Scope
Whether the code is in the scoped asset at the deployed revision, whether the class is excluded, and whether every clause of the chosen impact row has an artefact behind it.
- Binding table
- Exclusion matches
- Impact row, clause by clause
Operator
Hand over the draft, the code and the programme rules. The Gauntlet runs eight stages in the order that saves work and returns one decision, the one blocker behind it and the cheapest action that removes it.
US$10 per week. Runs on your own model and key.
The seizure bug is in the code. The proof reads the return value of liquidate on a mock oracle; the impact row names the borrower’s collateral.
Words a hunter already uses. The dossier never ends on “consider” or “it depends”.
Scope, provenance and prior art end a report without a proof. They run before the stages that cost you work. Each stage reads the output of the stages before it.
Whether the code is in the scoped asset at the deployed revision, whether the class is excluded, and whether every clause of the chosen impact row has an artefact behind it.
Who performs each step, whether the behaviour is documented design or an audit fix, whether the bug adds anything over the intended path, and whether every precondition is reachable from live state.
Whether a known issue, a prior audit note, a team branch or your own earlier report has the same root cause or the same one-line fix.
Whether the proof runs production code on every step and ends by reading the object the impact row names, with measured numbers.
The highest row of the programme’s own scale that the proof fully asserts, after every downgrade clause.
The one sentence that closes this report in ten minutes, and whether the first paragraph already answers it.
Whether the claims follow from the code, the proof is inline, the form and the body agree, and the limits are stated.
One decision.
A draft claims a Critical pool drain in Brinewell Lend, a lending protocol invented for this page. Eight stages later the finding stands, the severity moves, and one test is missing.
The seizure bug is in the code. The proof reads the return value of liquidate on a mock oracle; the impact row names the borrower’s collateral.
| Stage | Its verdict | The one thing it decided |
|---|---|---|
| 1Scope | Its verdictSubmit | The one thing it decidedThe file and the function exist in the scoped asset at the deployed revision. No exclusion names the class. |
| 2Provenance | Its verdictProve first | The one thing it decidedEvery step is performed by an unprivileged liquidator. The unhealthy state is set through MockOracle.setPrice, with no route from live state shown. |
| 3Prior art | Its verdictRewrite, then submit | The one thing it decidedAudit item L-04 has the same symptom and a different root cause. The report has to state the difference in its first paragraph. |
| 4Proof | Its verdictProve first | The one thing it decidedThe final assertion reads the return value of liquidate. The impact row names the borrower’s collateral. |
| 5Severity | Its verdictRewrite, then submit | The one thing it decidedThe proof supports High on the scale supplied. The draft selects Critical. |
| 6Triager | Its verdictProve first | The one thing it decidedFastest close: impact not shown. “The attacker drains the pool” has no assertion behind it. |
| 7Report | Its verdictRewrite, then submit | The one thing it decidedRoot cause and fix are confirmed against lines 215-216. The title claims a pool drain; the code shows a loss per position. |
| 8Verdict | Its verdictProve first | The one thing it decidedOne fork test stands between this draft and a High. |
liquidate sizes the seizure from the whole collateral, not from the amount repaidA liquidator who repays 1 unit of debt on an unhealthy position takes all of its collateral. The borrower loses the collateral above the debt. Bound: each unhealthy position’s collateral, minus the debt repaid.
liquidate checks one thing about the position: _healthFactor(p) < WAD (line 214).seized from p.collateral and bonusBps. repay is not in the expression.seized at p.collateral, so any repay above zero seizes the whole collateral.repay and send seized to the caller.function liquidate(address borrower, uint256 repay) external nonReentrant {
Position storage p = positions[borrower];
if (_healthFactor(p) >= WAD) revert Healthy();
uint256 seized = (p.collateral * (BPS + bonusBps)) / BPS;
if (seized > p.collateral) seized = p.collateral;
p.debt -= repay;
p.collateral -= seized;
debtToken.safeTransferFrom(msg.sender, address(this), repay);
collateralToken.safeTransfer(msg.sender, seized);
}
The position is unhealthy. The borrower was going to lose that collateral to liquidation anyway.
OpenThe intended path seizes the repaid amount plus the bonus. The draft never shows the two outcomes side by side, and its test reaches the unhealthy state through MockOracle.setPrice.
Compute seized from repay: convert it to collateral at the oracle price, add bonusBps, then cap at p.collateral.
Run the fork test with both assertions, then paste the command and its output into the report body.
| # | Action | Artefact it produces | Stage |
|---|---|---|---|
| 1 | ActionRerun the test on a fork of the deployed revision, with the price moved by the real feed. | Artefact it producesCommand and output | StageProof |
| 2 | ActionAssert the borrower’s collateral balance before and after, and add the full-repay control. | Artefact it producesTwo assertions | StageProof |
| 3 | ActionChange the claimed severity to High and quote the impact row word for word. | Artefact it producesEdited report | StageSeverity |
| 4 | ActionName audit item L-04 in the first paragraph and state the different root cause. | Artefact it producesOne paragraph | StagePrior art |
| 5 | ActionReplace “drains the pool” in the title with the per-position loss. | Artefact it producesEdited title | StageReport |
The run asks for the evidence that decides outcomes. A field left empty is named in the dossier as not supplied.
Your report, the source files it cites and the proof with its command and output.
The programme’s impact list, the row you intend to select, the exclusions and the trusted roles.
The programme’s own scale with its thresholds and downgrade clauses, pasted in.
The scoped asset, the revision your proof ran against and the revision that is deployed.
Known issues, audits and fix-review notes, team branches, and your own earlier reports on the programme.
The date you first reproduced it, the fee and duplicate rules, and what the platform stored after you filled in the form.
No new machinery. The Gauntlet is eight hosted reviews, run in order from your browser on your own key.
Each stage is a hosted review with its own profile. It goes through our server, which adds the method of the stage, to your provider. Your provider bills each call to your key.
A stage’s output goes to the later stages as a file named stage-<n>-<profile>.md, next to your draft and your code.
A cancelled run, a provider error or a reload keeps every stage that finished. The run picks up at the stage that did not.
The dossier downloads as one record with the SHA-256 manifest of every file the run read.
The Gauntlet is part of Operator at US$10 per week. A run is eight reviews on your own model, so your provider bills eight model calls to your key.
The one you choose. Every stage is a hosted review: your files and your API key go through our server, which adds the method of the stage, to your provider. That is OpenRouter, Anthropic, OpenAI, Google Gemini, xAI, DeepSeek, Mistral or Groq. No file, key or review is stored.
The stages run hosted, on an API key. The report stage is the Challenge a draft report profile, which also exports as a prompt on its own. From a coding agent, the gauntlet prompt of the MCP server runs the same order: seven hosted reviews through run_review with a connection token, and the report stage on your agent’s own model.
The run stops there. A drop or a hold-duplicate from scope, provenance or prior art ends the report before the proof stage costs you a day, and the dossier opens on that verdict. One button runs the remaining stages anyway.
It reads the files you supply. The proof stage reads your test and its output and tells you the one run that is missing. You run it locally.
The example dossier on this page and every single profile, one hosted review per UTC day. Each gauntlet stage except the final verdict is also a profile you run on its own.
Unlimited hosted reviews, the Gauntlet, Panel review and four reviews running at once.
US$10 billed weekly, renews until you cancel in the Stripe portal; access runs to the end of the paid week.