# bounty-goal

Report a critical finding whose PoC reproduces from a clean environment via a repeatable script and a short report naming the affected component, what the attacker gains, and the fix (Re-run the PoC from a clean environment every turn - it reproduces exactly, or it isn't a finding); Nothing out of scope; read the program policy first and reproduce only on assets you own; touch only notes/**, pocs/**; or the PoC reproduces from a clean environment and the report is written or scope is exhausted with no critical candidate left or three turns pass with no new lead

- **Kind:** goal
- **Source:** https://github.com/forefy/.context
- **Page:** https://forefy.com/goals/ab7ad8f1-8909-4bd4-a2a9-87a5902453e1
- **API (JSON + files):** https://forefy.com/api/asr/ab7ad8f1-8909-4bd4-a2a9-87a5902453e1

---

## goal.md

---
kind: goal
schema: goal.v1
name: bounty-goal
description: Land one critical, reproducible bug on a bounty program's in-scope target.
end_state:
  - Report a critical finding whose PoC reproduces from a clean environment via a repeatable script and a short report naming the affected component, what the attacker gains, and the fix
proof:
  - Re-run the PoC from a clean environment every turn - it reproduces exactly, or it isn't a finding
guardrail:
  invariants:
    - Nothing out of scope; read the program policy first and reproduce only on assets you own
  allowed_paths:
    - notes/**
    - pocs/**
termination:
  stop_on:
    - the PoC reproduces from a clean environment and the report is written
    - scope is exhausted with no critical candidate left
    - three turns pass with no new lead
---

