Program brief extraction
Convert the supplied program brief into allowed assets, excluded assets, prohibited methods, account requirements and disclosure conditions. Quote the supporting passage for each entry; flag ambiguity.
UNLIMITED AI · PROMPT LIBRARY
Search 500 original bug bounty prompts across 20 categories: recon, authorization, APIs, code review, validation and reporting. Find a task and copy its prompt.
Browse 500 original bug bounty prompts for mapping attack surfaces, reviewing code, validating findings and writing clear vulnerability reports.
Choose a prompt, then attach the relevant sanitized brief, source code, captures or notes you are permitted to share. Each prompt specifies a concrete review task and expected output. These are research instructions, not prevalidated exploits or claims that a vulnerability exists.
Use only within your program’s authorization and data-sharing rules. Copy buttons include a short context instruction to preserve scope, distinguish facts from assumptions and avoid invented results. No API key or account is needed to browse this library.
500 prompts across 20 categories
Convert the supplied program brief into allowed assets, excluded assets, prohibited methods, account requirements and disclosure conditions. Quote the supporting passage for each entry; flag ambiguity.
Compare this hostname inventory against the written wildcard rules. Separate explicit matches, exclusions and uncertain ownership; do not infer authorization from a shared parent company.
Build a research schedule from my allowed hours and program restrictions. Allocate time to mapping, focused validation and evidence review, with stopping criteria for each phase.
Design the minimum test-account set for these roles and tenant boundaries. Identify which accounts and permissions I must obtain before comparing behavior.
Compare these two dated program briefs. List changes to assets, permitted methods, exclusions and reporting requirements, with a suggested update to my research checklist.
Review the supplied dependency and domain map. Distinguish first-party assets from hosted vendors and integrations; list ownership questions that must be resolved before active testing.
Extract automation and traffic restrictions from this brief. Turn them into explicit concurrency, delay, retry and stop settings, leaving unspecified values unresolved.
Rank these research questions by clarity, available evidence, authorized access and validation effort. Explain the ranking without guessing payout or severity.
Propose synthetic records for this workflow that cover relevant roles and object states. Explain how each record supports a specific authorization or integrity check.
Turn these scattered notes into one bounded research objective. State the security property, required observations, disconfirming evidence and what would end the investigation.
Map the supplied application workflow into services and trust boundaries. Mark which connections are observed, inferred or unknown and identify evidence needed to resolve uncertainty.
Draft a concise scope clarification from these conflicting rules. Ask only the questions necessary to determine whether the proposed test is permitted; do not send it.
Create a handling plan for these evidence types. Specify redaction, access controls, retention and deletion checkpoints consistent with the supplied program requirements.
Translate this risky production hypothesis into a local laboratory experiment. Preserve the suspected security property while replacing real accounts, secrets and services with synthetic equivalents.
Define explicit stop conditions for the proposed test, including unexpected access, service errors and data exposure. Connect each condition to a concrete observation.
Organize these screenshots and notes into user-facing features, account roles and sensitive transitions. Highlight unobserved areas without inventing endpoints.
Extract every assumption from this research plan. For each, explain how it affects validity and identify the smallest observation that could confirm or reject it.
Compare my proposed steps with the provided rules. Mark each permitted, prohibited or unclear, citing the relevant rule and suggesting a permitted alternative where possible.
Compare my idea with these public disclosed reports. Identify shared prerequisites and root causes; explain what evidence would demonstrate a distinct issue.
Design a first-pass review using supplied documentation and captures only. Prioritize unanswered security questions without initiating requests to the application.
List the prerequisites behind this hypothesis: role, tenant, object state, feature flag and session condition. Separate normal user capabilities from administrative privileges.
Turn my session notes into a handoff with scope, completed observations, unresolved hypotheses, artifact locations and next steps. Preserve failed attempts and uncertainty.
Build a chronological ledger from these notes. Separate actions, responses, interpretations and questions so later reviewers can reconstruct what actually happened.
Identify operations in this workflow that create commitments, delete records or affect other users. Propose harmless substitutes for research where feasible.
Create a one-hour plan for this single feature using the supplied materials. Limit the scope to three hypotheses and state what evidence each requires.
Merge these passive hostname exports, normalize names and preserve source attribution. Flag wildcard entries and stale observations instead of treating every name as a live asset.
Compare the supplied DNS snapshots. Identify changed records and unresolved names, separating configuration changes from evidence of a security issue.
Group certificate names by domain and observation date. Identify names worth checking against scope; do not infer current ownership or availability from a certificate alone.
Cluster these permitted HTTP probe results by title, status, technology clues and response similarity. Explain uncertainty where shared infrastructure could create misleading matches.
Inspect this collected redirect chain inventory. Identify cross-domain hops and ownership questions while preserving each original URL and final destination.
Analyze these baseline and candidate responses for wildcard behavior. Recommend comparison features beyond status code, including normalized body structure and headers.
Compare historical and current inventories. Mark newly observed, no-longer-observed and unchanged assets; distinguish absence of evidence from confirmed decommissioning.
Organize these public ownership clues into a dossier per host. Separate direct evidence from naming conventions and list unanswered scope questions.
Review the supplied technology fingerprints. Assign confidence from observed headers and content, and flag versions inferred solely from scanner heuristics.
Classify these assets as likely production, staging, development or unknown using supplied evidence. Explain why naming alone is insufficient to establish environment or authorization.
Review the supplied DNS and HTTP evidence for potentially dangling services. Identify missing ownership proof; do not provision or claim third-party resources.
Prioritize this in-scope host list by exposed application features and evidence gaps. Avoid treating an unusual port or product banner as a confirmed vulnerability.
Turn these application screenshots into a searchable inventory of functions, login boundaries and visible integrations. Retain the source URL for every observation.
Interpret these authorized scan results, distinguishing open services, filtered responses and uncertain fingerprints. Suggest low-impact verification questions rather than exploit attempts.
Review this architecture evidence for possible CDN and origin roles. List observations needed to distinguish them without probing unapproved infrastructure.
Normalize this mixed URL and hostname list while preserving internationalized names, ports and original values. Explain collisions introduced by normalization.
Audit my recon dataset for missing timestamps, sources and scope decisions. Produce a repair checklist so each asset can be traced to its evidence.
Group hosts that appear to serve the same application using the supplied captures. Preserve separate tenancy and ownership boundaries even when page content matches.
Extract paths from these supplied robots and sitemap files. Group by function, and explain why listing or exclusion does not establish authorization or sensitivity.
Map documented products and services to the supplied asset list. Flag undocumented relationships as hypotheses rather than expanding testing scope automatically.
Compare anomalous responses with their baselines. Identify likely login redirects, maintenance pages, bot challenges and genuinely different application content.
Review this candidate inventory and define explainable filters for duplicates, generic errors and irrelevant third-party assets. Preserve raw records for auditability.
Build a timeline from these dated DNS, certificate and HTTP records. Highlight where conclusions depend on gaps in observation.
Analyze these shared-IP observations. Explain what can and cannot be inferred about ownership, isolation and scope from co-location alone.
Summarize the supplied recon results into confirmed inventory, unresolved ownership and next authorized observations. Include counts with definitions and avoid inflated findings.
Extract endpoint references from the supplied JavaScript source. Preserve the containing function and distinguish literal routes, constructed paths and third-party URLs.
Build a parameter inventory from these captured requests. Record location, observed type, example shape and apparent purpose without exposing credential values.
Normalize these application routes for comparison while retaining method, version and parameter structure. Explain which routes must remain distinct for authorization analysis.
Review the supplied source-map contents for disclosed source structure and sensitive configuration references. Report exact locations with secrets redacted; do not use discovered credentials.
Compare client-side validation with the provided server handler. Identify rules enforced only in the client and the missing server evidence needed to assess impact.
Trace these feature flags through the supplied bundle. Distinguish presentation controls from server-side entitlements and identify the endpoint that enforces each permission.
Compare captured routes across API versions. Highlight changed authentication, fields and response structures without assuming an older version is insecure.
List fields referenced by the client but absent from the visible form. Explain their likely role and what server-side validation must be checked.
Trace how this function builds its URL, headers and body. Identify controllable inputs and encoding boundaries with line references.
Review these sanitized request URLs for data that should not appear in query strings or paths. Explain possible exposure surfaces without claiming observed leakage.
Classify these endpoint responses as application errors, gateway errors, authentication redirects or unknown. State which response details support each classification.
Inspect captured pagination requests for cursor, offset and limit semantics. Propose a small test-account comparison to verify consistent access boundaries across pages.
Map supplied filter and sort parameters to their server handlers. Identify validation and authorization questions for each supported operator.
Build a method-by-route matrix from the supplied API captures. Flag undocumented methods and missing captures rather than inventing supported operations.
Inventory local storage, session storage and IndexedDB usage visible in this source. Classify stored data and trace which code reads or writes it.
Compare these two JavaScript versions for new endpoints, permissions and sensitive flows. Focus on semantic changes rather than minification differences.
Map the scripts in this captured page to their origins and loaded functions. Identify data access questions and uncertainty about dynamically loaded code.
Organize these sanitized WebSocket frames by action and object identifier. Identify session establishment and per-message authorization questions.
Explain the supplied service worker's fetch handlers, caches and scope. Identify which authenticated responses could enter a shared or persistent cache.
Extract named operations and variables from these client files. Group by object and privilege boundary while keeping queries separate from mutations.
Trace upload, preview, download and deletion URLs from the provided captures. Identify differences in authentication and expiration across the lifecycle.
Classify suspected keys in this permitted source sample as public identifiers, test values or potentially sensitive credentials. Redact values and identify verification that does not use them.
Compare how these supplied URL parsing functions handle scheme, host, port and relative paths. Identify disagreements using synthetic examples only.
Compare the API specification with observed client requests. List missing routes, fields and security descriptions, with evidence references.
Turn these bundle findings into a short review queue ranked by reachable trust boundaries. Require a source reference and falsifiable question for every item.
Diagram the supplied login sequence from initial request to authenticated session. Identify where identity is verified, state is created and errors are returned.
Compare session identifiers before and after login in my test-account captures. Check rotation and invalidation evidence without exposing raw token values.
Design a bounded test using my own account to verify logout behavior across browser tabs and an existing API session. Define expected results per session type.
Review the supplied reset flow for token issuance, expiration, single use and account binding. Identify missing evidence without attempting other users' resets.
Map verification and session effects around an email change using supplied captures. Identify which address authorizes the transition and when the new identity becomes active.
Analyze this MFA enrollment and removal sequence. Identify required reauthentication, recovery handling and session-state changes from the evidence provided.
Review this recovery-code design for single use, storage and regeneration semantics. Propose controlled tests with codes generated for my test account.
Compare normal and persistent-login sessions using the supplied documentation and captures. Identify expiration, revocation and device-binding questions.
Review these redacted Set-Cookie headers against the described deployment. Explain the purpose and limitations of each flag in this specific flow.
Create a matrix for idle timeout, absolute lifetime and renewal based on these test observations. Distinguish frontend logout from server-side invalidation.
Compare stated session policy with my own-device observations. Identify whether logout and password changes revoke the expected sessions.
Locate sensitive operations in this workflow and identify evidence of recent-authentication checks. Separate a missing prompt from a demonstrated authorization failure.
Compare supplied login and recovery responses for observable differences. Identify benign explanations and the controlled evidence needed before claiming enumeration.
Trace how the supplied client and server code handle passwords. Identify logging, transport and storage concerns without retaining or displaying actual credentials.
Review how an invitation is bound to an account, organization and role. Check expiration and reuse semantics using only the supplied test-account evidence.
Map the identity checks used to link two login methods. Identify where email verification, existing-session ownership and explicit consent are required.
Explain the supplied application and identity-provider logout flows. Distinguish application session termination from upstream identity-provider session termination.
Review the provided device authorization sequence for user-code binding, expiration and approval context. Identify what the approving user can verify.
Inspect these sanitized authentication errors for sensitive internal details and inconsistent handling. Separate information exposure from ordinary diagnostic messages.
Compare registration, change and reset password validation in the supplied code. Identify inconsistent checks and their practical effect without guessing exploitability.
Evaluate this token storage approach against the application's browser threat model. Compare persistence, script access and cross-site request behavior.
Review the supplied magic-link implementation for intended account, expiration and consumption. Identify how redirects and preexisting sessions affect the flow.
Plan a controlled test for a disabled test account's existing sessions. Specify expected behavior for interactive requests, refresh operations and background jobs.
Convert this confirmed authentication fix into regression cases covering success, failure, expiration and replay. Each case must state its observable assertion.
Summarize these session tests with timestamps, account states and token aliases. Identify which conclusions are proven and which require additional observation.
Build a permission matrix for these objects using two researcher-controlled accounts. Separate owner, same-tenant peer and different-tenant access expectations.
Compare the supplied read and update handlers for the same resource. Identify whether both enforce the same object and tenant boundaries.
Review how this endpoint validates parent and child identifiers. Determine whether the relationship is checked server-side and cite the relevant code.
Inspect this batch handler for per-item authorization. Design a minimal test with owned synthetic records and explicit permitted versus denied outcomes.
Review test captures before and after a role downgrade. Identify stale permissions in sessions, cached responses and asynchronous operations.
Trace organization selection through the supplied requests. Identify which values choose the tenant and where the server verifies membership.
Map the permissions used to request, generate and download an export. Check that each stage binds the artifact to the authorized requester.
Compare search responses for controlled accounts with different access. Identify whether counts, snippets or suggestions expose records outside the permitted set.
Review attachment metadata and download handlers. Identify whether access follows the parent resource's permissions throughout preview and download flows.
Analyze access to synthetic soft-deleted objects under the supplied retention policy. Distinguish authorized recovery from unintended continued visibility.
Review this administrative handler and its middleware chain. Identify the server-side privilege requirement and whether every route reaches that check.
Compare allowed fields across the supplied roles. Identify fields returned or accepted beyond the role's documented rights and specify minimal validation evidence.
Review this shared-link design for audience, expiry and revocation. Distinguish intentional bearer access from a broken access-control claim.
Trace job creation, status polling and output retrieval. Identify how the requester and tenant are bound at every stage.
Design a controlled check for removed-member access to existing projects, links and sessions. Use only artifacts created for the test.
Review whether this handler trusts a tenant identifier from the request or derives it from verified membership. Cite the decision point and unresolved context.
Map inherited permissions across this folder or project hierarchy. Identify exceptions, overrides and expected behavior after moving a resource.
Compare service-account scopes with endpoint requirements from the supplied documentation. Identify overbroad privileges and missing enforcement evidence.
Review whether notification content and destinations honor current resource access. Consider removed members and changed sharing settings using synthetic records.
Compare audit-log access across controlled roles and tenants. Distinguish required administrative visibility from unintended cross-tenant disclosure.
Review edit and delete permissions for comments in the supplied workflow. Separate comment-author rights from parent-resource and moderator permissions.
Analyze this permission cache design around membership changes. Identify invalidation paths and a bounded test that can distinguish stale authorization from stale display.
Map alternative paths to the same object through REST, GraphQL and exports. Compare authorization checks without assuming one path inherits another's protections.
Challenge this suspected authorization finding. Identify legitimate sharing or role rules that could explain the behavior and the evidence that rules them out.
Review this authorization report for clear account ownership, role separation and object provenance. Remove claims unsupported by the provided comparison.
Review the supplied OpenAPI document for authentication declarations, sensitive operations and inconsistent security overrides. Distinguish specification gaps from verified server behavior.
Map each supplied GraphQL resolver to its authorization check and data source. Identify fields whose checks differ from the parent object's checks.
Compare these response fields with the feature's stated needs. Identify unnecessary sensitive fields and the evidence required to establish unauthorized exposure.
Trace request fields into this model update. Identify explicit allowlists, protected attributes and unexpected binding behavior using the supplied source.
Design a controlled comparison of this mutation across my test roles. State object ownership, expected denial and the smallest synthetic state change.
Review the supplied handshake flow for identity establishment and origin handling. Separate handshake checks from later message-level permissions.
Plan a controlled test of an existing socket after session expiry or logout. Specify expected behavior for reads and state-changing messages.
Compare these API specification versions for changed field types, required values and security declarations. Prioritize changes affecting trust boundaries.
Inspect these sanitized GraphQL errors for internal paths, query details and sensitive values. Explain what is actually disclosed and avoid speculative impact.
Compare supplied handlers for JSON, form and multipart requests. Identify differences in validation and authorization caused by parsing paths.
Review cursor ownership and access checks in this resolver. Propose test-account observations that separate cursor tampering from ordinary invalid-cursor handling.
Map documented API key scopes to captured endpoint behavior. Identify missing tests for narrower scopes without using credentials outside my account.
Trace webhook registration, update and deletion permissions in this code. Identify whether destination and event scope are bound to the correct tenant.
Assess the supplied deprecated API routes for continued authentication and validation parity. Treat continued availability alone as an observation, not a vulnerability.
Review query-cost accounting for aliases and repeated fields in a local configuration. Suggest bounded unit tests rather than high-volume production queries.
Explain how this API batch handles mixed success, failure and authorization. Identify whether denied items can affect allowed items' state.
Review how idempotency keys are associated with user, route and request body. Identify collisions or reuse questions using synthetic operations.
Compare status codes and response bodies for documented API outcomes. Identify client assumptions that could cause a security-sensitive misinterpretation.
Review default authorization behavior when middleware or scope annotations are absent. Cite the supplied framework configuration and affected routes.
Explain what the supplied schema reveals and what it does not prove. Identify sensitive operations worth reviewing within scope without labeling introspection itself a finding.
Trace authorization for GraphQL subscriptions at registration and event delivery. Identify how later permission changes affect existing subscribers.
Review caching around this authenticated API response. Identify which user, tenant and permission attributes form the cache key.
Analyze optional expand or include parameters in these captures. Check whether related objects preserve their own access restrictions.
Review this API client's retry policy against non-idempotent operations. Identify duplicate-action risks and propose local tests with explicit assertions.
Compare a claimed API weakness with the request, response and state evidence. List unsupported assumptions and the minimum missing observation.
Trace this supplied browser code from controllable input to DOM writes. Identify encoding and sanitization boundaries with line references and reachable conditions.
Classify each reflected value in these sanitized responses by HTML, attribute, URL or script context. Explain which contextual protections must be reviewed.
Map where this user-authored content is rendered across views and roles. Identify inconsistent sanitization using supplied templates and synthetic examples.
Review this sanitizer configuration against the application's permitted markup. Identify risky allowances and propose harmless regression inputs for a local test suite.
Explain this Content Security Policy in the context of the supplied page. Distinguish effective restrictions, report-only settings and unsupported assumptions.
Review the provided Trusted Types policies and DOM call sites. Identify uncovered sinks and whether policy functions actually validate their inputs.
Analyze this message listener for origin, source and message-shape checks. Trace sensitive operations reached after validation using the supplied code.
Review how this code selects a destination window and target origin. Identify whether sensitive content could reach an unintended recipient.
Inspect the supplied code for reliance on named DOM properties. Explain possible identifier collisions and propose a local, non-executing reproduction fixture.
Trace this client-side redirect function from input to navigation. Identify validation boundaries and distinguish intentional external links from trust-sensitive redirects.
Review permitted URL schemes for these link and media fields. Identify inconsistent normalization and propose safe unit tests for rejected schemes.
Compare raw HTML handling, link sanitization and image processing in this markdown pipeline. Identify differences between preview and saved rendering.
Review these templates for automatic escaping and explicit unescaped output. Map each exception to its input source and intended content type.
Explain which scripts can access the data stored by this page. Identify sensitive values and distinguish storage choice from a demonstrated script-execution issue.
Analyze this iframe's sandbox and permission attributes. Explain the capabilities granted and whether they match the embedded content's intended role.
Review external navigation and opener relationships in this code. Identify where an untrusted destination could retain a reference to the original window.
Trace the supplied caching rules for authenticated pages. Identify user separation, logout invalidation and stale sensitive-response concerns.
Review object merges and property lookups in this code for unsafe inherited-property behavior. Propose local assertions using benign synthetic objects.
Analyze this dynamic style construction for controllable values and validation. Distinguish cosmetic influence from evidence of a security-sensitive consequence.
Review this scanner result and response context. Determine whether input reaches executable interpretation or remains safely encoded, and list missing evidence.
Plan minimal screenshots and request captures for this confirmed browser issue. Exclude credentials and unrelated user data while preserving context.
Compare rendering of the same synthetic record in list, detail, admin and notification views. Identify which contexts require separate encoding review.
Review whether hidden routes rely solely on frontend checks. Identify the corresponding server-side authorization evidence needed before claiming a bypass.
Convert this escaping fix into tests for all affected output contexts. Include normal content and edge cases without assuming one encoding fits every sink.
Rewrite this browser-security impact statement to match the demonstrated origin, user interaction and accessible data. Remove unsupported account-takeover claims.
Analyze this state-changing request for authentication transport, browser reachability and anti-CSRF checks. Identify which prerequisites are established by the supplied capture.
Explain how the supplied cookie settings interact with these navigation and request flows. Identify tests needed across the relevant browser contexts.
Review this origin-validation function for exact parsing and comparison behavior. Use synthetic origins to identify normalization mistakes in local tests.
Interpret these CORS headers alongside credential mode and response sensitivity. Distinguish permissive public data from authenticated data exposure.
Compare preflight and actual-request behavior from these captures. Identify inconsistent authorization assumptions without treating preflight success as proof of access.
Review how anti-CSRF tokens bind to sessions or requests in the supplied code. Identify issuance, comparison and invalidation behavior.
Compare accepted content types for this action. Identify which browser-generated request forms reach the same handler and what validation applies.
Review the supplied login flow for account binding and anti-CSRF controls. Explain a controlled test using researcher-owned accounts and explicit user effects.
Assess this logout behavior under the program's criteria. Separate nuisance effects from demonstrated security consequences and avoid exaggerated severity.
Audit the provided origin allowlist for wildcard, suffix and null-origin handling. Explain deployment-specific implications with synthetic examples.
Map cookie scope and origin trust across these owned subdomains. Identify assumptions about sibling applications and the evidence needed to assess them.
Explain how these cookie paths affect sending and visibility in the supplied application. Do not describe path scoping as a general isolation boundary.
Review captures containing duplicate cookie names with different paths or domains. Identify how the server selects values and where behavior is uncertain.
Analyze this CSRF control's use of Origin and Referer. Identify missing-header behavior and cases the application handles inconsistently.
Identify GET routes in the supplied code that change state. Explain their authentication and browser-triggering conditions before proposing a test.
Review a file-upload flow's browser submission and CSRF checks. Limit the validation design to harmless files in a test account.
Compare cached responses for different supplied origins. Identify whether cache variation preserves the intended origin-specific policy.
Trace browser fetch credentials settings through this client. Explain how they interact with cookies and CORS for each destination.
Map state-changing routes to anti-CSRF middleware. Highlight exceptions and identify whether alternative protections are actually present.
Compare cookie expiration with server session lifetime in these observations. Identify inconsistencies without assuming cookie deletion revokes a server session.
Review host-only and domain-scoped cookies in this architecture. Propose narrower scope where it fits the documented login requirements.
Diagnose this browser CORS error using the supplied network capture. Separate authentication failure, policy mismatch and server error causes.
Review this proof for a real state change under realistic browser conditions. Identify manually added headers or prerequisites that invalidate the claim.
Design regression tests for this CSRF fix across allowed and disallowed origins, missing tokens and expired sessions. Define an expected outcome for each.
Summarize the supplied cookie security configuration by purpose, scope and lifetime. Flag unknown server behavior separately from header observations.
Map server-side URL fetching in the supplied code. Record controllable URL components, allowed destinations and the component performing the request.
Analyze this URL-fetching feature's intended destinations and access privileges. Identify evidence needed to establish a server-side request beyond the intended boundary.
Review how the outbound client handles redirects. Identify whether destination restrictions are rechecked on each hop using local synthetic fixtures.
Explain the supplied fetcher's resolution and connection sequence. Identify where destination validation and actual connection addresses could diverge.
Review this allowlist against parsed scheme, hostname and port. Propose local unit cases for ambiguous syntax without contacting external services.
Analyze webhook destination validation and update permissions. Identify how the application restricts destinations and handles redirection or failed delivery.
Trace image URL processing from submission to fetch and storage. Identify content-type, size and destination controls in the supplied implementation.
Review which external resources this document renderer can load. Map network access and local-file handling to the configured restrictions.
Analyze this import workflow's fetch, parse and storage stages. Identify which controls apply before retrieval and before processing returned content.
Interpret the supplied observations to distinguish server fetches, browser fetches, cached responses and validation errors. State confidence and missing evidence.
Review researcher-controlled callback logs for correlation with a permitted test. Require timestamps and unique markers before attributing the request to the target.
Design a minimal validation using an approved researcher-controlled endpoint. Specify the expected observation and stop after proof without querying internal services.
Review the supplied outbound network policy for protection of metadata and private address ranges. Focus on configuration and local tests, not credential retrieval.
Assess whether this redirect is expected navigation or crosses a security-sensitive trust boundary. Identify user interaction and integration context from evidence.
Extract redirect-related parameters from these captures. Classify login returns, payment callbacks and ordinary links by their intended destination rules.
Compare allowed return URLs with the supplied redirect implementation. Identify whether account or authorization state is preserved across the transition.
Review this webhook verifier for canonicalization, replay handling and constant-time comparison. Use synthetic signed events for local assertions.
Analyze the provided event ID and timestamp handling. Propose controlled duplicate-event tests against a sandbox and define expected state changes.
Trace storage and retrieval of third-party credentials in this code. Identify encryption, access-control and logging questions without revealing secret values.
Review how disconnection revokes access, cancels jobs and handles stored credentials. Identify lingering capabilities in the supplied lifecycle evidence.
Trace callback state to the correct user and tenant. Identify checks preventing a valid callback from updating the wrong organization.
Assess timeout, redirect and response-size limits in this configuration. Suggest bounded local tests for graceful failure without service stress.
Create synthetic unit cases for relative paths, scheme-relative URLs, encoded separators and fragments in this redirect validator. State expected acceptance or rejection.
Inspect sanitized integration errors for credentials, internal URLs and tenant data. Separate developer diagnostics from information returned to users.
Review this suspected SSRF report for proof of server-side behavior and demonstrated impact. Remove assumptions about internal access that were not tested.
Map validation, storage, preview, download and deletion for this upload feature. Identify where file identity and owner permissions are enforced.
Compare extension, declared MIME type and detected content handling in this code. Propose harmless local fixtures for inconsistent combinations.
Review filename transformations before storage and download. Identify collisions, ambiguous Unicode and path-separator handling using synthetic names.
Trace user input through path normalization and file access in the supplied handler. Identify the directory boundary and how it is enforced.
Review archive extraction code for destination containment, symbolic links and overwrite behavior. Design local tests using harmless synthetic files.
Analyze how uploaded documents are previewed and which origin serves them. Identify script, cookie and access-control boundaries from the supplied configuration.
Trace metadata stripping, decoding and output encoding for uploaded images. Identify validation stages and safe error-handling tests.
Review signed URL expiry, resource binding and audience assumptions. Compare the design with the documented sharing policy.
Determine whether deleting an attachment removes stored content, metadata and preview artifacts. Design a controlled check using a file I uploaded.
Inspect temporary-file creation and cleanup in this code. Identify permissions, predictable naming and race assumptions without accessing system files.
Review how object storage keys are derived and authorized. Identify whether caller-supplied keys can select another tenant's synthetic record.
Map file conversion subprocess inputs and outputs. Identify execution, network and filesystem restrictions in the supplied sandbox configuration.
Review spreadsheet export handling for cells beginning with formula-sensitive characters. Propose inert test data and verify the export's intended consumer behavior.
Analyze SVG acceptance and rendering in this upload feature. Identify sanitization, embedding context and download behavior before assessing browser risk.
Compare multipart parsing at proxy and application layers from supplied traces. Identify differing filename and duplicate-field interpretations using local fixtures.
Review size checks across proxy, application and storage layers. Propose small boundary tests in a local environment instead of resource-exhaustion attempts.
Build a role matrix for creating, replacing, viewing and deleting files. Include parent-object permissions and shared-link behavior.
Review this path-related scanner alert. Distinguish reflected input, generic errors and actual access outside the intended directory.
Analyze replacement behavior for two files with matching names in my test account. Identify whether storage identity is separate from display name.
Review Content-Type and Content-Disposition for uploaded files. Explain how the supplied browser context affects rendering versus download behavior.
Assess the supplied public artifact listing for actual sensitive content. Record minimal evidence and redact secrets without downloading unrelated archives.
Review these permitted directory responses for source or configuration exposure. Distinguish directory names from accessible contents and supported impact.
Compare stated retention with test-file lifecycle observations. Identify whether derived previews or exports remain accessible after deletion.
Map file-processing dependencies in the supplied lockfile to their reachable use. Prioritize vendor advisory checks without assuming version alone proves exploitability.
Convert this confirmed file-handling fix into tests for containment, ownership, normalization and cleanup using harmless local files.
Trace input into the supplied database query builder. Identify parameter binding, dynamic identifiers and string concatenation with exact source references.
Compare these two database access implementations. Explain which values are bound and which remain part of query syntax; avoid assuming ORM use guarantees safety.
Review sanitized database errors and their triggering inputs. Separate parser errors from proof of controllable query structure and identify missing confirmation evidence.
Analyze how request data becomes a database filter. Identify operator allowlists, type validation and unexpected object merging in the supplied code.
Review this search backend's query construction. Distinguish literal user terms from permitted query syntax and identify escaping inconsistencies.
Trace controllable values into subprocess calls. Distinguish argument arrays from shell interpretation and identify missing validation in supplied code.
Review a subprocess argument list for user-controlled option positions. Propose local unit tests with benign values that verify option separation.
Map user-controlled values into template selection and rendering. Distinguish template data from executable template source and cite the relevant boundaries.
Inspect the supplied expression evaluation feature for allowed grammar and accessible objects. Identify sandbox assumptions requiring local validation.
Review entity, DTD and network access settings in this XML parser. Propose local tests that confirm restrictions without reading sensitive files.
Inventory deserialization calls in the supplied repository. Record format, trust source and validation controls; prioritize reachable untrusted inputs.
Review this object reconstruction logic for caller-selected types and constructors. Explain the security boundary and propose benign local fixtures.
Analyze dynamic regex construction for escaping and complexity concerns. Suggest bounded local examples that distinguish syntax errors from problematic matching behavior.
Review how user input enters this directory-search filter. Identify context-specific escaping and separate distinguished-name handling from filter syntax.
Trace input into XPath construction in the supplied code. Identify variables versus string-built expressions and recommend explicit local assertions.
Review user-controlled HTTP header values for newline handling and normalization. Compare application and proxy behavior using synthetic captured examples.
Compare parser behavior on the supplied CSV fixtures. Identify discrepancies in quoting, delimiters and row boundaries that affect validation or authorization.
Analyze how each supplied component handles duplicate JSON keys. Identify inconsistent validation and processing interpretations with local fixtures.
Trace normalization and comparison for this identifier field. Identify whether equivalent representations receive different validation or access decisions.
Review numeric parsing, range checks and downstream conversions in this code. Identify overflow, truncation and signedness assumptions with boundary unit cases.
Compare validation and use of this boolean-like field. Identify strings, arrays or null values that change meaning across components.
Map decoding, normalization and escaping order for this input. Identify repeated transformations and explain which component ultimately interprets the result.
Review this proposed injection finding for a reachable interpreter and controllable syntax. List alternative explanations and evidence that would disprove it.
Evaluate this patch against the original data flow. Check whether it fixes the interpretation boundary or only blocks a small set of strings.
Create a compact corpus of benign parser edge cases for this documented format. For each, state the expected normalized value or explicit rejection.
Build a state diagram from these sandbox checkout captures. Identify required transitions, authoritative prices and conditions that must hold before order completion.
Compare coupon validation across preview and checkout in supplied code. Identify expiration, eligibility and combination rules that must remain consistent.
Review quantity validation from request parsing through inventory and billing. Propose sandbox unit tests for zero, negative and boundary values.
Trace currency and minor-unit handling in this payment integration. Identify rounding and denomination assumptions without initiating financial transactions.
Review this refund workflow's authorization, amount limits and state transitions using synthetic examples. Distinguish application records from provider settlement state.
Map plan state to feature entitlements in the supplied code. Identify behavior during upgrade, cancellation, expiry and payment failure.
Analyze trial eligibility decisions across registration and subscription state. Identify server-side enforcement and missing evidence without creating accounts at scale.
Trace referral credit issuance and reversal in the supplied implementation. Identify self-reference, duplicate-event and state-ordering questions in local tests.
Model reservation, expiration and purchase transitions. Identify invariants that prevent overselling or abandoned reservations using sandbox fixtures.
Review this multi-stage approval process for role separation and required ordering. Identify whether later steps validate earlier approvals server-side.
Identify a concrete shared-state invariant in this workflow. Propose a bounded local concurrency test and the evidence needed to distinguish timing from normal behavior.
Review how repeated form or API submissions are deduplicated. Define expected behavior for identical requests and legitimate retries.
Analyze this multi-service operation when one stage fails. Identify compensating actions and persistent states that could violate the documented business rule.
Trace every price-related field in the supplied request to the authoritative calculation. Identify where server-side recomputation or verification occurs.
Compare entitlement cache updates with billing events. Identify stale-access windows and propose controlled sandbox observations rather than assuming exploitability.
Review whether an inviter can assign roles beyond their own authority. Map UI choices to server-side constraints in supplied code.
Analyze quota enforcement for create, clone, import and restore operations. Identify paths that update or bypass the same accounting mechanism.
Review cancellation behavior while an asynchronous task is queued or running. Identify whether output access and resource cleanup remain consistent.
Design local tests around expiry timestamps and timezone handling for this offer. Specify inclusive versus exclusive boundaries and authoritative clock assumptions.
Review whether a previously valid workflow token remains usable after completion. Use a sandbox transition model and define expected rejection conditions.
Trace synthetic credit from issuance through transfer, redemption and revocation. Identify ownership and conservation invariants in the supplied design.
Compare the action described in an approval notice with the actual approved operation. Identify fields that could change between review and execution.
Convert these product rules into a test table with prerequisites, action, expected state and prohibited outcome. Flag contradictory requirements.
Rewrite this logic-bug impact statement using only demonstrated state changes and documented pricing or entitlements. Remove invented financial loss estimates.
Check this patch against every entry point to the affected workflow. Include imports, bulk actions and background jobs where supplied evidence shows they exist.
Explain the supplied object storage policy by principal, action and resource. Identify public access and explicit restrictions without listing or retrieving stored objects.
Review this redacted identity policy for excessive actions and resources. Tie each concern to the described workload and propose a narrower permission set.
Analyze the supplied presigned URL generation code for resource ownership, action and expiry. Identify checks that must happen before signing.
Review this container manifest for privileges, mounts and network exposure. Explain which settings matter in the described deployment context.
Map the supplied service and ingress manifests to externally reachable routes. Identify authentication boundaries and distinguish intended exposure from configuration risk.
Trace how deployment secrets reach the application. Identify logs, build artifacts and environment exports that could disclose them without printing values.
Inspect this permitted build artifact manifest for accidentally included source, configuration or debug files. Identify minimal evidence needed for each concern.
Review pull-request and release workflows for untrusted input reaching privileged jobs. Identify event conditions, token scope and artifact trust assumptions.
Analyze how build cache keys and permissions separate projects and contributors. Identify whether untrusted jobs can influence trusted release outputs.
Compare intended infrastructure configuration with the supplied observed inventory. List security-relevant deviations and evidence gaps without changing resources.
Review who can read application and infrastructure logs in this policy. Identify whether logs contain data that exceeds those users' intended access.
Assess supplied responses from debug or health endpoints. Distinguish routine health signals from sensitive configuration or runtime information.
Map TLS termination across this documented proxy chain. Identify certificate validation and transport assumptions between each hop.
Review which forwarded headers the application trusts and which proxies can set them. Identify incorrect client-origin assumptions in supplied configuration.
Classify variable names and redacted values from this deployment sample. Identify secrets, public configuration and values whose sensitivity requires context.
Evaluate this listing response against the intended access policy. Separate object-name disclosure from proof of readable contents or write access.
Prepare an evidence outline for a suspected exposed cloud key. Redact the key and avoid using it; identify owner notification and program-approved validation needs.
Review event-source permissions and handler assumptions in this configuration. Identify whether event contents are authenticated and scoped to the correct resource.
Trace tenant identifiers through queue publication, consumption and result storage. Identify authorization checks lost at asynchronous boundaries.
Review the supplied backup storage and restore permissions. Identify separation between reading backups and performing restoration operations.
Analyze the provided CDN rules for authentication, cache bypass and header forwarding. Identify differences from application expectations.
Assess whether rollback restores vulnerable configuration or stale secrets using these release manifests. Propose verification steps after a rollback.
Review supplied logging statements and tracing attributes for credentials and personal data. Suggest redaction that preserves diagnostic usefulness.
Challenge this cloud misconfiguration claim against resource policy, reachability and intended audience. Identify missing evidence before assigning impact.
Convert this confirmed configuration fix into automated assertions over manifests and policies. Include expected exceptions with documented justification.
Review the supplied Android manifest for exported components, deep links and backup settings. Tie each concern to reachable behavior rather than flags alone.
Explain the supplied iOS entitlements and their intended capabilities. Identify excessive permissions relative to the documented app features.
Trace these deep links into application actions. Identify parameter validation, authentication requirements and sensitive transitions from supplied source.
Review allowed origins, JavaScript bridges and navigation handling in this WebView configuration. Identify trust boundaries with line references.
Analyze where this app stores session credentials and how they are accessed. Distinguish platform protections from application-level access assumptions.
Review the supplied cache schema for private records and logout cleanup. Propose tests with synthetic data on a researcher-controlled device.
Trace sensitive values copied to or read from the clipboard. Assess necessity and lifetime in the application's stated workflow.
Map exported Android components to their permission checks. Identify which actions are callable and what evidence would establish unauthorized effect.
Compare mobile and web requests for the same operation. Identify differences in validation, fields and server-side authorization.
Review this desktop application's IPC handlers for sender validation and allowed operations. Identify untrusted input reaching privileged functionality.
Analyze the supplied Electron settings and preload bridge. Identify exposed capabilities and whether remote content can invoke them.
Review how this client validates update metadata and downloaded packages. Identify signature, origin and rollback checks from supplied code.
Trace custom protocol input into local actions. Identify parsing, path and argument boundaries using benign local examples.
Review access and encryption settings for the supplied app database. Identify which stored records need protection under the described threat model.
Inspect sanitized mobile logs for tokens, identifiers and private content. Recommend targeted redaction without removing useful error context.
Review whether biometric approval protects a server operation or only hides local UI. Identify the backend evidence needed to assess the actual boundary.
Assess the supplied sensitive-screen behavior against documented requirements. Separate platform limitations from a demonstrated data-exposure issue.
Review app-link configuration and domain association files. Identify mismatches that affect intended routing without claiming domain ownership.
Compare token refresh, logout and account switching in these captures. Identify stale data or identity confusion between researcher-controlled accounts.
Analyze conflict resolution and authorization during offline changes and later sync. Use synthetic records to identify security-relevant state transitions.
Review supplied push payloads and lock-screen behavior. Identify private fields and whether the content matches the application's privacy requirements.
Trace file sharing through platform intents or share sheets. Identify URI permissions, recipient scope and temporary access revocation.
Review which app files enter the supplied backup configuration. Identify sensitive records and the platform protections relevant to restoration.
Analyze this desktop feature's filesystem and process privileges. Identify operations that rely on an overly trusted local configuration source.
Review this mobile or desktop report for platform version, app build, account state and installation conditions needed to reproduce the result.
Map system instructions, user input, retrieved documents and tool results in this AI application. Identify where untrusted content can influence privileged decisions.
Review retrieval authorization for the supplied design. Check whether tenant and user permissions apply before retrieval and again before displaying results.
Build a permission matrix for this agent's tools. Separate read-only operations, reversible changes and actions requiring explicit user approval.
Design a synthetic document that tests whether quoted instructions are treated as data. Keep the test harmless and define the expected refusal to alter workflow.
Review storage and retrieval of chat history across test tenants. Identify identifiers and access checks protecting each conversation.
Trace model-generated values into application actions. Identify schema validation, allowlists and human review before security-sensitive use.
Review the supplied tool schema and handler. Identify whether validation occurs server-side and how unexpected or missing fields are rejected.
Evaluate how answers cite retrieved documents. Design a test using synthetic documents that distinguishes source-supported statements from unsupported generation.
Compare the proposed action shown to the user with the action executed after approval. Identify parameters that could change between those stages.
Review persistent agent memory keys and access controls. Identify separation among users, workspaces and organizations from the supplied code.
Review this prompt-building pipeline for accidental inclusion of credentials or private configuration. Suggest substitutions that preserve task context without exposing secrets.
Map prompts, completions, tool calls and traces to storage destinations. Identify retention and access questions that the supplied documentation leaves unanswered.
Review how this application selects model providers and base URLs. Identify whether untrusted input can redirect sensitive prompts to an unintended service.
Evaluate task duration, tool-call count and retry controls in this configuration. Propose bounded local tests for graceful termination.
Design synthetic malformed model outputs for this parser. Verify that validation failures do not trigger partial or unintended application actions.
Review vector-store metadata filtering and collection separation. Identify where missing or caller-controlled tenant filters could affect retrieval.
Compare this proposed AI issue with the program's stated scope. Separate undesirable model text from a demonstrated application security boundary failure.
Analyze how tool output is inserted into the next model context. Identify delimiters, provenance and authority assumptions using supplied examples.
Review filesystem tool restrictions for an agent workspace. Propose harmless local fixtures that verify access remains within approved directories.
Map browser actions available to this assistant to approval and destination checks. Identify where page content could be mistaken for user authorization.
Create a small synthetic evaluation set for this documented AI security property. Include successful behavior, failure cases and clear scoring criteria.
Review this conversation transcript for identity or task-state confusion. Identify the exact turn where assumptions changed and what evidence supports it.
Design an agent handoff that preserves proposed action, destination, data and uncertainty. Ensure reviewers can approve a concrete action rather than a vague objective.
Review this prompt-injection mitigation against the original trust boundary. Distinguish stronger instructions from enforceable tool and data access controls.
Structure this AI application finding around reproducible inputs, tool actions and observed impact. Avoid relying solely on a provocative model response.
Map supplied routes through middleware to controllers. Identify authentication and authorization checks that apply to each handler, including explicit exceptions.
Trace sensitive inputs through validation, transformation, storage and output in this module. Cite functions and separate confirmed flows from unresolved calls.
Review these flagged APIs for actual reachability from untrusted inputs. Explain required conditions before treating a static-analysis warning as actionable.
Compare validators used by create, update and import paths. Identify inconsistent rules and whether the difference affects a security property.
Trace exceptions from this service to user-visible responses and logs. Identify sensitive context that crosses the intended visibility boundary.
Compare the supplied advisory with dependency version, configuration and reachable features. List prerequisites met, unmet and unknown without assuming version match proves impact.
Review dependency changes in this lockfile diff. Prioritize security-relevant runtime changes and distinguish development-only dependencies.
Explain which trust boundary this patch changes. Identify equivalent call sites and missing regression cases using only the supplied repository context.
Inspect this reusable permission helper for default behavior, null inputs and role hierarchy. Propose explicit local tests for denied cases.
Compare database fields with serialized API output. Identify sensitive fields exposed by default or through nested objects.
Trace fallback behavior after authentication, parsing or dependency failures. Identify cases where errors broaden access or skip validation.
Explain how environment, file and request configuration values override each other. Identify security-sensitive settings influenced by less trusted sources.
Review these logging calls for secrets and private data. Propose field-level redaction while preserving correlation identifiers and error categories.
Compare the supplied security fix with existing tests. Identify untested inputs, alternate routes and negative assertions that matter to the original issue.
List security assumptions this code makes about framework defaults. Identify which must be verified against the installed version's official documentation.
Identify helpers that delete, replace or transfer resources. Trace their authorization and transaction boundaries before reviewing callers.
Analyze this transaction's reads, writes and external side effects. Identify invariants that may fail if the transaction aborts or retries.
Inspect this shared-state code for locking and atomicity assumptions. Propose deterministic local tests rather than relying on repeated production requests.
Trace whether a feature flag changes only presentation or also server permissions. Identify unsafe assumptions when flags are missing or stale.
Review these redacted secret-scanner matches for context and likely sensitivity. Identify public examples and placeholders separately; never attempt credential use.
Inspect generated client or server code for security-relevant defaults. Identify where regeneration could overwrite manual validation fixes.
Map package boundaries and shared security helpers in this repository. Identify applications that use different versions or bypass common enforcement.
Review this data migration for permission, ownership and default-value changes. Identify post-migration invariants requiring validation.
Prepare a compact source-review evidence bundle with relevant lines, call chain and unresolved context. Avoid including unrelated private code.
Recommend the narrowest reliable location to enforce this security rule. Compare central middleware, service-layer checks and handler-specific validation with tradeoffs.
Derive the cache key from the supplied configuration. Identify request attributes that influence content but are absent from the key.
Review how this cache handles authenticated responses. Identify user separation, cache-control directives and bypass rules from the supplied evidence.
Compare these response captures for reliable cache-hit indicators. Distinguish intermediary reuse from application-generated identical content.
Explain whether the supplied Vary headers match content negotiation and origin-specific behavior. Identify mismatches using existing captures.
Map invalidation after update, deletion and permission change. Identify stale-sensitive-content risks and a bounded test with researcher-owned data.
Compare path and header normalization across the supplied proxy and application configuration. Identify disagreements suitable for isolated local tests.
Review this HTTP proxy chain's documented framing behavior. Identify ambiguous parsing assumptions and recommend a local harness rather than live desynchronization tests.
Trace use of the Host and forwarded-host values in links, redirects and routing. Identify where configured canonical origins should be authoritative.
Review how this application generates reset and invitation links. Identify request-controlled origin components and the relevant validation.
Analyze whether compression settings interact with secret-bearing responses in this architecture. List prerequisites without claiming an attack from configuration alone.
Review method override handling across proxy, middleware and routing. Identify whether authorization sees the same effective method as the handler.
Compare how supplied components interpret repeated headers. Design local fixtures to identify differences without sending ambiguous requests to shared infrastructure.
Review permission and caching behavior for partial-content downloads. Identify whether range responses enforce the same restrictions as full responses.
Analyze ETag and conditional responses for user-specific resources. Identify whether validators reveal state across accounts in supplied observations.
Compare authenticated responses under supported content types and language settings. Identify whether alternate representations omit authorization or redaction.
Review whether application or proxy errors are cached and shared. Distinguish availability impact from sensitive response exposure.
Analyze caching of the supplied redirect responses. Identify destination variation and whether user-specific redirects can be reused incorrectly.
Compare slash, case and encoded-path normalization in this local routing setup. Identify alternate paths that reach different middleware chains.
Review the trusted-proxy list and deployment topology. Identify which clients can influence apparent IP, protocol or host values.
Analyze which identity forms the rate-limit key and how proxies affect it. Review configuration and local behavior without bypassing production controls.
Challenge this cache-poisoning hypothesis against cacheability, key influence and persistence evidence. Identify missing prerequisites before any program-approved validation.
Review the supplied path and caching rules for disagreement about resource type. Use a researcher-owned synthetic page to define a minimal permitted check.
Map authentication and authorization across HTTP upgrade handling. Identify whether the upgraded connection inherits the intended session and origin checks.
Trace user-controlled data into raw HTTP response construction. Identify newline normalization and library protections from supplied source.
Review this proxy-related report for complete request path, protocol version and observed behavior. Separate parser speculation from reproducible application impact.
Map the supplied authorization flow from initiation to session creation. Identify state, redirect URI, code exchange and account-binding checks.
Review state generation, storage, comparison and consumption in this OAuth implementation. Identify binding to the initiating browser and expected failure behavior.
Trace verifier generation and challenge validation in supplied code. Identify where values are bound to the authorization transaction.
Compare registered redirect URIs with runtime validation. Identify exact-match expectations and deployment exceptions that need documentation.
Compare requested scopes with displayed consent and application use. Identify unnecessary permissions without assuming the provider grants every requested scope.
Analyze token rotation and reuse handling from my test-account captures. Use token aliases and timestamps rather than exposing credentials.
Review verification of issuer and audience in this token consumer. Identify whether validation matches the application's intended provider and resource.
Review the permitted algorithms and key selection in supplied verification code. Identify reliance on untrusted token metadata and propose local negative tests.
Compare issuance, expiration and clock-skew handling. Identify boundaries and distinguish server validation from client display of expiry.
Review key rotation and cache-refresh behavior in this design. Identify how retired keys and unknown key identifiers are handled.
Compare validation paths for access, identity and refresh tokens. Identify whether each endpoint accepts only the intended token purpose.
Trace how external identities attach to local accounts. Identify verified-identity checks and handling of preexisting accounts with matching email addresses.
Plan a controlled test of access after revocation using my own integration. Distinguish local session state from provider token validity.
Review the supplied SAML validation configuration for issuer, audience, recipient and time conditions. Identify missing context before assessing security.
Trace how a response is associated with its initiating request and browser session. Identify unsolicited-response behavior in the documented flow.
Review security-sensitive identifier generation in this source. Distinguish unpredictable secrets from ordinary unique labels and identify the randomness API used.
Explain the supplied password hashing parameters and upgrade path. Identify where current vendor guidance should be checked rather than inventing universal settings.
Review how this design separates encryption keys, signing keys and application secrets. Identify reuse and access-control concerns within the supplied architecture.
Trace encryption and decryption failures in this implementation. Identify nonce management and integrity checks without attempting to recover plaintext.
Compare signed bytes with parsed webhook or API fields. Identify transformations that could cause verifier and consumer disagreement.
Review logs and tracing configuration for bearer tokens and authorization codes. Propose redaction that keeps safe correlation information.
Design a controlled test for single-use tokens issued to my own account. Specify consumption, expiry and replay outcomes without accessing another account.
Challenge this cryptographic finding against actual attacker capabilities and reachable code. Separate obsolete terminology from demonstrated weakness.
Generate local negative tests for wrong issuer, audience, expiry, signature and token type. State the expected rejection reason for each.
Rewrite this identity-related report to clearly distinguish authentication, authorization and account linking. Preserve only the demonstrated account-state changes.
Restate this finding as a falsifiable security claim. List established facts, assumptions, missing observations and evidence that would contradict it.
Reduce these reproduction steps to the smallest sequence that still demonstrates the issue. Preserve required state and remove unrelated actions.
Compare vulnerable and baseline captures while controlling account, object and session differences. Identify variables that prevent a valid comparison.
Generate plausible non-vulnerable explanations for this observation. For each, identify a low-impact observation that could rule it out.
Create a timestamped timeline linking actions, request IDs, responses and state changes. Flag gaps and conflicting timestamps.
Verify that each object in this proof belongs to a researcher-controlled account. Identify missing creation evidence and ambiguous ownership.
Review these screenshots for the information a triager needs. Identify missing context and data that should be redacted before submission.
Redact credentials and personal data from this request while preserving method, structure and security-relevant relationships. Use consistent aliases across artifacts.
Explain the meaningful differences between these responses. Ignore volatile fields only when their irrelevance is justified by the hypothesis.
Build a matrix of tested roles, object states and client versions. Mark observed results separately from combinations that remain untested.
List every prerequisite behind this impact statement. Identify which are demonstrated, attacker-controlled, victim-dependent or unknown.
Propose a negative control for this suspected vulnerability. Explain the expected difference if the security hypothesis is correct.
Identify a legitimate operation that confirms the test setup works. Use it to distinguish a protection from an unrelated environment failure.
Analyze these repeated observations for state and timing differences. Identify a deterministic reproduction hypothesis without increasing traffic blindly.
Review this scanner result against raw request and response evidence. Explain what it detects and what remains unproven.
Separate the observed symptom from possible underlying causes. Identify which source or behavioral evidence would support each cause.
Determine the minimum synthetic or redacted evidence needed to show this disclosure. Avoid collecting additional records once the boundary failure is established.
Assess severity using the supplied program framework and demonstrated impact. State uncertainty and avoid inventing access, scale or business consequences.
Compare these two findings for shared root cause, affected boundary and remediation. Explain whether they may be distinct without deciding program policy.
Identify configuration, feature flags and account history needed for this result. Separate universal behavior from environment-specific conditions.
Plan a retest that confirms the original issue is fixed and normal behavior remains intact. Use the same controlled accounts and synthetic records.
Find contradictions between this narrative and attached artifacts. Quote the conflicting observations and suggest precise corrections.
Rewrite this research note to clearly label unconfirmed behavior. Preserve useful evidence without presenting a hypothesis as a submitted vulnerability.
Prepare a validation handoff with prerequisites, safe test data, expected observations and stop conditions. Include unresolved questions explicitly.
Decide whether the provided evidence supports reporting, further validation or closing the hypothesis. Explain the decision and the single most important remaining gap.
Write three concise titles naming the affected feature and demonstrated security consequence. Avoid severity adjectives that the evidence does not support.
Summarize this confirmed finding in three sentences: affected boundary, reproducible behavior and demonstrated impact. Keep technical details in the reproduction section.
Rewrite these notes into numbered steps with prerequisites and expected observations. Do not invent commands, endpoints or results absent from the evidence.
Create an expected-versus-actual comparison for this finding. Tie expected behavior to documented permissions or a clearly stated security invariant.
Rewrite the impact section using only demonstrated capabilities and affected data. Mark scale and downstream consequences as unknown unless supported.
Draft a concise narration for this permitted proof of concept. Explain each action and observed result without exposing credentials or unrelated records.
Build an artifact index linking each claim to its supporting request, response, screenshot or source excerpt. Flag claims with no supporting artifact.
Propose remediation at the violated trust boundary. Compare a primary fix with defense-in-depth measures and identify compatibility considerations.
Prepare a developer-focused reproduction using the supplied environment details and synthetic data. Highlight the handler or state transition most relevant to debugging.
Draft a factual response to these triage questions using existing evidence. Clearly identify questions requiring another authorized test; do not send the response.
Draft a respectful severity clarification tied to the program's framework and demonstrated impact. Avoid pressure, threats or unsupported payout arguments.
Explain the technical differences between my finding and the described duplicate. Focus on root cause, affected boundary and remediation, acknowledging uncertainty.
Review this report for missing prerequisites, account roles, identifiers and observations. Prioritize gaps that prevent reproduction rather than cosmetic edits.
Compare the supplied patch and retest results. Identify whether the original security property is enforced and whether alternate entry points were considered.
Write a test specification with setup, action and assertions for this confirmed issue. Include a permitted success case and an unauthorized failure case.
Review this proposed public write-up against the supplied disclosure approval. Identify private details and claims outside the approved scope.
Redact the supplied appendix while preserving technical meaning. Maintain consistent aliases and list which evidence references changed.
Edit this report for concise professional language. Remove repetition, speculation and dramatic claims while preserving reproduction details and uncertainty.
Convert these validated notes into description, prerequisites, steps, evidence, impact and remediation. Put unresolved hypotheses in a separate section.
Review this claimed regression against the original fix and new observations. Identify whether it is the same root cause or a different behavior.
Explain why this retest is inconclusive using the supplied environment differences. Identify the minimum missing prerequisite before another attempt.
Draft a closure summary recording confirmed impact, fix, retest outcome and remaining limitations. Avoid asserting complete security beyond the tested boundary.
Extract reusable methodological lessons from this completed investigation. Separate lessons supported by evidence from techniques that merely happened to work once.
Draft a short list of questions about this patch's intended security invariant and coverage. Focus on ambiguity that affects verification; do not send it.
Review the complete report for scope, reproducibility, evidence consistency and confidentiality. Return a concise correction list and identify any unsupported claim remaining.
No matching prompts. Try a broader term or another category.
No matches here — press Enter to search everything.
Type to search products.
Cookie preferences
Signing in to your account, your shopping cart, secure payment and fraud protection, and remembering this choice.
Your language, currency and light or dark preference.
Anonymous statistics about how visitors find and use this store, including which campaign or website brought you here.