Bug bounty report check
Paste a draft. Fourteen checks answer at once: what is on the page, what is missing, and which sentence a triager will quote back at you.
Your content never leaves the browser.
Markdown or plain text. The checks run as you type.
Result
0of 14 checks pass
Paste a draft, or load the example, to see each check with the line it found.
- Not run
Title states mechanism and consequence
- Not run
Scoped asset named
- Not run
Pinned revision
- Not run
Impact row quoted verbatim
- Not run
Severity stated once and consistent
- Not run
Trusted roles in the attack path
- Not run
Proof inline with command and output
- Not run
Final assertion on a balance, owner or stored record
- Not run
Mocks and pranks of privileged roles
- Not run
Known-issue and prior-audit comparison
- Not run
Limits and non-claims stated
- Not run
Self-negating phrases
- Not run
Secrets and private report links
- Not run
Local paths
The fourteen checks
Each result is one of three states. Pass: the part is on the page, with the line that carries it. Missing: nothing in the draft matches. Flagged: a line was found that a triager closes on, quoted so you can fix it.
| Check | What it looks for | Fix when it is open |
|---|---|---|
| Title states mechanism and consequence | What it looks forThe first heading or Title line names what the code does wrong and what is lost, locked, read, bypassed or blocked. | Fix when it is openWrite the title as one sentence: what the code does wrong, then what the attacker gains or the user loses. |
| Scoped asset named | What it looks forA scope, asset or target line carries an address, a repository link or a file. | Fix when it is openName the asset exactly as the programme lists it: the contract address or the repository path. |
| Pinned revision | What it looks forA commit hash, or a code link that contains one. A link to a branch is flagged. | Fix when it is openState the commit the finding was reproduced on and link every code reference at that commit. |
| Impact row quoted verbatim | What it looks forAn impact line with the programme’s row in quotation marks or in a quote block. | Fix when it is openCopy the impact row from the programme page word for word and put it in quotation marks. |
| Severity stated once and consistent | What it looks forOne severity level. A range, or two different levels, is flagged. | Fix when it is openState one severity, at the row the body argues, and remove every other level. |
| Trusted roles in the attack path | What it looks forNumbered attack steps that name owner, admin, keeper, operator or governance. | Fix when it is openLabel who performs each step; a decisive step by a trusted role ends the report. |
| Proof inline with command and output | What it looks forA run command and the output it printed, in the report body. A link alone is flagged. | Fix when it is openPaste the exact command and the output it printed into the report body. |
| Final assertion on a balance, owner or stored record | What it looks forAn assertion in the proof that reads a balance, an owner or a stored value. | Fix when it is openEnd the proof with an assertion that reads the object the impact row names. |
| Mocks and pranks of privileged roles | What it looks forA prank of a role-named address, a mock, or a forced state write in the proof. | Fix when it is openReach each state through public calls from live state, or name the mocked step and its route. |
| Known-issue and prior-audit comparison | What it looks forA line that names a known issue, an audit note or an earlier report. | Fix when it is openName the nearest known issue or audit note and say in one sentence how the root cause differs. |
| Limits and non-claims stated | What it looks forA limits section, or a sentence that says what the report does not claim. | Fix when it is openAdd two or three lines that say what the proof does not show and what you are not claiming. |
| Self-negating phrases | What it looks forSentences that contain: closest impact, if compromised, assuming, could potentially, currently zero, can be avoided by, does not establish. | Fix when it is openProve the condition each sentence concedes, or cut the claim that depends on it. |
| Secrets and private report links | What it looks forKeys, tokens, seed phrases, private platform links, email addresses and public IP addresses. | Fix when it is openRemove each listed line and rotate any key that was pasted anywhere. |
| Local paths | What it looks forHome-directory paths such as /home/name/ or C:\Users\name\. | Fix when it is openReplace each local path with a repository-relative path. |
Seven phrases that close a report
Each one concedes a point before the triager has to make it. The check quotes the sentence so you can prove the condition or cut the claim.
- “closest impact”
- Says the selected impact row does not fit.
- “if compromised”
- Makes a trusted party the attacker.
- “assuming”
- States a precondition with no route to it from live state.
- “could potentially”
- Describes an outcome the proof did not produce.
- “currently zero”
- Says nothing is at risk today.
- “can be avoided by”
- Names an action that removes the loss.
- “does not establish”
- Concedes the claim is unproven.
What a report that lands contains
- An executed proof with its command and output, and a control case.
- A final assertion on the object the impact row names: a balance, an owner, a stored record.
- The exact code location on a pinned revision, and a concrete fix.
- A title that states mechanism and consequence in one sentence.
- Numbered attack steps, kept separate from test code.
- The impact row quoted verbatim.
- Limits and non-claims stated by the author, and the nearest known issue named and distinguished.
Twelve checks, distilled from 105 real case files across five platforms. The wins and the closures. For a blank page, start from a report template or the report guide.
Questions
Where does my draft go?
Nowhere. The fourteen checks are JavaScript that runs in this tab, and the page sends no request with your text. After the page has loaded it makes one request: a counter that says the tool was used, with nothing of yours in it. Pressing “Run the full challenge on your model” moves the draft to the workbench through this browser’s session storage. A model sees it only when you start a review there.
What does 14 of 14 tell me?
That the parts a triager looks for first are on the page: a commit, a quoted impact row, one severity, an inline proof with its output, a comparison with known issues. The check reads text. Whether the claim survives an adversary is what the workbench challenge answers.
Which report formats does it read?
Markdown and plain text. Immunefi, Cantina, Sherlock and HackerOne reports all carry these parts, under different headings. The checks look for the content, so the heading names do not matter.
The text is in order. Now test the claim.
In the workbench your own model splits the draft into claims and marks each one confirmed, overstated, contradicted or unverifiable, with the line that decides it.