Compare

Bounty Operator vs a chat app, a local audit skill and platform pre-checks

Four ways to check a finding before you file it, and four tools that cover part of the same ground. The tables say what each one gives you: pinned inputs and hashes, method, counterargument, verdict, cost shape and privacy. Facts about other products are numbered, linked and dated.

What each one gives you

Scroll the table sideways for the other three columns.

What you getBounty OperatorPasting into a chat appOpen-source audit skillsPlatform pre-checks
Built forArguing against one finding or one draft report before it is filed.Whatever you ask. The conversation is the workflow.Running a packaged procedure inside a coding agent. A skill is a folder with a SKILL.md of instructions the agent loads when a task matches. [5]Feedback on a draft inside one platform.Immunefi: Studio Review. [1]HackerOne: Report Assistant. [4]
Inputs pinned and hashedEvery file is labelled, line-numbered and listed in a SHA-256 manifest. Line references in the review are checked against it.What you paste into the conversation.The files in your working tree, as the agent reads them. The skill format defines instructions and optional scripts. [5]The report form. HackerOne states that only the text you enter is used to generate suggestions. [4]
MethodTwelve checks and eleven review profiles with a fixed output format. The checks are on the method page. The three core profiles are open source. The others run on the hosted service.The prompt you write that day.The instructions the skill’s author wrote. [5]Immunefi: PoC clarity, impact framing, completeness and duplicate risk [2], run by the triaging agent its triage team uses. [3]HackerOne: steps to reproduce, expected and actual behaviour, impact, asset scope, severity, supporting material and custom fields. [4]
CounterargumentEvery finding carries the strongest objection, marked resolved or open, with the line that settles it.When you ask for one.When the skill’s instructions ask for one.Immunefi returns improvement notes. [1]HackerOne returns check results and suggestions you choose to apply. [4]
VerdictOne of five: submit, rewrite-then-submit, prove-first, hold-duplicate, drop.Free text.The report format the skill defines.Immunefi’s sample review shows a verdict line with ratings for PoC clarity, impact and duplicate risk. [1]HackerOne shows a result per check. [4]
Duplicate signalOverlap with the known issues and audits you supply, classed by root cause.Overlap with what you paste.Overlap with what the agent reads.Immunefi: a duplicate-risk assessment [1], from an agent backed by the reports submitted to Immunefi. [3]
PlatformsAny. You paste the programme’s rules: Immunefi, Cantina, Sherlock, HackerOne.Any.Any.Its own.Studio Review: Immunefi. [1]Report Assistant: the HackerOne report form. [4]
Access and cost shapeOpen to anyone. Free: 1 hosted review per UTC day. Operator: US$10 per week, flat. Your provider bills model usage to your key.Your chat subscription.A folder you install. [5]Model usage is billed by the plan your coding agent runs on.Studio Review is in invite-only beta. [2]Report Assistant is optional in the report form. [4]Neither page cited states a price.
Where your draft goesThrough our server to the model provider you choose, on your key. Bounty Operator stores no files, prompts, keys or results. A core profile exported as a prompt goes from your browser to the chat app you paste it into.To the chat provider, into your chat history.Consumer plans use conversations for model training according to your settings: OpenAI’s “Improve the model for everyone” control [6] and Anthropic’s model-improvement setting. [7]To the model behind your coding agent, under that provider’s terms.To the platform that triages the report.HackerOne states that report data is not shared with the programme before you submit. [4]

“Open-source audit skills” means the free skill packs that run a security review from inside a coding agent. “Platform pre-checks” means the draft-review tools the bounty platforms publish for their own report forms.

Four tools on the same ground

Each of these checks a finding before it is filed, as one step of a larger job: hunting, filtering or deduplicating. The last column names the gauntlet stages that ask the same kind of question.

ToolWhat it doesHow it runsCostSame ground as
A free hunting kit with a go/no-go gateWhat it doesRuns recon, hunts for bugs and writes the report for HackerOne, Bugcrowd, Intigriti or Immunefi. A seven-question gate checks the finding before the report is written, and a two-minute check gives a go or a no-go. [8]How it runsA command-line tool and a plugin for a coding agent. [8]CostFree. MIT licence. [8]Same ground asScope, provenance, proof
A hosted bounty tool with a lifetime priceWhat it doesEight agents hunt in parallel across web, API and smart-contract targets. Findings are deduplicated, put through four gates (refutation, reachability, trigger, impact), scored with CVSS and written up for the same four platforms. [9]How it runsA skill for a coding agent, and a hosted version that runs each session in its own sandbox on your AI key. [9]CostThe skill is free. [9]The hosted version listed a one-time lifetime price of US$199. [10]Same ground asProvenance, proof
A known-issue registerWhat it doesBuilds one known-issues.json from audit reports: local files and folders, PDFs, URLs and GitHub repositories. A new issue, or a whole report, is then compared with the register for duplicates. [11]How it runsA command in a coding agent, or a Python command-line tool. [11]CostFree. MIT licence. [11]Same ground asPrior art
A false-positive filterWhat it doesTakes a finding, or a CSV of findings, and the codebase. It verifies the location, tests whether the attack reduces to a trusted role acting maliciously, argues generic and issue-specific counter-arguments against the code, and returns VALID, INVALID or DOWNGRADED with code-line evidence. [12]How it runsA skill and a slash command in a coding agent. [12]CostFree. [12]Same ground asProvenance, triager

Three of the four find the bug or filter a batch of findings. Bounty Operator starts from one finding you already hold and argues against the report: scope, design intent, duplicates, proof, severity and what the platform stored.

Sources

Each number in the table points here. Statements about Bounty Operator describe the product on this site.

  1. [1]Immunefi, “Immunefi Studio”checked 2 October 2026
  2. [2]Immunefi on X: Studio Review checks and beta statusposted 10 September 2026, checked 2 October 2026
  3. [3]Immunefi on X: the agent behind Studio Reviewposted 11 September 2026, checked 2 October 2026
  4. [4]HackerOne Help Center, “Report Assistant”dated 13 April 2026, checked 2 October 2026
  5. [5]Agent Skills, “What are Agent Skills?”checked 2 October 2026
  6. [6]OpenAI Help Center, “Data controls in ChatGPT”checked 2 October 2026
  7. [7]Anthropic Privacy Center, “Is my data used for model training?”dated 16 March 2026, checked 2 October 2026
  8. [8]GitHub, “awarexone/Agentic-Bug-Hunter”, READMEchecked 3 October 2026
  9. [9]GitHub, “Gabson0x/bountyforge”, READMEchecked 3 October 2026
  10. [10]BountyForge, hosted versionprice checked 3 October 2026
  11. [11]GitHub, “J4X-Security/K.I.T”, READMEchecked 3 October 2026
  12. [12]GitHub, “heavyw8t/The-Judge”, READMEchecked 3 October 2026

Where each one fits

They answer different questions, and they combine.

  1. A chat app

    One question about one function, answered in a minute. The record is the conversation.

  2. An open-source audit skill

    A sweep of a repository from your coding agent. It produces candidates for you to verify.

  3. A platform pre-check

    A read of your draft on the platform that will triage it, where you have access to it.

  4. A hunting kit or a finding filter

    Recon, hunting and a first gate on what an agent found. What it keeps is a candidate.

  5. Bounty Operator

    One candidate, argued against in a fixed order: scope, intent, prior art, proof, severity. Pinned inputs, one verdict, any platform. It also runs from a coding agent over MCP.

Put your next finding through it

One hosted review per UTC day is free, on your own model and key.