A resource for researchers
A report someone can follow.
Start with one clear observation. Keep the code, evidence, affected version and unresolved questions together. These four steps work for reviewing your own source or material you are authorized to assess.
1. Choose the exact material
Add the relevant source, notes or draft. Record the project, authorization and commit. The GitHub importer reads your selected file at an exact commit; a file manifest records the SHA-256 of each supplied file.
Keep the first review focused. Include the callers and relevant dependencies when they are needed to understand a claim.
2. Choose the right review
Code security review checks authorization, data handling and failure behavior. Solidity source review applies attributed Pashov X-Ray guidance to caller permissions and invariants. Challenge a draft report checks the claims against the evidence.
Run the local privacy check and inspect the exact request. Then use your own API key, export the request to your chat app, or use the MCP connection.
3. Separate the observation from the claim
For each observation, keep an exact code reference, the expected behavior, evidence of the consequence, the strongest counterargument, and a defensive fix. A local result and a production consequence are separate claims.
When impact is missing, preserve the gap and leave severity unrated. When a known issue or prior fix addresses the same root cause, keep the candidate on hold and record the comparison.
4. Save the packet and take the next step
Download the review packet and file manifest. Verify the references and conclusions, apply or assess the suggested defensive fix, and record a safe local regression result. The account portal shows recent review activity; the actual files and results stay with you.
If you decide to submit a report, check the live program rules, exact affected version, listed impact and known issues. Keep the report clear and concise.
A small claim is easier to check.
“This branch returns an upstream error body” follows from the bundled example code. “This leaks an API credential in production” needs additional evidence. The workbench helps keep that distinction visible.
Sources and attribution
The report structure draws on HackerOne’s report-quality guidance. The Solidity profile contains selected MIT-licensed Pashov X-Ray guidance, pinned to an exact source revision, with the upstream license. It is a hosted source-review adaptation. The upstream command execution and multi-agent runner are separate tools.