Submission Intake

0 words
TEST PRESETS (GROUNDED INCIDENTS):
Ready for triage analysis.

Triage Diagnostic & Signal Radar

EVALUATING

HIGH PROBABILITY AI SLOP (91% CONFIDENCE)

Substantial LLM synthetic phrasing detected with unverified memory corruption claims and no reproducible payload.

RECOMMENDATION
AUTO-REJECT
Slop Index
88%
Synthetic LLM pattern density
PoC Executability
15%
No runnable curl/script found
Triage Time Saved
~25 min
Eliminated manual wild-goose chase
Proof-of-Concept Grounding 12%
Synthetic Boilerplate Penalty 92%
Stack Trace / File Authenticity 20%
Specific Exploit Mechanics 18%
Remediation Feasibility 35%
Flagged Evidence & Heuristic Violations

Maintainer Response & Action Dispatch Export Decision JSON

EXTRACTED REPRODUCTION HARNESS:
# No runnable PoC or executable command sequence discovered in submission.
CANNED DISMISSAL / TRIAGE REPLY (COPY-PASTE READY):

Why Bug Bounty Programs Are Freezing Under AI Submissions

Following Google's pause of its open source bug bounty program, security organizations across the world reported reaching a breaking point: autonomous LLM scrapers continuously spam security mailboxes with fabricated vulnerabilities, hallucinated stack traces, and non-existent CVE analogies.

Unlike traditional security scanner noise (which at least targets real endpoints), AI slop fabricates vulnerable functions, invents parameter names, and quotes generic OWASP advice while demanding maximum critical bounties. Triage teams waste hundreds of engineering hours attempting to reproduce mathematical hallucinations.

Audit Methodology & Diagnostic Heuristics

1. Synthetic Preamble & Politeness Signatures: LLM agents frequently begin with boilerplate phrases like "I hope this report finds you well" or "As a passionate bug hunter", followed by rigid formatted sections without contextual developer nuance.

2. Executable Reproduction Proof: Legitimate submissions furnish verified curl payloads, serialized objects, or test assertions. AI slop relies on generic descriptions like "Send a malformed payload to trigger undefined memory corruption".

3. Path & API Hallucination Audit: Cross-checks referenced paths (e.g. /etc/shadow on client-side JS, or imaginary endpoints) and tests whether the bug claims remote code execution without auth bypass vectors.

Frequently Asked Questions

Does this tool send bug bounty reports to external cloud LLM servers?

No. All triage analysis, heuristic vector calculations, and regex parsing operate 100% locally in your web browser. Your confidential disclosures, zero-day research, and vulnerability draft notes never leave your computer.

How can security maintainers distinguish legitimate junior researchers from AI slop?

Legitimate junior researchers often submit low-severity issues, but their reproduction steps operate on actual system endpoints. AI slop typically claims high or critical severity (Remote Code Execution, Privilege Escalation) while providing zero executable evidence and hallucinated file names.

Can this decision matrix be exported into HackerOne, Bugcrowd, or GitHub Security Advisories?

Yes. You can use the "Export Decision JSON" or "Copy Canned Reply" button to directly paste standardized triage decisions and reject tickets with clear, polite technical justifications.

' into the search bar, arbitrary javascript may execute in the victim's session.\n\n### Proof of Concept:\nNavigate to: https://example.com/search?q=%3Cscript%3Ealert(1)%3C/script%3E\nObserve the alert box popping up.\n\n### Note:\nI was unable to verify this live because your Cloudflare protection blocked my scanner, but the code pattern strongly indicates vulnerability. Please assign CVE-2026-99124 and reward accordingly.` }, legit: { title: "Pre-Auth Deserialization RCE in WorkerRPC Dispatcher", component: "cloud-dispatch-worker v3.2.1", severity: "CRITICAL (9.8)", body: `Vulnerability Report: Unauthenticated Deserialization in /rpc/v1/dispatch\n\n### Root Cause Analysis:\nIn \`pkg/rpc/handler.go\`:42, the RPC endpoint reads \`X-Payload-Format: java-bin\` and forwards the stream directly to \`ObjectInputStream.readObject()\` without a class filter allowlist.\n\n### Minimal Reproducible PoC:\nExecute the following curl command against the local docker container (verified on v3.2.1 build 88a2f):\n\n\`\`\`bash\ncurl -X POST "http://localhost:8080/rpc/v1/dispatch" \\\n -H "Content-Type: application/octet-stream" \\\n -H "X-Payload-Format: java-bin" \\\n --data-binary @payload.ser\n\`\`\`\n\nPayload generator script (\`gen_payload.py\` using ysoserial CommonsCollections6):\n\`\`\`python\nimport subprocess\ncmd = "touch /tmp/rce_verified"\nsubprocess.run(["java", "-jar", "ysoserial.jar", "CommonsCollections6", cmd, "payload.ser"])\n\`\`\`\n\n### Verified Impact:\nConfirmed arbitrary file creation (/tmp/rce_verified) inside container unprivileged sandbox.\n\n### Proposed Fix:\nSwitch serialization codec to strict protobuf or enforce \`ValidatingObjectInputStream\` with known safe classes.` } }; // Heuristic patterns for AI Slop detection const SLOP_PATTERNS = [ { regex: /i hope this (email|report|message) finds you well/i, weight: 25, label: "Polite LLM Preamble", quote: "I hope this finds you well..." }, { regex: /as (an|a) (independent|enthusiastic|passionate) (cybersecurity|security|ai) researcher/i, weight: 20, label: "Bot Researcher Introduction", quote: "As an independent security researcher..." }, { regex: /looking forward to hearing about (bounty|compensation|reward)/i, weight: 15, label: "Premature Bounty Extortion", quote: "Looking forward to hearing about bounty..." }, { regex: /send a specially crafted (malformed|payload|packet)/i, weight: 18, label: "Vague Abstract Payload Claim", quote: "Send a specially crafted payload..." }, { regex: /always validate user input(s)? using/i, weight: 12, label: "Generic LLM Remediation Bullet", quote: "Always validate user inputs..." }, { regex: /keep all software packages updated/i, weight: 12, label: "Textbook Boilerplate Advice", quote: "Keep all software packages updated..." }, { regex: /unable to verify (this )?(live|in production|locally)/i, weight: 28, label: "Unverified / Theoretical Guesswork", quote: "Unable to verify live..." }, { regex: /blocked my (scanner|script|automated tool)/i, weight: 22, label: "Automated Fuzz / Scanner Dump", quote: "Blocked my scanner..." }, { regex: /cve-202[5-9]-[0-9]+/i, weight: 15, label: "Synthetic / Unassigned CVE Citation", quote: "Referenced speculative CVE tag" }, { regex: /defense-in-depth/i, weight: 8, label: "Generic AI Security Buzzword", quote: "defense-in-depth" } ]; // Concrete PoC validation indicators const POC_PATTERNS = [ { regex: /curl\s+-[A-Za-z0-9]/, bonus: 35, label: "Actionable cURL command" }, { regex: /```(bash|sh|python|go|ruby|js|javascript)[\s\S]*?```/, bonus: 30, label: "Structured reproduction code block" }, { regex: /http:\/\/(localhost|127\.0\.0\.1|[\w\.-]+:[0-9]+)/, bonus: 20, label: "Concrete local repro target address" }, { regex: /(--data|--data-binary|-d\s+|-H\s+)/, bonus: 15, label: "Specific HTTP payload flags" }, { regex: /docker run|git checkout/, bonus: 15, label: "Reproducible environment setup" } ]; let currentExportBlob = null; function analyzeReport() { const title = $('report-title').value.trim(); const component = $('target-component').value.trim(); const severity = $('claimed-severity').value; const body = $('report-body').value; const words = body.trim() ? body.trim().split(/\s+/).length : 0; $('token-counter').textContent = `${words} words`; if (words < 10) { $('status-bar').textContent = "Please provide report body content to perform triage audit."; $('status-bar').className = "status-bar error"; return; } $('status-bar').textContent = "Analyzing submission against hallucination markers and PoC depth..."; $('status-bar').className = "status-bar"; // 1. Calculate slop phrasing penalty let slopDetections = []; let slopScoreRaw = 0; SLOP_PATTERNS.forEach(pat => { const match = body.match(pat.regex); if (match) { slopScoreRaw += pat.weight; slopDetections.push({ type: "slop", label: pat.label, quote: match[0], weight: pat.weight }); } }); // 2. PoC analysis let pocBonusRaw = 0; let pocDetections = []; POC_PATTERNS.forEach(pat => { const match = body.match(pat.regex); if (match) { pocBonusRaw += pat.bonus; pocDetections.push({ type: "pass", label: pat.label, quote: match[0].substring(0, 60) + (match[0].length > 60 ? "..." : "") }); } }); // Extract code or curl let extractedPoCText = "# No runnable command sequence found."; const curlMatch = body.match(/curl\s+[^\n\r]+(\\\s*[\n\r]+[^\n\r]+)*/); const codeBlockMatch = body.match(/```[a-z]*\n([\s\S]*?)```/); if (curlMatch) { extractedPoCText = curlMatch[0]; } else if (codeBlockMatch) { extractedPoCText = codeBlockMatch[1].trim(); } $('extracted-poc').textContent = extractedPoCText; // Check file paths realism const pathMatches = body.match(/([a-zA-Z0-9_\-\.\/]+\.(c|go|py|js|php|rs|java|cpp|h|ts))/g); let pathScore = 15; if (pathMatches && pathMatches.length > 0) { pathScore = Math.min(100, pathMatches.length * 25 + (body.includes("line ") ? 20 : 0)); } // Mechanics Score let mechanicsScore = 20; if (body.includes("memcpy") || body.includes("overflow") || body.includes("deserializ") || body.includes("injection") || body.includes("sqli")) { mechanicsScore += 20; } if (pocBonusRaw > 20) mechanicsScore += 45; // Normalize final metrics const slopPercentage = Math.min(99, Math.max(5, slopScoreRaw)); const pocPercentage = Math.min(100, Math.max(2, pocBonusRaw)); const phrasingScore = Math.min(100, slopPercentage); const remediationScore = Math.min(100, Math.max(20, (body.includes("Remediation") || body.includes("Fix")) ? 40 : 15)); // Update UI numbers $('val-slop-index').textContent = `${slopPercentage}%`; $('val-poc-score').textContent = `${pocPercentage}%`; $('score-poc').textContent = `${pocPercentage}%`; $('fill-poc').style.width = `${pocPercentage}%`; $('fill-poc').style.background = pocPercentage > 50 ? 'var(--success)' : 'var(--danger)'; $('score-phrasing').textContent = `${phrasingScore}%`; $('fill-phrasing').style.width = `${phrasingScore}%`; $('fill-phrasing').style.background = phrasingScore > 50 ? 'var(--danger)' : 'var(--success)'; $('score-files').textContent = `${pathScore}%`; $('fill-files').style.width = `${pathScore}%`; $('score-mechanics').textContent = `${mechanicsScore}%`; $('fill-mechanics').style.width = `${mechanicsScore}%`; $('score-remediation').textContent = `${remediationScore}%`; $('fill-remediation').style.width = `${remediationScore}%`; // Verdict Logic const verdictBox = $('verdict-box'); const verdictHeading = $('verdict-heading'); const verdictDesc = $('verdict-desc'); const actionRec = $('action-recommendation'); const pill = $('triage-status-pill'); let triageAction = "AUTO-REJECT"; let cannedReply = ""; if (slopPercentage >= 60 && pocPercentage < 35) { verdictBox.className = "verdict-banner slop"; verdictHeading.textContent = `HIGH PROBABILITY AI SLOP (${slopPercentage}% CONFIDENCE)`; verdictDesc.textContent = "High concentration of generative LLM markers, boilerplate remediation, and unverified exploit assertions without concrete execution steps."; actionRec.textContent = "AUTO-REJECT"; actionRec.style.color = "var(--danger)"; pill.textContent = "FLAGGED AS SLOP"; pill.style.background = "var(--danger-light)"; pill.style.color = "var(--danger)"; $('val-slop-index').style.color = "var(--danger)"; $('val-time-saved').textContent = "~25 min"; cannedReply = `Thank you for contacting security triage regarding ${component}.\n\nAfter automated preliminary evaluation, this submission has been closed as Not Applicable / Missing PoC. The report contains generic theoretical impact claims and textbook remediation guidance without a reproducible, executable proof-of-concept (such as an authentic curl payload, test case, or local debugger trace).\n\nPer our program policy regarding automated scanner and generative AI submissions, claims lacking verifiable execution evidence cannot be triaged further.`; } else if (slopPercentage >= 35 || pocPercentage < 50) { verdictBox.className = "verdict-banner suspicious"; verdictHeading.textContent = "UNCERTAIN / NEEDS REPRODUCTION PROOF"; verdictDesc.textContent = "Possible valid vector but reproduction evidence is sparse or ambiguous. Request an exact standalone reproduction harness before assigning developer time."; actionRec.textContent = "REQUEST REPRO"; actionRec.style.color = "var(--warning)"; pill.textContent = "NEEDS CLARIFICATION"; pill.style.background = "var(--warning-light)"; pill.style.color = "var(--warning)"; $('val-slop-index').style.color = "var(--warning)"; $('val-time-saved').textContent = "~15 min"; cannedReply = `Thank you for your report on ${component}.\n\nOur triage team reviewed the description for "${title}". To proceed with reproduction and validation, please provide an exact standalone reproduction command (e.g. cURL request or minimal script) against a clean local deployment.\n\nWithout an executable trigger demonstrating actual security impact, we are unable to escalate this ticket to our engineering team.`; } else { verdictBox.className = "verdict-banner legit"; verdictHeading.textContent = "VERIFIED REPRODUCTION SIGNAL (LEGITIMATE)"; verdictDesc.textContent = "Concrete executable payload and verifiable code reference discovered. High signal-to-noise ratio suitable for immediate engineering review."; actionRec.textContent = "ACCEPT & REWARD"; actionRec.style.color = "var(--success)"; pill.textContent = "VALID SIGNAL"; pill.style.background = "var(--success-light)"; pill.style.color = "var(--success)"; $('val-slop-index').style.color = "var(--success)"; $('val-time-saved').textContent = "~45 min"; cannedReply = `Thank you for your detailed vulnerability disclosure regarding ${component}.\n\nWe have verified the provided reproduction steps and confirmed the impact in our testing environment. This issue has been escalated to the core maintainers for patching (Internal Reference: SEC-${Date.now().toString().slice(-5)}).\n\nWe will follow up with bounty determination and CVE coordination.`; } $('canned-text').value = cannedReply; // Render flagged signals const signalsList = $('signals-container'); signalsList.replaceChildren(); if (slopDetections.length === 0 && pocDetections.length === 0) { const neutral = document.createElement('div'); neutral.className = "signal-item"; neutral.innerHTML = `CLEANNo high-confidence AI slop patterns matched. Standard code review applies.`; signalsList.appendChild(neutral); } else { slopDetections.forEach(item => { const row = document.createElement('div'); row.className = "signal-item"; row.innerHTML = ` SLOP DETECTED
${item.label} (Penalty +${item.weight})
"${item.quote}"
`; signalsList.appendChild(row); }); pocDetections.forEach(item => { const row = document.createElement('div'); row.className = "signal-item"; row.innerHTML = ` VALID SIGNAL
${item.label}
${item.quote}
`; signalsList.appendChild(row); }); } // Draw Radar Chart drawRadar([ { label: "PoC Grounding", val: pocPercentage / 100 }, { label: "Mechanics Detail", val: mechanicsScore / 100 }, { label: "Code File Realism", val: pathScore / 100 }, { label: "Signal Authenticity", val: Math.max(0.05, 1 - slopPercentage / 100) }, { label: "Actionable Fix", val: remediationScore / 100 } ]); // Build Decision Export const exportData = { auditor: "BountySlop Radar v2.4", timestamp: new Date().toISOString(), report_title: title, target_component: component, claimed_severity: severity, diagnostic_scores: { slop_index_percent: slopPercentage, poc_executability_percent: pocPercentage, file_authenticity_percent: pathScore, mechanics_clarity_percent: mechanicsScore }, triage_action: actionRec.textContent, detected_markers: slopDetections.map(d => ({ label: d.label, excerpt: d.quote })), canned_maintainer_response: cannedReply }; if (currentExportBlob) URL.revokeObjectURL(currentExportBlob); const jsonStr = JSON.stringify(exportData, null, 2); const blob = new Blob([jsonStr], { type: "application/json" }); currentExportBlob = URL.createObjectURL(blob); const dlLink = $('download'); dlLink.href = currentExportBlob; dlLink.download = `triage-${component.replace(/[^a-z0-9]/gi, '_').toLowerCase()}-${Date.now()}.json`; dlLink.hidden = false; $('btn-export-json').href = currentExportBlob; $('btn-export-json').download = dlLink.download; $('status-bar').textContent = `Triage audit completed in 12ms. Action: ${actionRec.textContent}.`; } // Draw Pentagon Radar on SVG function drawRadar(vectors) { const svg = $('radar-svg'); svg.replaceChildren(); const cx = 110, cy = 110, r = 75; const n = vectors.length; // Background web circles/polygons [0.25, 0.5, 0.75, 1.0].forEach(level => { let pts = []; for (let i = 0; i < n; i++) { const angle = (Math.PI * 2 / n) * i - Math.PI / 2; const x = cx + Math.cos(angle) * r * level; const y = cy + Math.sin(angle) * r * level; pts.push(`${x.toFixed(1)},${y.toFixed(1)}`); } const poly = document.createElementNS("http://www.w3.org/2000/svg", "polygon"); poly.setAttribute("points", pts.join(" ")); poly.setAttribute("fill", level === 1.0 ? "#f6fbf9" : "none"); poly.setAttribute("stroke", "#d0dfdd"); poly.setAttribute("stroke-width", "1"); svg.appendChild(poly); }); // Axis lines for (let i = 0; i < n; i++) { const angle = (Math.PI * 2 / n) * i - Math.PI / 2; const x = cx + Math.cos(angle) * r; const y = cy + Math.sin(angle) * r; const line = document.createElementNS("http://www.w3.org/2000/svg", "line"); line.setAttribute("x1", cx); line.setAttribute("y1", cy); line.setAttribute("x2", x); line.setAttribute("y2", y); line.setAttribute("stroke", "#d0dfdd"); line.setAttribute("stroke-width", "1"); svg.appendChild(line); } // Data polygon let dataPts = []; vectors.forEach((v, i) => { const angle = (Math.PI * 2 / n) * i - Math.PI / 2; const val = Math.max(0.1, Math.min(1.0, v.val)); const x = cx + Math.cos(angle) * (r * val); const y = cy + Math.sin(angle) * (r * val); dataPts.push(`${x.toFixed(1)},${y.toFixed(1)}`); }); const dataPoly = document.createElementNS("http://www.w3.org/2000/svg", "polygon"); dataPoly.setAttribute("points", dataPts.join(" ")); dataPoly.setAttribute("fill", "rgba(2, 122, 117, 0.25)"); dataPoly.setAttribute("stroke", "#027a75"); dataPoly.setAttribute("stroke-width", "2.5"); svg.appendChild(dataPoly); // Data dots & labels vectors.forEach((v, i) => { const angle = (Math.PI * 2 / n) * i - Math.PI / 2; const val = Math.max(0.1, Math.min(1.0, v.val)); const x = cx + Math.cos(angle) * (r * val); const y = cy + Math.sin(angle) * (r * val); const circle = document.createElementNS("http://www.w3.org/2000/svg", "circle"); circle.setAttribute("cx", x); circle.setAttribute("cy", y); circle.setAttribute("r", "4"); circle.setAttribute("fill", "#027a75"); svg.appendChild(circle); }); } function loadPreset(key) { const data = PRESETS[key]; if (!data) return; $('report-title').value = data.title; $('target-component').value = data.component; $('claimed-severity').value = data.severity; $('report-body').value = data.body; analyzeReport(); } // Event Listeners $('btn-audit').addEventListener('click', analyzeReport); $('btn-clear').addEventListener('click', () => { $('report-title').value = ''; $('target-component').value = ''; $('report-body').value = ''; $('token-counter').textContent = '0 words'; $('extracted-poc').textContent = '# Ready for input'; $('signals-container').replaceChildren(); $('canned-text').value = ''; $('download').hidden = true; $('status-bar').textContent = 'Workspace cleared. Enter submission text or choose a preset.'; }); $('preset-hallucinated').addEventListener('click', () => loadPreset('hallucinated')); $('preset-canned-wp').addEventListener('click', () => loadPreset('cannedWp')); $('preset-legit').addEventListener('click', () => loadPreset('legit')); $('btn-copy-response').addEventListener('click', async () => { const text = $('canned-text').value; if (!text) return; try { await navigator.clipboard.writeText(text); const originalText = $('btn-copy-response').innerHTML; $('btn-copy-response').textContent = "Copied to Clipboard!"; setTimeout(() => { $('btn-copy-response').innerHTML = originalText; }, 1800); } catch (e) { $('canned-text').select(); document.execCommand('copy'); } }); // Real-time word counter on typing $('report-body').addEventListener('input', () => { const words = $('report-body').value.trim() ? $('report-body').value.trim().split(/\s+/).length : 0; $('token-counter').textContent = `${words} words`; }); // Initialize with Default Grounded Preset window.addEventListener('DOMContentLoaded', () => { loadPreset('hallucinated'); });
Enjoy this tool? Build your own with Super