Proof / Bug bounty proof pack
Most public AI-security demos stop at one of three points: a benchmark scan, a chat transcript, or a source-only suspicion. This proof pack is different. Ninety results across six method families, shaped for a HackerOne triager.
Each family is documented with a top-find write-up that preserves vulnerability logic and review value while removing target identifiers.
The bug bounty pages present only public-safe mechanisms, proof standards and remediation patterns. They intentionally remove target names, domains, report IDs, package identifiers, secrets, hashes and reusable production exploit steps. No paid bounty outcome is claimed.
| ID | Redacted result |
|---|---|
| BB-001 | Exported account log bridge exposes sensitive operational data |
| BB-002 | Open account interface brokers token material across a trust boundary |
| BB-003 | Cross-origin login-state endpoint leaks authentication context |
| BB-004 | Public cloud business-secret and auth bootstrap material exposure |
| BB-005 | Authorisation replay across a privileged action boundary |
| BB-006 | Validation enforced on outbound, skipped on inbound recipient release |
| BB-007 | Forwarding calldata rebinds asset across cross-domain authorisation |
| BB-008 | Exported broadcast accepts privileged action without intent verification |
| BB-009 | Step-up boundary skipped for sensitive account mutation |
| … | (complete inventory available under engagement) |