review the provided device authorization sequence for user-code binding, expiration and approval context. Identify what the approving user can verify.

PROMPT 094

Authentication error review

Inspect these sanitized authentication errors for sensitive internal details and inconsistent handling. Separate information exposure from ordinary diagnostic messages.

PROMPT 095

Password policy consistency

Compare registration, change and reset password validation in the supplied code. Identify inconsistent checks and their practical effect without guessing exploitability.

PROMPT 096

Session storage threat model

Evaluate this token storage approach against the application's browser threat model. Compare persistence, script access and cross-site request behavior.

PROMPT 097

Magic-link account binding

Review the supplied magic-link implementation for intended account, expiration and consumption. Identify how redirects and preexisting sessions affect the flow.

PROMPT 098

Disabled-account sessions

Plan a controlled test for a disabled test account's existing sessions. Specify expected behavior for interactive requests, refresh operations and background jobs.

PROMPT 099

Authentication regression cases

Convert this confirmed authentication fix into regression cases covering success, failure, expiration and replay. Each case must state its observable assertion.

PROMPT 100

Session evidence summary

Summarize these session tests with timestamps, account states and token aliases. Identify which conclusions are proven and which require additional observation.

Authorization & tenancy · 25 prompts
PROMPT 101

Object ownership matrix

Build a permission matrix for these objects using two researcher-controlled accounts. Separate owner, same-tenant peer and different-tenant access expectations.

PROMPT 102

Read versus write access

Compare the supplied read and update handlers for the same resource. Identify whether both enforce the same object and tenant boundaries.

PROMPT 103

Nested resource ownership

Review how this endpoint validates parent and child identifiers. Determine whether the relationship is checked server-side and cite the relevant code.

PROMPT 104

Bulk operation authorization

Inspect this batch handler for per-item authorization. Design a minimal test with owned synthetic records and explicit permitted versus denied outcomes.

PROMPT 105

Role downgrade effects

Review test captures before and after a role downgrade. Identify stale permissions in sessions, cached responses and asynchronous operations.

PROMPT 106

Organization switching

Trace organization selection through the supplied requests. Identify which values choose the tenant and where the server verifies membership.

PROMPT 107

Export authorization

Map the permissions used to request, generate and download an export. Check that each stage binds the artifact to the authorized requester.

PROMPT 108

Search result isolation

Compare search responses for controlled accounts with different access. Identify whether counts, snippets or suggestions expose records outside the permitted set.

PROMPT 109

Attachment ownership

Review attachment metadata and download handlers. Identify whether access follows the parent resource's permissions throughout preview and download flows.

PROMPT 110

Soft-deleted resources

Analyze access to synthetic soft-deleted objects under the supplied retention policy. Distinguish authorized recovery from unintended continued visibility.

PROMPT 111

Administrative action boundary

Review this administrative handler and its middleware chain. Identify the server-side privilege requirement and whether every route reaches that check.

PROMPT 112

Field-level permissions

Compare allowed fields across the supplied roles. Identify fields returned or accepted beyond the role's documented rights and specify minimal validation evidence.

PROMPT 113

Shared link permissions

Review this shared-link design for audience, expiry and revocation. Distinguish intentional bearer access from a broken access-control claim.

PROMPT 114

Asynchronous job ownership

Trace job creation, status polling and output retrieval. Identify how the requester and tenant are bound at every stage.

PROMPT 115

Membership removal

Design a controlled check for removed-member access to existing projects, links and sessions. Use only artifacts created for the test.

PROMPT 116

Tenant identifier trust

Review whether this handler trusts a tenant identifier from the request or derives it from verified membership. Cite the decision point and unresolved context.

PROMPT 117

Permission inheritance

Map inherited permissions across this folder or project hierarchy. Identify exceptions, overrides and expected behavior after moving a resource.

PROMPT 118

Service account permissions

Compare service-account scopes with endpoint requirements from the supplied documentation. Identify overbroad privileges and missing enforcement evidence.

PROMPT 119

Notification visibility

Review whether notification content and destinations honor current resource access. Consider removed members and changed sharing settings using synthetic records.

PROMPT 120

Audit log isolation

Compare audit-log access across controlled roles and tenants. Distinguish required administrative visibility from unintended cross-tenant disclosure.

PROMPT 121

Comment ownership

Review edit and delete permissions for comments in the supplied workflow. Separate comment-author rights from parent-resource and moderator permissions.

PROMPT 122

Permission cache invalidation

Analyze this permission cache design around membership changes. Identify invalidation paths and a bounded test that can distinguish stale authorization from stale display.

PROMPT 123

Graph authorization paths

Map alternative paths to the same object through REST, GraphQL and exports. Compare authorization checks without assuming one path inherits another's protections.

PROMPT 124

Access-control counterexample

Challenge this suspected authorization finding. Identify legitimate sharing or role rules that could explain the behavior and the evidence that rules them out.

PROMPT 125

Authorization report proof

Review this authorization report for clear account ownership, role separation and object provenance. Remove claims unsupported by the provided comparison.

REST, GraphQL & WebSockets · 25 prompts
PROMPT 126

OpenAPI security review

Review the supplied OpenAPI document for authentication declarations, sensitive operations and inconsistent security overrides. Distinguish specification gaps from verified server behavior.

PROMPT 127

Resolver permission mapping

Map each supplied GraphQL resolver to its authorization check and data source. Identify fields whose checks differ from the parent object's checks.

PROMPT 128

API response minimization

Compare these response fields with the feature's stated needs. Identify unnecessary sensitive fields and the evidence required to establish unauthorized exposure.

PROMPT 129

Mass assignment code review

Trace request fields into this model update. Identify explicit allowlists, protected attributes and unexpected binding behavior using the supplied source.

PROMPT 130

GraphQL mutation isolation

Design a controlled comparison of this mutation across my test roles. State object ownership, expected denial and the smallest synthetic state change.

PROMPT 131

WebSocket handshake authentication

Review the supplied handshake flow for identity establishment and origin handling. Separate handshake checks from later message-level permissions.

PROMPT 132

WebSocket session expiry

Plan a controlled test of an existing socket after session expiry or logout. Specify expected behavior for reads and state-changing messages.

PROMPT 133

API schema drift

Compare these API specification versions for changed field types, required values and security declarations. Prioritize changes affecting trust boundaries.

PROMPT 134

GraphQL error disclosure

Inspect these sanitized GraphQL errors for internal paths, query details and sensitive values. Explain what is actually disclosed and avoid speculative impact.

PROMPT 135

API content-type handling

Compare supplied handlers for JSON, form and multipart requests. Identify differences in validation and authorization caused by parsing paths.

PROMPT 136

GraphQL pagination boundaries

Review cursor ownership and access checks in this resolver. Propose test-account observations that separate cursor tampering from ordinary invalid-cursor handling.

PROMPT 137

API key scope mapping

Map documented API key scopes to captured endpoint behavior. Identify missing tests for narrower scopes without using credentials outside my account.

PROMPT 138

Webhook subscription permissions

Trace webhook registration, update and deletion permissions in this code. Identify whether destination and event scope are bound to the correct tenant.

PROMPT 139

API version retirement

Assess the supplied deprecated API routes for continued authentication and validation parity. Treat continued availability alone as an observation, not a vulnerability.

PROMPT 140

GraphQL alias accounting

Review query-cost accounting for aliases and repeated fields in a local configuration. Suggest bounded unit tests rather than high-volume production queries.

PROMPT 141

Batch request semantics

Explain how this API batch handles mixed success, failure and authorization. Identify whether denied items can affect allowed items' state.

PROMPT 142

Idempotency key binding

Review how idempotency keys are associated with user, route and request body. Identify collisions or reuse questions using synthetic operations.

PROMPT 143

HTTP status consistency

Compare status codes and response bodies for documented API outcomes. Identify client assumptions that could cause a security-sensitive misinterpretation.

PROMPT 144

API default permissions

Review default authorization behavior when middleware or scope annotations are absent. Cite the supplied framework configuration and affected routes.

PROMPT 145

GraphQL introspection context

Explain what the supplied schema reveals and what it does not prove. Identify sensitive operations worth reviewing within scope without labeling introspection itself a finding.

PROMPT 146

Subscription authorization

Trace authorization for GraphQL subscriptions at registration and event delivery. Identify how later permission changes affect existing subscribers.

PROMPT 147

API caching identity

Review caching around this authenticated API response. Identify which user, tenant and permission attributes form the cache key.

PROMPT 148

Object expansion review

Analyze optional expand or include parameters in these captures. Check whether related objects preserve their own access restrictions.

PROMPT 149

Client retry side effects

Review this API client's retry policy against non-idempotent operations. Identify duplicate-action risks and propose local tests with explicit assertions.

PROMPT 150

API evidence cross-check

Compare a claimed API weakness with the request, response and state evidence. List unsupported assumptions and the minimum missing observation.

Browser security & XSS · 25 prompts
PROMPT 151

DOM source-to-sink trace

Trace this supplied browser code from controllable input to DOM writes. Identify encoding and sanitization boundaries with line references and reachable conditions.

PROMPT 152

HTML context classification

Classify each reflected value in these sanitized responses by HTML, attribute, URL or script context. Explain which contextual protections must be reviewed.

PROMPT 153

Stored content rendering

Map where this user-authored content is rendered across views and roles. Identify inconsistent sanitization using supplied templates and synthetic examples.

PROMPT 154

Sanitizer configuration review

Review this sanitizer configuration against the application's permitted markup. Identify risky allowances and propose harmless regression inputs for a local test suite.

PROMPT 155

CSP interpretation

Explain this Content Security Policy in the context of the supplied page. Distinguish effective restrictions, report-only settings and unsupported assumptions.

PROMPT 156

Trusted Types coverage

Review the provided Trusted Types policies and DOM call sites. Identify uncovered sinks and whether policy functions actually validate their inputs.

PROMPT 157

PostMessage receiver review

Analyze this message listener for origin, source and message-shape checks. Trace sensitive operations reached after validation using the supplied code.

PROMPT 158

PostMessage sender review

Review how this code selects a destination window and target origin. Identify whether sensitive content could reach an unintended recipient.

PROMPT 159

DOM clobbering review

Inspect the supplied code for reliance on named DOM properties. Explain possible identifier collisions and propose a local, non-executing reproduction fixture.

PROMPT 160

Client redirect logic

Trace this client-side redirect function from input to navigation. Identify validation boundaries and distinguish intentional external links from trust-sensitive redirects.

PROMPT 161

URL scheme validation

Review permitted URL schemes for these link and media fields. Identify inconsistent normalization and propose safe unit tests for rejected schemes.

PROMPT 162

Markdown rendering review

Compare raw HTML handling, link sanitization and image processing in this markdown pipeline. Identify differences between preview and saved rendering.

PROMPT 163

Template escaping audit

Review these templates for automatic escaping and explicit unescaped output. Map each exception to its input source and intended content type.

PROMPT 164

Browser storage exposure

Explain which scripts can access the data stored by this page. Identify sensitive values and distinguish storage choice from a demonstrated script-execution issue.

PROMPT 165

Sandboxed iframe review

Analyze this iframe's sandbox and permission attributes. Explain the capabilities granted and whether they match the embedded content's intended role.

PROMPT 166

Window opener review

Review external navigation and opener relationships in this code. Identify where an untrusted destination could retain a reference to the original window.

PROMPT 167

Service worker cache review

Trace the supplied caching rules for authenticated pages. Identify user separation, logout invalidation and stale sensitive-response concerns.

PROMPT 168

Client-side prototype handling

Review object merges and property lookups in this code for unsafe inherited-property behavior. Propose local assertions using benign synthetic objects.

PROMPT 169

CSS injection context

Analyze this dynamic style construction for controllable values and validation. Distinguish cosmetic influence from evidence of a security-sensitive consequence.

PROMPT 170

XSS false-positive review

Review this scanner result and response context. Determine whether input reaches executable interpretation or remains safely encoded, and list missing evidence.

PROMPT 171

Browser evidence capture

Plan minimal screenshots and request captures for this confirmed browser issue. Exclude credentials and unrelated user data while preserving context.

PROMPT 172

Cross-view consistency

Compare rendering of the same synthetic record in list, detail, admin and notification views. Identify which contexts require separate encoding review.

PROMPT 173

Client route authorization

Review whether hidden routes rely solely on frontend checks. Identify the corresponding server-side authorization evidence needed before claiming a bypass.

PROMPT 174

XSS patch regression

Convert this escaping fix into tests for all affected output contexts. Include normal content and edge cases without assuming one encoding fits every sink.

PROMPT 175

Browser finding impact

Rewrite this browser-security impact statement to match the demonstrated origin, user interaction and accessible data. Remove unsupported account-takeover claims.

CSRF, CORS & cookies · 25 prompts
PROMPT 176

CSRF prerequisite map

Analyze this state-changing request for authentication transport, browser reachability and anti-CSRF checks. Identify which prerequisites are established by the supplied capture.

PROMPT 177

SameSite flow review

Explain how the supplied cookie settings interact with these navigation and request flows. Identify tests needed across the relevant browser contexts.

PROMPT 178

Origin validation code

Review this origin-validation function for exact parsing and comparison behavior. Use synthetic origins to identify normalization mistakes in local tests.

PROMPT 179

CORS response assessment

Interpret these CORS headers alongside credential mode and response sensitivity. Distinguish permissive public data from authenticated data exposure.

PROMPT 180

Preflight handling

Compare preflight and actual-request behavior from these captures. Identify inconsistent authorization assumptions without treating preflight success as proof of access.

PROMPT 181

CSRF token binding

Review how anti-CSRF tokens bind to sessions or requests in the supplied code. Identify issuance, comparison and invalidation behavior.

PROMPT 182

Content-type CSRF boundary

Compare accepted content types for this action. Identify which browser-generated request forms reach the same handler and what validation applies.

PROMPT 183

Login CSRF assessment

Review the supplied login flow for account binding and anti-CSRF controls. Explain a controlled test using researcher-owned accounts and explicit user effects.

PROMPT 184

Logout CSRF impact

Assess this logout behavior under the program's criteria. Separate nuisance effects from demonstrated security consequences and avoid exaggerated severity.

PROMPT 185

CORS allowlist review

Audit the provided origin allowlist for wildcard, suffix and null-origin handling. Explain deployment-specific implications with synthetic examples.

PROMPT 186

Cross-subdomain trust

Map cookie scope and origin trust across these owned subdomains. Identify assumptions about sibling applications and the evidence needed to assess them.

PROMPT 187

Cookie path semantics

Explain how these cookie paths affect sending and visibility in the supplied application. Do not describe path scoping as a general isolation boundary.

PROMPT 188

Cookie name collision

Review captures containing duplicate cookie names with different paths or domains. Identify how the server selects values and where behavior is uncertain.

PROMPT 189

Referer fallback review

Analyze this CSRF control's use of Origin and Referer. Identify missing-header behavior and cases the application handles inconsistently.

PROMPT 190

State-changing GET review

Identify GET routes in the supplied code that change state. Explain their authentication and browser-triggering conditions before proposing a test.

PROMPT 191

Cross-site file upload

Review a file-upload flow's browser submission and CSRF checks. Limit the validation design to harmless files in a test account.

PROMPT 192

CORS cache behavior

Compare cached responses for different supplied origins. Identify whether cache variation preserves the intended origin-specific policy.

PROMPT 193

Credentials mode review

Trace browser fetch credentials settings through this client. Explain how they interact with cookies and CORS for each destination.

PROMPT 194

CSRF middleware coverage

Map state-changing routes to anti-CSRF middleware. Highlight exceptions and identify whether alternative protections are actually present.

PROMPT 195

Cookie expiration comparison

Compare cookie expiration with server session lifetime in these observations. Identify inconsistencies without assuming cookie deletion revokes a server session.

PROMPT 196

Subdomain cookie policy

Review host-only and domain-scoped cookies in this architecture. Propose narrower scope where it fits the documented login requirements.

PROMPT 197

CORS error triage

Diagnose this browser CORS error using the supplied network capture. Separate authentication failure, policy mismatch and server error causes.

PROMPT 198

CSRF proof review

Review this proof for a real state change under realistic browser conditions. Identify manually added headers or prerequisites that invalidate the claim.

PROMPT 199

Cross-site regression suite

Design regression tests for this CSRF fix across allowed and disallowed origins, missing tokens and expired sessions. Define an expected outcome for each.

PROMPT 200

Cookie policy summary

Summarize the supplied cookie security configuration by purpose, scope and lifetime. Flag unknown server behavior separately from header observations.

SSRF, redirects & integrations · 25 prompts
PROMPT 201

Outbound fetch inventory

Map server-side URL fetching in the supplied code. Record controllable URL components, allowed destinations and the component performing the request.

PROMPT 202

SSRF trust boundary

Analyze this URL-fetching feature's intended destinations and access privileges. Identify evidence needed to establish a server-side request beyond the intended boundary.

PROMPT 203

Redirect-following review

Review how the outbound client handles redirects. Identify whether destination restrictions are rechecked on each hop using local synthetic fixtures.

PROMPT 204

DNS resolution policy

Explain the supplied fetcher's resolution and connection sequence. Identify where destination validation and actual connection addresses could diverge.

PROMPT 205

URL allowlist implementation

Review this allowlist against parsed scheme, hostname and port. Propose local unit cases for ambiguous syntax without contacting external services.

PROMPT 206

Webhook destination review

Analyze webhook destination validation and update permissions. Identify how the application restricts destinations and handles redirection or failed delivery.

PROMPT 207

Image proxy review

Trace image URL processing from submission to fetch and storage. Identify content-type, size and destination controls in the supplied implementation.

PROMPT 208

PDF renderer resources

Review which external resources this document renderer can load. Map network access and local-file handling to the configured restrictions.

PROMPT 209

Import-from-URL flow

Analyze this import workflow's fetch, parse and storage stages. Identify which controls apply before retrieval and before processing returned content.

PROMPT 210

SSRF response classification

Interpret the supplied observations to distinguish server fetches, browser fetches, cached responses and validation errors. State confidence and missing evidence.

PROMPT 211

Callback evidence review

Review researcher-controlled callback logs for correlation with a permitted test. Require timestamps and unique markers before attributing the request to the target.

PROMPT 212

Outbound request minimization

Design a minimal validation using an approved researcher-controlled endpoint. Specify the expected observation and stop after proof without querying internal services.

PROMPT 213

Cloud metadata defense review

Review the supplied outbound network policy for protection of metadata and private address ranges. Focus on configuration and local tests, not credential retrieval.

PROMPT 214

Open redirect context

Assess whether this redirect is expected navigation or crosses a security-sensitive trust boundary. Identify user interaction and integration context from evidence.

PROMPT 215

Redirect parameter inventory

Extract redirect-related parameters from these captures. Classify login returns, payment callbacks and ordinary links by their intended destination rules.

PROMPT 216

OAuth return URL review

Compare allowed return URLs with the supplied redirect implementation. Identify whether account or authorization state is preserved across the transition.

PROMPT 217

Webhook signature validation

Review this webhook verifier for canonicalization, replay handling and constant-time comparison. Use synthetic signed events for local assertions.

PROMPT 218

Webhook replay policy

Analyze the provided event ID and timestamp handling. Propose controlled duplicate-event tests against a sandbox and define expected state changes.

PROMPT 219

Integration credential storage

Trace storage and retrieval of third-party credentials in this code. Identify encryption, access-control and logging questions without revealing secret values.

PROMPT 220

Integration disconnect behavior

Review how disconnection revokes access, cancels jobs and handles stored credentials. Identify lingering capabilities in the supplied lifecycle evidence.

PROMPT 221

Callback tenant binding

Trace callback state to the correct user and tenant. Identify checks preventing a valid callback from updating the wrong organization.

PROMPT 222

Outbound timeout policy

Assess timeout, redirect and response-size limits in this configuration. Suggest bounded local tests for graceful failure without service stress.

PROMPT 223

Redirect normalization tests

Create synthetic unit cases for relative paths, scheme-relative URLs, encoded separators and fragments in this redirect validator. State expected acceptance or rejection.

PROMPT 224

Integration error leakage

Inspect sanitized integration errors for credentials, internal URLs and tenant data. Separate developer diagnostics from information returned to users.

PROMPT 225

SSRF report precision

Review this suspected SSRF report for proof of server-side behavior and demonstrated impact. Remove assumptions about internal access that were not tested.

Files, uploads & paths · 25 prompts
PROMPT 226

Upload lifecycle map

Map validation, storage, preview, download and deletion for this upload feature. Identify where file identity and owner permissions are enforced.

PROMPT 227

Extension MIME consistency

Compare extension, declared MIME type and detected content handling in this code. Propose harmless local fixtures for inconsistent combinations.

PROMPT 228

Filename normalization

Review filename transformations before storage and download. Identify collisions, ambiguous Unicode and path-separator handling using synthetic names.

PROMPT 229

Download path resolution

Trace user input through path normalization and file access in the supplied handler. Identify the directory boundary and how it is enforced.

PROMPT 230

Archive extraction review

Review archive extraction code for destination containment, symbolic links and overwrite behavior. Design local tests using harmless synthetic files.

PROMPT 231

File preview isolation

Analyze how uploaded documents are previewed and which origin serves them. Identify script, cookie and access-control boundaries from the supplied configuration.

PROMPT 232

Image processing pipeline

Trace metadata stripping, decoding and output encoding for uploaded images. Identify validation stages and safe error-handling tests.

PROMPT 233

Signed download URL review

Review signed URL expiry, resource binding and audience assumptions. Compare the design with the documented sharing policy.

PROMPT 234

Attachment deletion semantics

Determine whether deleting an attachment removes stored content, metadata and preview artifacts. Design a controlled check using a file I uploaded.

PROMPT 235

Temporary file handling

Inspect temporary-file creation and cleanup in this code. Identify permissions, predictable naming and race assumptions without accessing system files.

PROMPT 236

Storage key ownership

Review how object storage keys are derived and authorized. Identify whether caller-supplied keys can select another tenant's synthetic record.

PROMPT 237

Document conversion boundary

Map file conversion subprocess inputs and outputs. Identify execution, network and filesystem restrictions in the supplied sandbox configuration.

PROMPT 238

CSV formula handling

Review spreadsheet export handling for cells beginning with formula-sensitive characters. Propose inert test data and verify the export's intended consumer behavior.

PROMPT 239

SVG handling review

Analyze SVG acceptance and rendering in this upload feature. Identify sanitization, embedding context and download behavior before assessing browser risk.

PROMPT 240

Multipart parser comparison

Compare multipart parsing at proxy and application layers from supplied traces. Identify differing filename and duplicate-field interpretations using local fixtures.

PROMPT 241

Large-file policy review

Review size checks across proxy, application and storage layers. Propose small boundary tests in a local environment instead of resource-exhaustion attempts.

PROMPT 242

Upload permission matrix

Build a role matrix for creating, replacing, viewing and deleting files. Include parent-object permissions and shared-link behavior.

PROMPT 243

Path traversal false positive

Review this path-related scanner alert. Distinguish reflected input, generic errors and actual access outside the intended directory.

PROMPT 244

Object overwrite assessment

Analyze replacement behavior for two files with matching names in my test account. Identify whether storage identity is separate from display name.

PROMPT 245

File content disposition

Review Content-Type and Content-Disposition for uploaded files. Explain how the supplied browser context affects rendering versus download behavior.

PROMPT 246

Backup artifact triage

Assess the supplied public artifact listing for actual sensitive content. Record minimal evidence and redact secrets without downloading unrelated archives.

PROMPT 247

Repository file exposure

Review these permitted directory responses for source or configuration exposure. Distinguish directory names from accessible contents and supported impact.

PROMPT 248

File retention review

Compare stated retention with test-file lifecycle observations. Identify whether derived previews or exports remain accessible after deletion.

PROMPT 249

Parser dependency review

Map file-processing dependencies in the supplied lockfile to their reachable use. Prioritize vendor advisory checks without assuming version alone proves exploitability.

PROMPT 250

File-handling regression suite

Convert this confirmed file-handling fix into tests for containment, ownership, normalization and cleanup using harmless local files.

Injection & parsing · 25 prompts
PROMPT 251

SQL query construction

Trace input into the supplied database query builder. Identify parameter binding, dynamic identifiers and string concatenation with exact source references.

PROMPT 252

Query parameterization review

Compare these two database access implementations. Explain which values are bound and which remain part of query syntax; avoid assuming ORM use guarantees safety.

PROMPT 253

Database error triage

Review sanitized database errors and their triggering inputs. Separate parser errors from proof of controllable query structure and identify missing confirmation evidence.

PROMPT 254

NoSQL filter construction

Analyze how request data becomes a database filter. Identify operator allowlists, type validation and unexpected object merging in the supplied code.

PROMPT 255

Search query escaping

Review this search backend's query construction. Distinguish literal user terms from permitted query syntax and identify escaping inconsistencies.

PROMPT 256

Command invocation review

Trace controllable values into subprocess calls. Distinguish argument arrays from shell interpretation and identify missing validation in supplied code.

PROMPT 257

Argument injection boundary

Review a subprocess argument list for user-controlled option positions. Propose local unit tests with benign values that verify option separation.

PROMPT 258

Template engine data flow

Map user-controlled values into template selection and rendering. Distinguish template data from executable template source and cite the relevant boundaries.

PROMPT 259

Expression evaluator review

Inspect the supplied expression evaluation feature for allowed grammar and accessible objects. Identify sandbox assumptions requiring local validation.

PROMPT 260

XML parser configuration

Review entity, DTD and network access settings in this XML parser. Propose local tests that confirm restrictions without reading sensitive files.

PROMPT 261

Deserialization entry points

Inventory deserialization calls in the supplied repository. Record format, trust source and validation controls; prioritize reachable untrusted inputs.

PROMPT 262

Unsafe type reconstruction

Review this object reconstruction logic for caller-selected types and constructors. Explain the security boundary and propose benign local fixtures.

PROMPT 263

Regular expression construction

Analyze dynamic regex construction for escaping and complexity concerns. Suggest bounded local examples that distinguish syntax errors from problematic matching behavior.

PROMPT 264

LDAP filter encoding

Review how user input enters this directory-search filter. Identify context-specific escaping and separate distinguished-name handling from filter syntax.

PROMPT 265

XPath query review

Trace input into XPath construction in the supplied code. Identify variables versus string-built expressions and recommend explicit local assertions.

PROMPT 266

Header value construction

Review user-controlled HTTP header values for newline handling and normalization. Compare application and proxy behavior using synthetic captured examples.

PROMPT 267

CSV parser ambiguity

Compare parser behavior on the supplied CSV fixtures. Identify discrepancies in quoting, delimiters and row boundaries that affect validation or authorization.

PROMPT 268

JSON duplicate keys

Analyze how each supplied component handles duplicate JSON keys. Identify inconsistent validation and processing interpretations with local fixtures.

PROMPT 269

Unicode normalization boundary

Trace normalization and comparison for this identifier field. Identify whether equivalent representations receive different validation or access decisions.

PROMPT 270

Integer conversion review

Review numeric parsing, range checks and downstream conversions in this code. Identify overflow, truncation and signedness assumptions with boundary unit cases.

PROMPT 271

Boolean coercion review

Compare validation and use of this boolean-like field. Identify strings, arrays or null values that change meaning across components.

PROMPT 272

Encoding pipeline analysis

Map decoding, normalization and escaping order for this input. Identify repeated transformations and explain which component ultimately interprets the result.

PROMPT 273

Injection finding challenge

Review this proposed injection finding for a reachable interpreter and controllable syntax. List alternative explanations and evidence that would disprove it.

PROMPT 274

Injection patch review

Evaluate this patch against the original data flow. Check whether it fixes the interpretation boundary or only blocks a small set of strings.

PROMPT 275

Parser regression corpus

Create a compact corpus of benign parser edge cases for this documented format. For each, state the expected normalized value or explicit rejection.

Business logic & workflows · 25 prompts
PROMPT 276

Checkout state model

Build a state diagram from these sandbox checkout captures. Identify required transitions, authoritative prices and conditions that must hold before order completion.

PROMPT 277

Coupon rule consistency

Compare coupon validation across preview and checkout in supplied code. Identify expiration, eligibility and combination rules that must remain consistent.

PROMPT 278

Quantity boundary review

Review quantity validation from request parsing through inventory and billing. Propose sandbox unit tests for zero, negative and boundary values.

PROMPT 279

Currency conversion review

Trace currency and minor-unit handling in this payment integration. Identify rounding and denomination assumptions without initiating financial transactions.

PROMPT 280

Refund state analysis

Review this refund workflow's authorization, amount limits and state transitions using synthetic examples. Distinguish application records from provider settlement state.

PROMPT 281

Subscription entitlement map

Map plan state to feature entitlements in the supplied code. Identify behavior during upgrade, cancellation, expiry and payment failure.

PROMPT 282

Trial eligibility review

Analyze trial eligibility decisions across registration and subscription state. Identify server-side enforcement and missing evidence without creating accounts at scale.

PROMPT 283

Referral accounting review

Trace referral credit issuance and reversal in the supplied implementation. Identify self-reference, duplicate-event and state-ordering questions in local tests.

PROMPT 284

Inventory reservation review

Model reservation, expiration and purchase transitions. Identify invariants that prevent overselling or abandoned reservations using sandbox fixtures.

PROMPT 285

Approval workflow analysis

Review this multi-stage approval process for role separation and required ordering. Identify whether later steps validate earlier approvals server-side.

PROMPT 286

Race condition hypothesis

Identify a concrete shared-state invariant in this workflow. Propose a bounded local concurrency test and the evidence needed to distinguish timing from normal behavior.

PROMPT 287

Duplicate submission handling

Review how repeated form or API submissions are deduplicated. Define expected behavior for identical requests and legitimate retries.

PROMPT 288

Partial failure recovery

Analyze this multi-service operation when one stage fails. Identify compensating actions and persistent states that could violate the documented business rule.

PROMPT 289

Client-supplied price review

Trace every price-related field in the supplied request to the authoritative calculation. Identify where server-side recomputation or verification occurs.

PROMPT 290

Entitlement cache review

Compare entitlement cache updates with billing events. Identify stale-access windows and propose controlled sandbox observations rather than assuming exploitability.

PROMPT 291

Invitation role selection

Review whether an inviter can assign roles beyond their own authority. Map UI choices to server-side constraints in supplied code.

PROMPT 292

Resource quota accounting

Analyze quota enforcement for create, clone, import and restore operations. Identify paths that update or bypass the same accounting mechanism.

PROMPT 293

Workflow cancellation

Review cancellation behavior while an asynchronous task is queued or running. Identify whether output access and resource cleanup remain consistent.

PROMPT 294

Time boundary testing

Design local tests around expiry timestamps and timezone handling for this offer. Specify inclusive versus exclusive boundaries and authoritative clock assumptions.

PROMPT 295

State replay assessment

Review whether a previously valid workflow token remains usable after completion. Use a sandbox transition model and define expected rejection conditions.

PROMPT 296

Gift credit lifecycle

Trace synthetic credit from issuance through transfer, redemption and revocation. Identify ownership and conservation invariants in the supplied design.

PROMPT 297

Approval notification mismatch

Compare the action described in an approval notice with the actual approved operation. Identify fields that could change between review and execution.

PROMPT 298

Business rule test table

Convert these product rules into a test table with prerequisites, action, expected state and prohibited outcome. Flag contradictory requirements.

PROMPT 299

Business impact grounding

Rewrite this logic-bug impact statement using only demonstrated state changes and documented pricing or entitlements. Remove invented financial loss estimates.

PROMPT 300

Workflow regression review

Check this patch against every entry point to the affected workflow. Include imports, bulk actions and background jobs where supplied evidence shows they exist.

Cloud, storage & deployment · 25 prompts
PROMPT 301

Bucket policy interpretation

Explain the supplied object storage policy by principal, action and resource. Identify public access and explicit restrictions without listing or retrieving stored objects.

PROMPT 302

Cloud identity permissions

Review this redacted identity policy for excessive actions and resources. Tie each concern to the described workload and propose a narrower permission set.

PROMPT 303

Presigned URL permissions

Analyze the supplied presigned URL generation code for resource ownership, action and expiry. Identify checks that must happen before signing.

PROMPT 304

Container configuration review

Review this container manifest for privileges, mounts and network exposure. Explain which settings matter in the described deployment context.

PROMPT 305

Kubernetes service exposure

Map the supplied service and ingress manifests to externally reachable routes. Identify authentication boundaries and distinguish intended exposure from configuration risk.

PROMPT 306

Secret injection lifecycle

Trace how deployment secrets reach the application. Identify logs, build artifacts and environment exports that could disclose them without printing values.

PROMPT 307

Public artifact review

Inspect this permitted build artifact manifest for accidentally included source, configuration or debug files. Identify minimal evidence needed for each concern.

PROMPT 308

CI workflow trust

Review pull-request and release workflows for untrusted input reaching privileged jobs. Identify event conditions, token scope and artifact trust assumptions.

PROMPT 309

Build cache isolation

Analyze how build cache keys and permissions separate projects and contributors. Identify whether untrusted jobs can influence trusted release outputs.

PROMPT 310

Infrastructure drift

Compare intended infrastructure configuration with the supplied observed inventory. List security-relevant deviations and evidence gaps without changing resources.

PROMPT 311

Log access permissions

Review who can read application and infrastructure logs in this policy. Identify whether logs contain data that exceeds those users' intended access.

PROMPT 312

Debug endpoint exposure

Assess supplied responses from debug or health endpoints. Distinguish routine health signals from sensitive configuration or runtime information.

PROMPT 313

TLS termination mapping

Map TLS termination across this documented proxy chain. Identify certificate validation and transport assumptions between each hop.

PROMPT 314

Proxy header trust

Review which forwarded headers the application trusts and which proxies can set them. Identify incorrect client-origin assumptions in supplied configuration.

PROMPT 315

Environment variable review

Classify variable names and redacted values from this deployment sample. Identify secrets, public configuration and values whose sensitivity requires context.

PROMPT 316

Storage listing impact

Evaluate this listing response against the intended access policy. Separate object-name disclosure from proof of readable contents or write access.

PROMPT 317

Cloud key exposure report

Prepare an evidence outline for a suspected exposed cloud key. Redact the key and avoid using it; identify owner notification and program-approved validation needs.

PROMPT 318

Serverless event permissions

Review event-source permissions and handler assumptions in this configuration. Identify whether event contents are authenticated and scoped to the correct resource.

PROMPT 319

Queue tenant isolation

Trace tenant identifiers through queue publication, consumption and result storage. Identify authorization checks lost at asynchronous boundaries.

PROMPT 320

Backup access controls

Review the supplied backup storage and restore permissions. Identify separation between reading backups and performing restoration operations.

PROMPT 321

CDN behavior review

Analyze the provided CDN rules for authentication, cache bypass and header forwarding. Identify differences from application expectations.

PROMPT 322

Deployment rollback review

Assess whether rollback restores vulnerable configuration or stale secrets using these release manifests. Propose verification steps after a rollback.

PROMPT 323

Observability data minimization

Review supplied logging statements and tracing attributes for credentials and personal data. Suggest redaction that preserves diagnostic usefulness.

PROMPT 324

Cloud finding context

Challenge this cloud misconfiguration claim against resource policy, reachability and intended audience. Identify missing evidence before assigning impact.

PROMPT 325

Configuration regression checks

Convert this confirmed configuration fix into automated assertions over manifests and policies. Include expected exceptions with documented justification.

Mobile & desktop clients · 25 prompts
PROMPT 326

Android manifest review

Review the supplied Android manifest for exported components, deep links and backup settings. Tie each concern to reachable behavior rather than flags alone.

PROMPT 327

iOS entitlement review

Explain the supplied iOS entitlements and their intended capabilities. Identify excessive permissions relative to the documented app features.

PROMPT 328

Deep-link routing

Trace these deep links into application actions. Identify parameter validation, authentication requirements and sensitive transitions from supplied source.

PROMPT 329

WebView navigation policy

Review allowed origins, JavaScript bridges and navigation handling in this WebView configuration. Identify trust boundaries with line references.

PROMPT 330

Mobile token storage

Analyze where this app stores session credentials and how they are accessed. Distinguish platform protections from application-level access assumptions.

PROMPT 331

Local cache sensitivity

Review the supplied cache schema for private records and logout cleanup. Propose tests with synthetic data on a researcher-controlled device.

PROMPT 332

Clipboard use review

Trace sensitive values copied to or read from the clipboard. Assess necessity and lifetime in the application's stated workflow.

PROMPT 333

Exported component permissions

Map exported Android components to their permission checks. Identify which actions are callable and what evidence would establish unauthorized effect.

PROMPT 334

Mobile API parity

Compare mobile and web requests for the same operation. Identify differences in validation, fields and server-side authorization.

PROMPT 335

Desktop IPC boundary

Review this desktop application's IPC handlers for sender validation and allowed operations. Identify untrusted input reaching privileged functionality.

PROMPT 336

Electron context isolation

Analyze the supplied Electron settings and preload bridge. Identify exposed capabilities and whether remote content can invoke them.

PROMPT 337

Update manifest validation

Review how this client validates update metadata and downloaded packages. Identify signature, origin and rollback checks from supplied code.

PROMPT 338

Custom protocol handling

Trace custom protocol input into local actions. Identify parsing, path and argument boundaries using benign local examples.

PROMPT 339

Local database permissions

Review access and encryption settings for the supplied app database. Identify which stored records need protection under the described threat model.

PROMPT 340

Mobile logging audit

Inspect sanitized mobile logs for tokens, identifiers and private content. Recommend targeted redaction without removing useful error context.

PROMPT 341

Biometric gate semantics

Review whether biometric approval protects a server operation or only hides local UI. Identify the backend evidence needed to assess the actual boundary.

PROMPT 342

Screenshot protection context

Assess the supplied sensitive-screen behavior against documented requirements. Separate platform limitations from a demonstrated data-exposure issue.

PROMPT 343

App link verification

Review app-link configuration and domain association files. Identify mismatches that affect intended routing without claiming domain ownership.

PROMPT 344

Mobile session lifecycle

Compare token refresh, logout and account switching in these captures. Identify stale data or identity confusion between researcher-controlled accounts.

PROMPT 345

Offline synchronization

Analyze conflict resolution and authorization during offline changes and later sync. Use synthetic records to identify security-relevant state transitions.

PROMPT 346

Push notification privacy

Review supplied push payloads and lock-screen behavior. Identify private fields and whether the content matches the application's privacy requirements.

PROMPT 347

Attachment sharing intents

Trace file sharing through platform intents or share sheets. Identify URI permissions, recipient scope and temporary access revocation.

PROMPT 348

Mobile backup review

Review which app files enter the supplied backup configuration. Identify sensitive records and the platform protections relevant to restoration.

PROMPT 349

Local privilege assumptions

Analyze this desktop feature's filesystem and process privileges. Identify operations that rely on an overly trusted local configuration source.

PROMPT 350

Client finding reproducibility

Review this mobile or desktop report for platform version, app build, account state and installation conditions needed to reproduce the result.

AI applications & agents · 25 prompts
PROMPT 351

Prompt trust boundary

Map system instructions, user input, retrieved documents and tool results in this AI application. Identify where untrusted content can influence privileged decisions.

PROMPT 352

RAG document access

Review retrieval authorization for the supplied design. Check whether tenant and user permissions apply before retrieval and again before displaying results.

PROMPT 353

Agent tool permissions

Build a permission matrix for this agent's tools. Separate read-only operations, reversible changes and actions requiring explicit user approval.

PROMPT 354

Indirect instruction handling

Design a synthetic document that tests whether quoted instructions are treated as data. Keep the test harmless and define the expected refusal to alter workflow.

PROMPT 355

Conversation tenant isolation

Review storage and retrieval of chat history across test tenants. Identify identifiers and access checks protecting each conversation.

PROMPT 356

Model output validation

Trace model-generated values into application actions. Identify schema validation, allowlists and human review before security-sensitive use.

PROMPT 357

Tool argument validation

Review the supplied tool schema and handler. Identify whether validation occurs server-side and how unexpected or missing fields are rejected.

PROMPT 358

Retrieval provenance

Evaluate how answers cite retrieved documents. Design a test using synthetic documents that distinguishes source-supported statements from unsupported generation.

PROMPT 359

Agent approval consistency

Compare the proposed action shown to the user with the action executed after approval. Identify parameters that could change between those stages.

PROMPT 360

Memory isolation

Review persistent agent memory keys and access controls. Identify separation among users, workspaces and organizations from the supplied code.

PROMPT 361

Secret handling in prompts

Review this prompt-building pipeline for accidental inclusion of credentials or private configuration. Suggest substitutions that preserve task context without exposing secrets.

PROMPT 362

AI log retention mapping

Map prompts, completions, tool calls and traces to storage destinations. Identify retention and access questions that the supplied documentation leaves unanswered.

PROMPT 363

Model endpoint selection

Review how this application selects model providers and base URLs. Identify whether untrusted input can redirect sensitive prompts to an unintended service.

PROMPT 364

Agent loop boundaries

Evaluate task duration, tool-call count and retry controls in this configuration. Propose bounded local tests for graceful termination.

PROMPT 365

Structured output failure

Design synthetic malformed model outputs for this parser. Verify that validation failures do not trigger partial or unintended application actions.

PROMPT 366

Cross-user embedding metadata

Review vector-store metadata filtering and collection separation. Identify where missing or caller-controlled tenant filters could affect retrieval.

PROMPT 367

AI finding scope review

Compare this proposed AI issue with the program's stated scope. Separate undesirable model text from a demonstrated application security boundary failure.

PROMPT 368

Tool result injection review

Analyze how tool output is inserted into the next model context. Identify delimiters, provenance and authority assumptions using supplied examples.

PROMPT 369

Agent file access boundaries

Review filesystem tool restrictions for an agent workspace. Propose harmless local fixtures that verify access remains within approved directories.

PROMPT 370

AI browser-action review

Map browser actions available to this assistant to approval and destination checks. Identify where page content could be mistaken for user authorization.

PROMPT 371

Evaluation dataset design

Create a small synthetic evaluation set for this documented AI security property. Include successful behavior, failure cases and clear scoring criteria.

PROMPT 372

Multi-turn state confusion

Review this conversation transcript for identity or task-state confusion. Identify the exact turn where assumptions changed and what evidence supports it.

PROMPT 373

Human review handoff

Design an agent handoff that preserves proposed action, destination, data and uncertainty. Ensure reviewers can approve a concrete action rather than a vague objective.

PROMPT 374

AI remediation assessment

Review this prompt-injection mitigation against the original trust boundary. Distinguish stronger instructions from enforceable tool and data access controls.

PROMPT 375

AI report evidence

Structure this AI application finding around reproducible inputs, tool actions and observed impact. Avoid relying solely on a provocative model response.

Source review & dependencies · 25 prompts
PROMPT 376

Controller middleware mapping

Map supplied routes through middleware to controllers. Identify authentication and authorization checks that apply to each handler, including explicit exceptions.

PROMPT 377

Data-flow inventory

Trace sensitive inputs through validation, transformation, storage and output in this module. Cite functions and separate confirmed flows from unresolved calls.

PROMPT 378

Dangerous API reachability

Review these flagged APIs for actual reachability from untrusted inputs. Explain required conditions before treating a static-analysis warning as actionable.

PROMPT 379

Validation reuse

Compare validators used by create, update and import paths. Identify inconsistent rules and whether the difference affects a security property.

PROMPT 380

Error handling source review

Trace exceptions from this service to user-visible responses and logs. Identify sensitive context that crosses the intended visibility boundary.

PROMPT 381

Dependency advisory context

Compare the supplied advisory with dependency version, configuration and reachable features. List prerequisites met, unmet and unknown without assuming version match proves impact.

PROMPT 382

Lockfile change triage

Review dependency changes in this lockfile diff. Prioritize security-relevant runtime changes and distinguish development-only dependencies.

PROMPT 383

Security patch diff

Explain which trust boundary this patch changes. Identify equivalent call sites and missing regression cases using only the supplied repository context.

PROMPT 384

Authorization helper review

Inspect this reusable permission helper for default behavior, null inputs and role hierarchy. Propose explicit local tests for denied cases.

PROMPT 385

Serialization field review

Compare database fields with serialized API output. Identify sensitive fields exposed by default or through nested objects.

PROMPT 386

Unsafe fallback review

Trace fallback behavior after authentication, parsing or dependency failures. Identify cases where errors broaden access or skip validation.

PROMPT 387

Configuration precedence

Explain how environment, file and request configuration values override each other. Identify security-sensitive settings influenced by less trusted sources.

PROMPT 388

Logging redaction review

Review these logging calls for secrets and private data. Propose field-level redaction while preserving correlation identifiers and error categories.

PROMPT 389

Test coverage gaps

Compare the supplied security fix with existing tests. Identify untested inputs, alternate routes and negative assertions that matter to the original issue.

PROMPT 390

Framework default assumptions

List security assumptions this code makes about framework defaults. Identify which must be verified against the installed version's official documentation.

PROMPT 391

Destructive helper review

Identify helpers that delete, replace or transfer resources. Trace their authorization and transaction boundaries before reviewing callers.

PROMPT 392

Transaction boundary review

Analyze this transaction's reads, writes and external side effects. Identify invariants that may fail if the transaction aborts or retries.

PROMPT 393

Concurrency source review

Inspect this shared-state code for locking and atomicity assumptions. Propose deterministic local tests rather than relying on repeated production requests.

PROMPT 394

Feature flag security review

Trace whether a feature flag changes only presentation or also server permissions. Identify unsafe assumptions when flags are missing or stale.

PROMPT 395

Secret scanner triage

Review these redacted secret-scanner matches for context and likely sensitivity. Identify public examples and placeholders separately; never attempt credential use.

PROMPT 396

Generated code review

Inspect generated client or server code for security-relevant defaults. Identify where regeneration could overwrite manual validation fixes.

PROMPT 397

Monorepo trust map

Map package boundaries and shared security helpers in this repository. Identify applications that use different versions or bypass common enforcement.

PROMPT 398

Migration security review

Review this data migration for permission, ownership and default-value changes. Identify post-migration invariants requiring validation.

PROMPT 399

Source evidence bundle

Prepare a compact source-review evidence bundle with relevant lines, call chain and unresolved context. Avoid including unrelated private code.

PROMPT 400

Fix location recommendation

Recommend the narrowest reliable location to enforce this security rule. Compare central middleware, service-layer checks and handler-specific validation with tradeoffs.

Caching, proxies & HTTP · 25 prompts
PROMPT 401

Cache key inventory

Derive the cache key from the supplied configuration. Identify request attributes that influence content but are absent from the key.

PROMPT 402

Authenticated response caching

Review how this cache handles authenticated responses. Identify user separation, cache-control directives and bypass rules from the supplied evidence.

PROMPT 403

Cache hit evidence

Compare these response captures for reliable cache-hit indicators. Distinguish intermediary reuse from application-generated identical content.

PROMPT 404

Vary header analysis

Explain whether the supplied Vary headers match content negotiation and origin-specific behavior. Identify mismatches using existing captures.

PROMPT 405

Cache invalidation lifecycle

Map invalidation after update, deletion and permission change. Identify stale-sensitive-content risks and a bounded test with researcher-owned data.

PROMPT 406

Reverse proxy normalization

Compare path and header normalization across the supplied proxy and application configuration. Identify disagreements suitable for isolated local tests.

PROMPT 407

Request framing review

Review this HTTP proxy chain's documented framing behavior. Identify ambiguous parsing assumptions and recommend a local harness rather than live desynchronization tests.

PROMPT 408

Host header trust

Trace use of the Host and forwarded-host values in links, redirects and routing. Identify where configured canonical origins should be authoritative.

PROMPT 409

Absolute URL generation

Review how this application generates reset and invitation links. Identify request-controlled origin components and the relevant validation.

PROMPT 410

Compression response review

Analyze whether compression settings interact with secret-bearing responses in this architecture. List prerequisites without claiming an attack from configuration alone.

PROMPT 411

HTTP method override

Review method override handling across proxy, middleware and routing. Identify whether authorization sees the same effective method as the handler.

PROMPT 412

Duplicate header interpretation

Compare how supplied components interpret repeated headers. Design local fixtures to identify differences without sending ambiguous requests to shared infrastructure.

PROMPT 413

Range request access

Review permission and caching behavior for partial-content downloads. Identify whether range responses enforce the same restrictions as full responses.

PROMPT 414

Conditional request privacy

Analyze ETag and conditional responses for user-specific resources. Identify whether validators reveal state across accounts in supplied observations.

PROMPT 415

Content negotiation boundary

Compare authenticated responses under supported content types and language settings. Identify whether alternate representations omit authorization or redaction.

PROMPT 416

Error response caching

Review whether application or proxy errors are cached and shared. Distinguish availability impact from sensitive response exposure.

PROMPT 417

Redirect cache behavior

Analyze caching of the supplied redirect responses. Identify destination variation and whether user-specific redirects can be reused incorrectly.

PROMPT 418

Canonical path comparison

Compare slash, case and encoded-path normalization in this local routing setup. Identify alternate paths that reach different middleware chains.

PROMPT 419

Trusted proxy configuration

Review the trusted-proxy list and deployment topology. Identify which clients can influence apparent IP, protocol or host values.

PROMPT 420

Rate-limit identity review

Analyze which identity forms the rate-limit key and how proxies affect it. Review configuration and local behavior without bypassing production controls.

PROMPT 421

Cache poisoning hypothesis review

Challenge this cache-poisoning hypothesis against cacheability, key influence and persistence evidence. Identify missing prerequisites before any program-approved validation.

PROMPT 422

Cache deception context

Review the supplied path and caching rules for disagreement about resource type. Use a researcher-owned synthetic page to define a minimal permitted check.

PROMPT 423

Protocol upgrade review

Map authentication and authorization across HTTP upgrade handling. Identify whether the upgraded connection inherits the intended session and origin checks.

PROMPT 424

Response splitting source review

Trace user-controlled data into raw HTTP response construction. Identify newline normalization and library protections from supplied source.

PROMPT 425

Proxy finding evidence

Review this proxy-related report for complete request path, protocol version and observed behavior. Separate parser speculation from reproducible application impact.

OAuth, tokens & cryptography · 25 prompts
PROMPT 426

OAuth flow mapping

Map the supplied authorization flow from initiation to session creation. Identify state, redirect URI, code exchange and account-binding checks.

PROMPT 427

State parameter lifecycle

Review state generation, storage, comparison and consumption in this OAuth implementation. Identify binding to the initiating browser and expected failure behavior.

PROMPT 428

PKCE implementation review

Trace verifier generation and challenge validation in supplied code. Identify where values are bound to the authorization transaction.

PROMPT 429

Redirect URI registration

Compare registered redirect URIs with runtime validation. Identify exact-match expectations and deployment exceptions that need documentation.

PROMPT 430

OAuth scope consent

Compare requested scopes with displayed consent and application use. Identify unnecessary permissions without assuming the provider grants every requested scope.

PROMPT 431

Refresh token rotation

Analyze token rotation and reuse handling from my test-account captures. Use token aliases and timestamps rather than exposing credentials.

PROMPT 432

Token audience validation

Review verification of issuer and audience in this token consumer. Identify whether validation matches the application's intended provider and resource.

PROMPT 433

JWT algorithm configuration

Review the permitted algorithms and key selection in supplied verification code. Identify reliance on untrusted token metadata and propose local negative tests.

PROMPT 434

Token expiry semantics

Compare issuance, expiration and clock-skew handling. Identify boundaries and distinguish server validation from client display of expiry.

PROMPT 435

Signing key rotation

Review key rotation and cache-refresh behavior in this design. Identify how retired keys and unknown key identifiers are handled.

PROMPT 436

Token type confusion

Compare validation paths for access, identity and refresh tokens. Identify whether each endpoint accepts only the intended token purpose.

PROMPT 437

OAuth account linking

Trace how external identities attach to local accounts. Identify verified-identity checks and handling of preexisting accounts with matching email addresses.

PROMPT 438

Consent revocation behavior

Plan a controlled test of access after revocation using my own integration. Distinguish local session state from provider token validity.

PROMPT 439

SAML assertion review

Review the supplied SAML validation configuration for issuer, audience, recipient and time conditions. Identify missing context before assessing security.

PROMPT 440

SAML request binding

Trace how a response is associated with its initiating request and browser session. Identify unsolicited-response behavior in the documented flow.

PROMPT 441

Cryptographic random use

Review security-sensitive identifier generation in this source. Distinguish unpredictable secrets from ordinary unique labels and identify the randomness API used.

PROMPT 442

Password hash configuration

Explain the supplied password hashing parameters and upgrade path. Identify where current vendor guidance should be checked rather than inventing universal settings.

PROMPT 443

Encryption key separation

Review how this design separates encryption keys, signing keys and application secrets. Identify reuse and access-control concerns within the supplied architecture.

PROMPT 444

Authenticated encryption handling

Trace encryption and decryption failures in this implementation. Identify nonce management and integrity checks without attempting to recover plaintext.

PROMPT 445

Signature canonicalization

Compare signed bytes with parsed webhook or API fields. Identify transformations that could cause verifier and consumer disagreement.

PROMPT 446

Token logging audit

Review logs and tracing configuration for bearer tokens and authorization codes. Propose redaction that keeps safe correlation information.

PROMPT 447

One-time token reuse

Design a controlled test for single-use tokens issued to my own account. Specify consumption, expiry and replay outcomes without accessing another account.

PROMPT 448

Cryptography claim review

Challenge this cryptographic finding against actual attacker capabilities and reachable code. Separate obsolete terminology from demonstrated weakness.

PROMPT 449

Token verification tests

Generate local negative tests for wrong issuer, audience, expiry, signature and token type. State the expected rejection reason for each.

PROMPT 450

Identity report precision

Rewrite this identity-related report to clearly distinguish authentication, authorization and account linking. Preserve only the demonstrated account-state changes.

Validation & evidence · 25 prompts
PROMPT 451

Finding hypothesis check

Restate this finding as a falsifiable security claim. List established facts, assumptions, missing observations and evidence that would contradict it.

PROMPT 452

Minimal reproduction

Reduce these reproduction steps to the smallest sequence that still demonstrates the issue. Preserve required state and remove unrelated actions.

PROMPT 453

Baseline comparison

Compare vulnerable and baseline captures while controlling account, object and session differences. Identify variables that prevent a valid comparison.

PROMPT 454

False-positive alternatives

Generate plausible non-vulnerable explanations for this observation. For each, identify a low-impact observation that could rule it out.

PROMPT 455

Evidence timeline

Create a timestamped timeline linking actions, request IDs, responses and state changes. Flag gaps and conflicting timestamps.

PROMPT 456

Synthetic data provenance

Verify that each object in this proof belongs to a researcher-controlled account. Identify missing creation evidence and ambiguous ownership.

PROMPT 457

Screenshot sufficiency

Review these screenshots for the information a triager needs. Identify missing context and data that should be redacted before submission.

PROMPT 458

Request redaction review

Redact credentials and personal data from this request while preserving method, structure and security-relevant relationships. Use consistent aliases across artifacts.

PROMPT 459

Response diff explanation

Explain the meaningful differences between these responses. Ignore volatile fields only when their irrelevance is justified by the hypothesis.

PROMPT 460

Reproducibility matrix

Build a matrix of tested roles, object states and client versions. Mark observed results separately from combinations that remain untested.

PROMPT 461

Impact prerequisite audit

List every prerequisite behind this impact statement. Identify which are demonstrated, attacker-controlled, victim-dependent or unknown.

PROMPT 462

Negative control design

Propose a negative control for this suspected vulnerability. Explain the expected difference if the security hypothesis is correct.

PROMPT 463

Positive control design

Identify a legitimate operation that confirms the test setup works. Use it to distinguish a protection from an unrelated environment failure.

PROMPT 464

Intermittent result analysis

Analyze these repeated observations for state and timing differences. Identify a deterministic reproduction hypothesis without increasing traffic blindly.

PROMPT 465

Scanner output validation

Review this scanner result against raw request and response evidence. Explain what it detects and what remains unproven.

PROMPT 466

Root cause versus symptom

Separate the observed symptom from possible underlying causes. Identify which source or behavioral evidence would support each cause.

PROMPT 467

Data exposure minimization

Determine the minimum synthetic or redacted evidence needed to show this disclosure. Avoid collecting additional records once the boundary failure is established.

PROMPT 468

Severity calibration

Assess severity using the supplied program framework and demonstrated impact. State uncertainty and avoid inventing access, scale or business consequences.

PROMPT 469

Duplicate root-cause comparison

Compare these two findings for shared root cause, affected boundary and remediation. Explain whether they may be distinct without deciding program policy.

PROMPT 470

Environment dependency

Identify configuration, feature flags and account history needed for this result. Separate universal behavior from environment-specific conditions.

PROMPT 471

Retest observation design

Plan a retest that confirms the original issue is fixed and normal behavior remains intact. Use the same controlled accounts and synthetic records.

PROMPT 472

Evidence contradiction review

Find contradictions between this narrative and attached artifacts. Quote the conflicting observations and suggest precise corrections.

PROMPT 473

Unconfirmed result wording

Rewrite this research note to clearly label unconfirmed behavior. Preserve useful evidence without presenting a hypothesis as a submitted vulnerability.

PROMPT 474

Validation handoff checklist

Prepare a validation handoff with prerequisites, safe test data, expected observations and stop conditions. Include unresolved questions explicitly.

PROMPT 475

Research completion review

Decide whether the provided evidence supports reporting, further validation or closing the hypothesis. Explain the decision and the single most important remaining gap.

Reporting, remediation & retesting · 25 prompts
PROMPT 476

Report title refinement

Write three concise titles naming the affected feature and demonstrated security consequence. Avoid severity adjectives that the evidence does not support.

PROMPT 477

Executive summary

Summarize this confirmed finding in three sentences: affected boundary, reproducible behavior and demonstrated impact. Keep technical details in the reproduction section.

PROMPT 478

Reproduction step editing

Rewrite these notes into numbered steps with prerequisites and expected observations. Do not invent commands, endpoints or results absent from the evidence.

PROMPT 479

Expected versus actual

Create an expected-versus-actual comparison for this finding. Tie expected behavior to documented permissions or a clearly stated security invariant.

PROMPT 480

Impact statement editing

Rewrite the impact section using only demonstrated capabilities and affected data. Mark scale and downstream consequences as unknown unless supported.

PROMPT 481

Proof-of-concept narration

Draft a concise narration for this permitted proof of concept. Explain each action and observed result without exposing credentials or unrelated records.

PROMPT 482

Artifact index

Build an artifact index linking each claim to its supporting request, response, screenshot or source excerpt. Flag claims with no supporting artifact.

PROMPT 483

Remediation options

Propose remediation at the violated trust boundary. Compare a primary fix with defense-in-depth measures and identify compatibility considerations.

PROMPT 484

Developer reproduction summary

Prepare a developer-focused reproduction using the supplied environment details and synthetic data. Highlight the handler or state transition most relevant to debugging.

PROMPT 485

Triage clarification response

Draft a factual response to these triage questions using existing evidence. Clearly identify questions requiring another authorized test; do not send the response.

PROMPT 486

Severity disagreement draft

Draft a respectful severity clarification tied to the program's framework and demonstrated impact. Avoid pressure, threats or unsupported payout arguments.

PROMPT 487

Duplicate clarification draft

Explain the technical differences between my finding and the described duplicate. Focus on root cause, affected boundary and remediation, acknowledging uncertainty.

PROMPT 488

Incomplete evidence checklist

Review this report for missing prerequisites, account roles, identifiers and observations. Prioritize gaps that prevent reproduction rather than cosmetic edits.

PROMPT 489

Remediation verification

Compare the supplied patch and retest results. Identify whether the original security property is enforced and whether alternate entry points were considered.

PROMPT 490

Regression test specification

Write a test specification with setup, action and assertions for this confirmed issue. Include a permitted success case and an unauthorized failure case.

PROMPT 491

Disclosure draft review

Review this proposed public write-up against the supplied disclosure approval. Identify private details and claims outside the approved scope.

PROMPT 492

Sensitive appendix cleanup

Redact the supplied appendix while preserving technical meaning. Maintain consistent aliases and list which evidence references changed.

PROMPT 493

Report language cleanup

Edit this report for concise professional language. Remove repetition, speculation and dramatic claims while preserving reproduction details and uncertainty.

PROMPT 494

Research note to report

Convert these validated notes into description, prerequisites, steps, evidence, impact and remediation. Put unresolved hypotheses in a separate section.

PROMPT 495

Fix bypass claim review

Review this claimed regression against the original fix and new observations. Identify whether it is the same root cause or a different behavior.

PROMPT 496

Retest failure explanation

Explain why this retest is inconclusive using the supplied environment differences. Identify the minimum missing prerequisite before another attempt.

PROMPT 497

Closure summary

Draft a closure summary recording confirmed impact, fix, retest outcome and remaining limitations. Avoid asserting complete security beyond the tested boundary.

PROMPT 498

Research lessons

Extract reusable methodological lessons from this completed investigation. Separate lessons supported by evidence from techniques that merely happened to work once.

PROMPT 499

Maintainer patch questions

Draft a short list of questions about this patch's intended security invariant and coverage. Focus on ambiguity that affects verification; do not send it.

PROMPT 500

Final submission review

Review the complete report for scope, reproducibility, evidence consistency and confidentiality. Return a concise correction list and identify any unsupported claim remaining.