Submission Intake
Triage Diagnostic & Signal Radar
Maintainer Response & Action Dispatch Export Decision JSON
Why Bug Bounty Programs Are Freezing Under AI Submissions
Following Google's pause of its open source bug bounty program, security organizations across the world reported reaching a breaking point: autonomous LLM scrapers continuously spam security mailboxes with fabricated vulnerabilities, hallucinated stack traces, and non-existent CVE analogies.
Unlike traditional security scanner noise (which at least targets real endpoints), AI slop fabricates vulnerable functions, invents parameter names, and quotes generic OWASP advice while demanding maximum critical bounties. Triage teams waste hundreds of engineering hours attempting to reproduce mathematical hallucinations.
Audit Methodology & Diagnostic Heuristics
1. Synthetic Preamble & Politeness Signatures: LLM agents frequently begin with boilerplate phrases like "I hope this report finds you well" or "As a passionate bug hunter", followed by rigid formatted sections without contextual developer nuance.
2. Executable Reproduction Proof: Legitimate submissions furnish verified curl payloads, serialized objects, or test assertions. AI slop relies on generic descriptions like "Send a malformed payload to trigger undefined memory corruption".
3. Path & API Hallucination Audit: Cross-checks referenced paths (e.g. /etc/shadow on client-side JS, or imaginary endpoints) and tests whether the bug claims remote code execution without auth bypass vectors.
Frequently Asked Questions
Does this tool send bug bounty reports to external cloud LLM servers?
No. All triage analysis, heuristic vector calculations, and regex parsing operate 100% locally in your web browser. Your confidential disclosures, zero-day research, and vulnerability draft notes never leave your computer.
How can security maintainers distinguish legitimate junior researchers from AI slop?
Legitimate junior researchers often submit low-severity issues, but their reproduction steps operate on actual system endpoints. AI slop typically claims high or critical severity (Remote Code Execution, Privilege Escalation) while providing zero executable evidence and hallucinated file names.
Can this decision matrix be exported into HackerOne, Bugcrowd, or GitHub Security Advisories?
Yes. You can use the "Export Decision JSON" or "Copy Canned Reply" button to directly paste standardized triage decisions and reject tickets with clear, polite technical justifications.