Start a draft
On a program page, select Start a report. The draft page opens. Only you can see a draft. If the button shows Sign in to report or Verify email to report, complete that step first.Fields
Title
Write the flaw type and the location. For example:Stored XSS in project name on the dashboard.
Affected asset
Write the exact URL, host, app, API, or repository. The asset must be in the program scope.Description
The description starts from a template with four headings:Description template
- Steps to reproduce: number each step. Include the exact requests, parameters, and accounts. Use the test accounts that the program gives, if it gives them.
- Expected behavior: what the system must do.
- Actual behavior: what the system does.
- Security impact: what an attacker can do, to which data or users, and under which conditions.
Attach evidence
Attach screenshots, request logs, scripts, or videos to the draft.- Select the paperclip on Description, or drop files on the field.
- Kalligator saves the draft and puts a Markdown link to the file at the cursor, for example
[request.txt](/reports/<report_id>/files/<file_id>). - Each file is private. Only you, the triage agent, and the Kalligator team can open it.
The triage agent cannot open Office documents. Send a PDF or plain text instead.
Add a severity estimate
Your severity estimate is optional. Select a value for each of the eight CVSS 3.1 base metrics. The page shows the score, the severity, and the vector. Triage treats your vector as unverified. The agent scores the report from its own evidence. The severity that triage assigns is not shown to you.Save the draft
Select Save draft. Each save increments the draft Revision. If you edit the same draft in two sessions, the page shows This draft changed in another session. Select Reload their version, or select Copy my text to keep your changes.A draft does not hold priority. If another hacker submits the same flaw first, their report can win. See Duplicates.
Write a draft with the API
You choose the report ID. Make a new UUIDv4 and sendrevision: 0.
Create a draft
revision: 1. Send that revision with your next change. See PUT /api/reports/{report_id} and PUT /api/reports/{report_id}/files/{file_id}.