Skip to main content
A good report lets the triage agent reproduce the flaw on the first turn. Write one flaw in each report.

Start a draft

On a program page, select Start a report. The draft page opens. Only you can see a draft. If the button shows Sign in to report or Verify email to report, complete that step first.

Fields

Title

Write the flaw type and the location. For example: Stored XSS in project name on the dashboard.

Affected asset

Write the exact URL, host, app, API, or repository. The asset must be in the program scope.

Description

The description starts from a template with four headings:
Description template
Write text under the headings. You cannot submit the template with no text.
  • Steps to reproduce: number each step. Include the exact requests, parameters, and accounts. Use the test accounts that the program gives, if it gives them.
  • Expected behavior: what the system must do.
  • Actual behavior: what the system does.
  • Security impact: what an attacker can do, to which data or users, and under which conditions.
Put one flaw in each report. A flaw is one root cause with one impact. If you found more than one flaw, submit a separate report for each. The triage agent checks only the first flaw in a report.

Attach evidence

Attach screenshots, request logs, scripts, or videos to the draft.
  • Select the paperclip on Description, or drop files on the field.
  • Kalligator saves the draft and puts a Markdown link to the file at the cursor, for example [request.txt](/reports/<report_id>/files/<file_id>).
  • Each file is private. Only you, the triage agent, and the Kalligator team can open it.
The triage agent cannot open Office documents. Send a PDF or plain text instead.
Files that you attach but do not link are still sent with the report. Remove the files that you do not need. To remove a file, first remove its link from the text.

Add a severity estimate

Your severity estimate is optional. Select a value for each of the eight CVSS 3.1 base metrics. The page shows the score, the severity, and the vector. Triage treats your vector as unverified. The agent scores the report from its own evidence. The severity that triage assigns is not shown to you.

Save the draft

Select Save draft. Each save increments the draft Revision. If you edit the same draft in two sessions, the page shows This draft changed in another session. Select Reload their version, or select Copy my text to keep your changes.
A draft does not hold priority. If another hacker submits the same flaw first, their report can win. See Duplicates.

Write a draft with the API

You choose the report ID. Make a new UUIDv4 and send revision: 0.
Create a draft
The response is the report with revision: 1. Send that revision with your next change. See PUT /api/reports/{report_id} and PUT /api/reports/{report_id}/files/{file_id}.

Next step

Submit the report.