Bug bounty report check

Paste a draft. Fourteen checks answer at once: what is on the page, what is missing, and which sentence a triager will quote back at you.

Your content never leaves the browser.

report-checkLocal · 14 checks

Markdown or plain text. The checks run as you type.

Result

0of 14 checks pass

Paste a draft, or load the example, to see each check with the line it found.

Run the full challenge on your model
  1. Not run

    Title states mechanism and consequence

  2. Not run

    Scoped asset named

  3. Not run

    Pinned revision

  4. Not run

    Impact row quoted verbatim

  5. Not run

    Severity stated once and consistent

  6. Not run

    Trusted roles in the attack path

  7. Not run

    Proof inline with command and output

  8. Not run

    Final assertion on a balance, owner or stored record

  9. Not run

    Mocks and pranks of privileged roles

  10. Not run

    Known-issue and prior-audit comparison

  11. Not run

    Limits and non-claims stated

  12. Not run

    Self-negating phrases

  13. Not run

    Secrets and private report links

  14. Not run

    Local paths

The fourteen checks

Each result is one of three states. Pass: the part is on the page, with the line that carries it. Missing: nothing in the draft matches. Flagged: a line was found that a triager closes on, quoted so you can fix it.

What each check looks for
CheckWhat it looks forFix when it is open
Title states mechanism and consequenceWhat it looks forThe first heading or Title line names what the code does wrong and what is lost, locked, read, bypassed or blocked.Fix when it is openWrite the title as one sentence: what the code does wrong, then what the attacker gains or the user loses.
Scoped asset namedWhat it looks forA scope, asset or target line carries an address, a repository link or a file.Fix when it is openName the asset exactly as the programme lists it: the contract address or the repository path.
Pinned revisionWhat it looks forA commit hash, or a code link that contains one. A link to a branch is flagged.Fix when it is openState the commit the finding was reproduced on and link every code reference at that commit.
Impact row quoted verbatimWhat it looks forAn impact line with the programme’s row in quotation marks or in a quote block.Fix when it is openCopy the impact row from the programme page word for word and put it in quotation marks.
Severity stated once and consistentWhat it looks forOne severity level. A range, or two different levels, is flagged.Fix when it is openState one severity, at the row the body argues, and remove every other level.
Trusted roles in the attack pathWhat it looks forNumbered attack steps that name owner, admin, keeper, operator or governance.Fix when it is openLabel who performs each step; a decisive step by a trusted role ends the report.
Proof inline with command and outputWhat it looks forA run command and the output it printed, in the report body. A link alone is flagged.Fix when it is openPaste the exact command and the output it printed into the report body.
Final assertion on a balance, owner or stored recordWhat it looks forAn assertion in the proof that reads a balance, an owner or a stored value.Fix when it is openEnd the proof with an assertion that reads the object the impact row names.
Mocks and pranks of privileged rolesWhat it looks forA prank of a role-named address, a mock, or a forced state write in the proof.Fix when it is openReach each state through public calls from live state, or name the mocked step and its route.
Known-issue and prior-audit comparisonWhat it looks forA line that names a known issue, an audit note or an earlier report.Fix when it is openName the nearest known issue or audit note and say in one sentence how the root cause differs.
Limits and non-claims statedWhat it looks forA limits section, or a sentence that says what the report does not claim.Fix when it is openAdd two or three lines that say what the proof does not show and what you are not claiming.
Self-negating phrasesWhat it looks forSentences that contain: closest impact, if compromised, assuming, could potentially, currently zero, can be avoided by, does not establish.Fix when it is openProve the condition each sentence concedes, or cut the claim that depends on it.
Secrets and private report linksWhat it looks forKeys, tokens, seed phrases, private platform links, email addresses and public IP addresses.Fix when it is openRemove each listed line and rotate any key that was pasted anywhere.
Local pathsWhat it looks forHome-directory paths such as /home/name/ or C:\Users\name\.Fix when it is openReplace each local path with a repository-relative path.

Seven phrases that close a report

Each one concedes a point before the triager has to make it. The check quotes the sentence so you can prove the condition or cut the claim.

“closest impact”
Says the selected impact row does not fit.
“if compromised”
Makes a trusted party the attacker.
“assuming”
States a precondition with no route to it from live state.
“could potentially”
Describes an outcome the proof did not produce.
“currently zero”
Says nothing is at risk today.
“can be avoided by”
Names an action that removes the loss.
“does not establish”
Concedes the claim is unproven.

What a report that lands contains

  • An executed proof with its command and output, and a control case.
  • A final assertion on the object the impact row names: a balance, an owner, a stored record.
  • The exact code location on a pinned revision, and a concrete fix.
  • A title that states mechanism and consequence in one sentence.
  • Numbered attack steps, kept separate from test code.
  • The impact row quoted verbatim.
  • Limits and non-claims stated by the author, and the nearest known issue named and distinguished.

Twelve checks, distilled from 105 real case files across five platforms. The wins and the closures. For a blank page, start from a report template or the report guide.

Questions

Where does my draft go?

Nowhere. The fourteen checks are JavaScript that runs in this tab, and the page sends no request with your text. After the page has loaded it makes one request: a counter that says the tool was used, with nothing of yours in it. Pressing “Run the full challenge on your model” moves the draft to the workbench through this browser’s session storage. A model sees it only when you start a review there.

What does 14 of 14 tell me?

That the parts a triager looks for first are on the page: a commit, a quoted impact row, one severity, an inline proof with its output, a comparison with known issues. The check reads text. Whether the claim survives an adversary is what the workbench challenge answers.

Which report formats does it read?

Markdown and plain text. Immunefi, Cantina, Sherlock and HackerOne reports all carry these parts, under different headings. The checks look for the content, so the heading names do not matter.

The text is in order. Now test the claim.

In the workbench your own model splits the draft into claims and marks each one confirmed, overstated, contradicted or unverifiable, with the line that decides it.

More free tools