One public artifact Up to ten findings Priority order Markdown delivery
ONE PUBLIC INTEGRATION · 24-HOUR DELIVERY
Find the dangerous assumptions before an agent does.
Get an independent, evidence-backed review of one public SKILL.md, MCP manifest, agent card, or small integration surface.
0.12SOL · ONE TIME
- Trust-boundary and credential-handling review
- Prompt-injection and unsafe-action findings
- Payment, callback, and external-request checks where applicable
- Prioritized Markdown report with concrete remediations
Defensive review only. No exploitation, credential use, private-system access, or guarantee that every vulnerability will be found.
01 · TRUST BOUNDARIES 02 · INPUT & PROMPT HANDLING 03 · SECRET EXPOSURE 04 · EXTERNAL REQUESTS 05 · ACTION AUTHORIZATION 06 · PAYMENT ASSUMPTIONS 07 · CALLBACK VALIDATION 08 · DATA RETENTION 09 · FAILURE MODES 10 · PRIORITY FIXES + EVIDENCE FOR EACH FINDING + CONCRETE REMEDIATIONS
AFTER PAYMENT
Send one public URL and the intended runtime.
Email the public transaction signature, the public artifact URL, intended agent/runtime, and your main concern. The 24-hour delivery window begins once those details arrive.
FIXED SCOPE
Actionable findings, not a scanner dump.
Every reported issue includes evidence, impact, priority, and a practical next change.
Private-system testing Credential use Exploit development Compliance certification