Prior-art overlap

Known-issue and prior-art overlap check

Paste your finding, the code it cites and everything already known about it: known-issue lists, audit reports, issues, pull requests. Your model fingerprints the root cause and classes every prior item as same-root, same-symptom-different-root or unrelated, with a line on each side.

Opens the workbench with Prior-art overlap selected. 1 hosted review per UTC day on your own key. No card.

ExampleExample output · invented protocol

VerdictHold: duplicate

Audit item M-03 has the same root cause, and the fix it recommends closes this path.

input-1/finding.md3 prior items
Overlap

Three prior items, classed against the finding in Pair.sol

Fingerprint

swap credits the amount sent, not the amount received, before _update. Closing fix: measure the balance delta after the transfer.

input-2/Pair.sol:131

Audit M-03

Fee-on-transfer tokens break the reserve invariant.

Same rootThe same missing balance-delta check in swap. The fix it recommends closes this path.

input-4/audit-report.md:204-221 input-2/Pair.sol:131

Known issue 4

Rebasing tokens are not supported.

Same symptom, different rootReserves drift through sync, a different code path. Its fix leaves line 131 unchanged.

input-3/known-issues.md:18 input-2/Pair.sol:164-170

PR 212

Add a reentrancy lock to swap.

UnrelatedA guard on entry. It does not touch the amount credited.

input-5/pr-212.diff:9-14

Next

Hold the report. Audit item M-03 already carries this root cause and its fix.

What the overlap check answers

One question: does a known issue, a prior audit note, a team branch or your own earlier report have the same root cause or the same one-line fix. Platforms judge duplicates on those two, so the check does too.

  1. A root-cause fingerprint

    The root cause and its one-line fix, read from the code you supplied.

  2. A class for every prior item

    Each known issue, audit note, branch or pull request classed same-root, same-symptom-different-root or unrelated, with a reference on each side.

  3. Your own earlier reports

    The broken invariant compared with what you already filed on the programme.

  4. The duplicate clock

    How exposed the finding is to a private duplicate, and the filing deadline that follows from it.

What to paste in

The check judges the documents you supply. Supply every one you have.

  • Your finding or draft report

    Notes are enough. The fingerprint comes from the code.

  • The source files it cites

    At the commit the finding names.

  • Known issues, prior audits, issues and pull requests

    The programme’s known-issues list, audit and fix-review reports, contest findings, tracker issues, diffs and commit messages.

Up to 50 files, 120 KB per file, 240 KB and 20,000 lines in total. Paste, drop files, or import a repository, pull request or commit from GitHub at a pinned commit.

What comes back

A class for every prior item, and the strings to search for the rest.

  • A Fingerprint: root cause, invariant, entry point and closing fix.
  • An Overlap table: every prior item classed, with a reference in the prior material and one in your code.
  • An Own reports table, and the duplicate clock with its filing deadline.
  • Search strings for the material you did not supply, each with where to run it.
  • One verdict. A same-root match holds the report as a duplicate.
  • A packet with the SHA-256 manifest of every file reviewed.

The search strings from the same review

What to run yourself against the material you did not supply. Pair is a contract invented for this page.

ExampleExample output · invented protocol · Pair

Search strings
StringWhere to run it
fee-on-transferWhere to run itAudit PDFs, the known-issues list, closed issues
balanceOf(address(this))Where to run itThe repository, every branch, with a full clone
_update(Where to run itPull requests and commit messages that touch Pair.sol
reserves must equal balancesWhere to run itAudit PDFs, in an auditor’s wording of the invariant

Questions

Does it search private report queues?

It reads the documents you supply: known-issue lists, audit reports, issues and pull requests. Private report queues are held by the platforms. The Search strings section lists what to look for in the repository, its issues and the audit reports, so you find the public material yourself.

What counts as the same root cause?

The same function and consequence, or the same fix. That is how platforms judge duplicates: the title, the wording and the strength of the proof carry no weight.

What if I supply no prior material?

The review names the documents to collect and gives you the search strings to find them. It judges the documents it was given and nothing from memory.

Which model runs the review?

The one you choose, on your own key: OpenRouter, Anthropic, OpenAI, Google Gemini, xAI, DeepSeek, Mistral or Groq. It runs as a hosted review: one per UTC day on Free, unlimited on Operator. From a coding agent it runs through run_review over MCP, on the same allowance.

Where do my files go?

Through our server to the model provider you choose, with your key, for that one request. The server adds the method of this profile on the way. Bounty Operator does not store your files, prompts, keys or results. The packet you download carries a SHA-256 manifest of every file reviewed.

Check the overlap before you spend the week

A root-cause fingerprint, every prior item classed against it, and a filing deadline.

Opens the workbench with Prior-art overlap selected. Free: 1 hosted review per UTC day. Operator: unlimited, US$10 per week.