▸case-05 I reviewed a SSRF draft against all proof requirements, and the sub-agent assigned it a score of 8 out of 10. Should I keep tweaking the background explanation paragraphs, or what is the status? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 During the audit of `https://auth.company.com/oauth/token`, my draft vulnerability report describes an OAuth token leakage, but lacks raw HTTP request and response traffic logs. What explicit action or command step should be suggested to supply this missing evidence? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 My draft report for an RCE finding on `server.target.internal` has detailed steps, but the binary exploit script mentioned in the text is not saved on disk. How does proof checking handle this missing PoC file? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 In my report for an API authorization flaw on `https://api.domain.org/v2/orders/441`, I mentioned 'send a modified auth header'. What specific detail must be included in the report to satisfy reproducibility requirements? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 I am preparing a report for a race condition vulnerability on `https://checkout.store.com/apply_coupon`. I noticed a similar report was submitted 6 months ago on a related endpoint. What must be included in the report regarding prior findings? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 A researcher submitted a 20-page report explaining a complex logic flaw on `https://pay.gateway.io/checkout` in elegant prose, but provided zero screenshots, CLI logs, or network captures. The score is 4/10. Can high-quality writing make up for missing evidence? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 An internal security report for a XSS issue on `https://forum.app.com/profile` received an evaluation score of exactly 7 out of 10. What is the explicit submission recommendation rule for this score? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 A report draft detailing a DOM-based XSS on `https://dashboard.vendor.com/settings` lacks visual proof of execution. What specific step should be recommended to fix this evidence gap? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 A draft report for CSRF on `https://app.enterprise.com/user/email_update` sets CVSS vector with Scope Changed (S:C) and High Availability impact based on potential account takeover cascades. How should severity fit evaluate this vector? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 I need to run an automated vulnerability scan against our target domain `https://staging.example.com` using OWASP ZAP CLI in baseline mode. What exact command line invocation should I run? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 Could you perform a quality review on my security vulnerability writeup located at `docs/reports/draft_xss.md`? Let me know what the assessment is, any issues I need to address, and recommendations if it needs further work. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 Calculate the exact CVSS v3.1 base score and vector string for an unauthenticated remote code execution vulnerability with Vector: `AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H`. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 To prove maximum impact for a SQL injection on `db.service.net`, I am planning to dump 100,000 user rows to show full database compromise. How should impact proof be structured to maintain a top-tier quality score without policy violations? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 I wrote a report on a local file disclosure in `/var/log/app.log` at `https://app.target.com/download`. I rated it as CVSS 9.8 Critical because an attacker could theoretically find database credentials in the log and execute code. Evaluating severity fit in report scoring, how should this severity be rated? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 I don't have a file path saved, but here is my draft report text: 'Title: CORS Misconfiguration on https://api.site.com/data. Summary: Origin header reflected with credentials. Impact: Arbitrary origin data read.' Please run the report quality check on this draft. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 We found an SQL injection vulnerability in our Python application where `query = f'SELECT * FROM users WHERE id = {user_id}'` is executed against PostgreSQL. Provide the corrected Python code using parameterized queries to fix this vulnerability. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 I am writing a bug report for an authentication bypass at `https://portal.company.com/login`. The report contains 15 pages of background history. What elements must the title, summary, and remediation focus on to ensure high triage quality? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 I just finished drafting a bug bounty submission in `./drafts/sqli_report.md`. Run an evaluation on it to give me feedback on any missing evidence or weak areas, and confirm whether it is ready to be sent. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 The evaluation score for a draft on `https://cloud.provider.net/s3_proxy` came back as 6 out of 10 due to missing exact request headers. What step must be taken next under the quality process? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 Please inspect the report draft stored in `~/pentest/findings/auth_bypass.txt`. Evaluate its completeness and proof, then tell me whether it is good for submission or if there are specific fixes I should make. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-23 A bug report for `https://store.company.com/cart` describes an integer overflow in quantity. The current remediation section says 'Fix the code'. How should triage empathy improve this section? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 A report for an unauthenticated endpoint at `https://internal-api.corp.local/status` lacks the raw HTTP response headers on disk. What command should be recommended to capture the missing HTTP headers? | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 Here is a report draft for an IDOR vulnerability on `api.example.com/v1/users/102`. The prose is very polished, but missing raw HTTP headers. The evaluation score came back as 5. How should this assessment handle the submission status? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |