Pre-submission review for bug bounty hunters and auditors

Find the hole in your report before the triager does.

Paste the draft and the code it cites. Your own model checks every claim against file and line, writes the strongest case against it and returns one verdict: submit, rewrite then submit, prove first, hold as a duplicate, or drop.

The example runs with no account and no key.

Free: one hosted review a day. Operator: US$10 a week for unlimited reviews, the full gauntlet, panel review and four at once.

Example

Draft claimsCriticalCode supportsMedium

VerdictRewrite, then submit

stake() skips settlement, so a fresh staker claims the whole reward reserve; principal is untouched, so the bug is Medium, not Critical

input-1/src/TesseraStaking.solsha256575d099f9d22…152 lines
F-1MediumProven in source

Unsettled stake() lets a fresh account claim the whole reward reserve

  • input-1/src/TesseraStaking.sol:87-94
Observed
function stake(uint256 amount) external {
    if (amount == 0) revert ZeroAmount();
    _updateGlobal();
    balanceOf[msg.sender] += amount;
    totalStaked += amount;
Counterargument

The exit() revert is known issue N-1

Resolvedinput-4/docs/known-issues.md:13 covers only the exit() revert, and no entry there covers the reward theft.

Next

Rewrite the report as Medium, select "Medium: Theft of unclaimed rewards", and inline the full test file.

Example review, as the model wrote it. Tessera Staking is an invented protocol.

How it works

  1. Load the code and the draft

    Drop files, paste them, or import from GitHub at a pinned commit. Up to 50 files and 240 KB per review. Pick one of eleven profiles.

  2. Run it on your model

    Use your own API key, connect OpenRouter in one click, or call it from your coding agent over MCP. The review goes through our server to your provider. The three core profiles also export as a prompt for your chat app. Read what is sent before it leaves the tab.

  3. Take the verdict and the packet

    One verdict, every finding tied to file and line, and the next action. The review, your evidence notes and a SHA-256 manifest download as one record. Bounty Operator stores none of it.

Run a review

Load the code or the draft, pick the check, and run it on your own model.

Load the material

Profile

Files

Drop files or a folder here

Source and text files. 120 KB per file. 240 KB, 50 files and 20,000 lines in total.

Paste textCode, a draft report or tool output

Named from what you paste. The review cites it by this name.

Import from GitHubA file, folder, repository or pull request link

Files are read at one exact commit, straight from GitHub to this tab.

Private repository

A read-only token. It goes to api.github.com from this tab and is forgotten on reload.

    Optional. Left empty, the profile's own request is used.

    Evidence

    Programme and proof facts

    Check

    Operator

    The gauntlet: eight stages, one verdict

    Hand over the draft, the code and the programme rules. One run takes the report through eight stages in the order that saves work, and ends on one decision.

    GatesThese end a report before the proof costs you a day.

    1. Scope

      Asset, revision, exclusions and the impact row, clause by clause.

    2. Provenance

      Who performs each step, and whether the project meant it.

    3. Prior art

      Same root cause, or only the same symptom.

    WorkWhat the draft has to show.

    1. Proof

      Checks that the proof shows the impact and not only the defect.

    2. Severity

      One level, graded on the programme's own table.

    3. Triager

      The three reasons a triager closes this report, ranked.

    4. Report

      Every claim in your draft, checked against the code.

    DecisionOne of five.

    1. Verdict

      One verdict, one blocker, the cheapest action that removes it.

    The run ends on one of five verdicts

    Submit
    Every decisive claim is backed by the supplied code and proof. File it.
    Rewrite, then submit
    The finding holds. The draft misstates its severity, impact, preconditions or fix.
    Prove first
    The claimed impact is not demonstrated on the real path yet. One artefact is missing.
    Hold: duplicate
    A known issue, an audit note, a branch or your own earlier report has the same root cause or the same fix.
    Drop
    The code contradicts the root cause, the behaviour is the design, or the rules exclude it.

    Any model can read code. This makes it argue like a triager.

    Your model, your key

    A review runs on the model you choose, under your own key. It passes through our server in memory, which adds the review method and stores no file, key or review. Your provider bills the usage.

    API key

    Paste a key for any of the eight providers, or connect OpenRouter in one click and pick any model it carries. The key is used for the one request it belongs to.

    Run with a key

    Chat subscription

    No key at hand. Export the prompt of a core profile (code security review, Solidity review or challenge a draft report), paste it into ChatGPT, Claude or a local model, then paste the answer back. The workbench turns it into finding cards and a packet. No daily limit.

    Run without a key

    Coding agent

    Add the MCP endpoint to Claude Code, Codex or Cursor. Your agent prepares a core review from the files in your repository and answers it on its own model, or runs any profile hosted with a connection token and your provider key.

    Terminal
    claude mcp add --transport http bounty-operator https://bountyoperator.com/api/mcp
    

    MCP setup for Codex, Cursor and tokens

    Free tools

    No account, no key. Each tool runs in your browser.

    US$10 a week. Unlimited reviews. Your model.

    Two plans. No seats, no credits, no per-line metering.

    Free

    Free

    US$0

    One hosted review per UTC day. No card.

    • 1 hosted review per UTC day
    • Any of the eleven single profiles
    • Gauntlet and Panel review: the worked examples
    • Prompt export and MCP prepare for the three core profiles, no daily limit
    • Free tools, GitHub import and local history

    Operator

    Operator

    US$10per week

    For contest weeks and live hunts.

    • Unlimited hosted reviews
    • The Gauntlet: eight stages, one verdict dossier
    • Panel review: two to four models, then cross-examination
    • Four hosted reviews running at once
    • Everything in Free

    US$10 billed weekly, renews until you cancel in the Stripe portal; access runs to the end of the paid week. Terms

    Questions

    The rest is in the terms and the privacy page.

    Can I use my ChatGPT or Claude subscription?

    Yes, for the three core profiles: code security review, Solidity review and challenge a draft report. Export the prompt, paste it into your chat app and paste the answer back. The workbench turns the answer into finding cards and a packet, with no key and no daily limit. Every other profile, the Gauntlet and Panel review run hosted on an API key, which providers bill separately from a chat subscription. A free account runs any single profile hosted once per UTC day. Claude Code, Codex and Cursor connect over MCP.

    What do you keep?

    No code, no prompts, no keys, no results. A hosted review passes through our server in memory: it adds the review method and sends your files, with your key, to the provider you chose. We store a random account identifier, your passkey public keys, hashed tokens, seven days of review activity (status, profile and timestamps) and Stripe references. No ad cookies, no tracking pixels, no third-party analytics scripts.

    What is in a review?

    One verdict and a one-sentence headline. Then each finding: severity, the lines it rests on, who loses what, the path step by step, the strongest counterargument and whether it is resolved, the one missing artefact, a fix, a test and the next action. After the findings come hardening notes, what was checked and found safe, and which files were read. It downloads as one packet with a SHA-256 manifest. A review reads the files you supply; it runs no code and touches no target.

    Which models does it run on?

    The one you pick, for every review. Hosted reviews run on your key at OpenRouter, Anthropic, OpenAI, Google Gemini, xAI, DeepSeek, Mistral or Groq, and an OpenRouter key reaches models from several labs. The prompt export of the core profiles works with any chat or local model.

    What does Operator add?

    Unlimited hosted reviews, the Gauntlet (eight stages, one verdict dossier), Panel review (two to four models, then a cross-examination pass) and four hosted reviews running at once. US$10 per week.

    Who runs it, and what about refunds?

    Tradi3 builds it and submits to the same queues: 2nd of 133 in Immunefi’s Firelight competition, 8th of 65 in Quantus. Payment runs through Stripe. Cancel in the billing portal and access runs to the end of the paid week. If you paid and got no access, or the service was down for a material part of your week, we fix it or refund that charge. Support: support@bountyoperator.com.

    Import from GitHub

    The prompt your model receives

    
    

    Cited lines

    Local history

    Off by default. When on, each finished review is saved in this browser as its packet and manifest. Source files and keys are never saved. Nothing is uploaded.

    Sign in

    Account

    Confirm it's you