A workbench for security researchers

Make your next report easier to defend.

Bring the code. Choose a specialist review. Leave with observations, counterarguments, and the evidence your next step needs.

Review my code

The example needs no account or API key. Your first hosted review each day is free.

provider-error-review.mdExample
provider_client.py Lines 2–3
2 if response.status_code >= 400:
3     return {"error": response.text}

The code shows an error body.
The draft claims a credential leak.

What closes the gap?

Evidence of the response contents and the affected caller. The supplied files don’t establish either.

Next step

Return a stable public error and verify the change locally.

Impact unrated
A prewritten walkthrough. Load it to inspect the files and download the packet.
Built by Tradi32nd Firelight8th QuantusView the public research record ↗
1

Choose your files

Upload, paste code, or import an authorized GitHub file. Pick the review that fits.

2

Check and review

Inspect what leaves the tab. Use your own API key or take the request to your AI client.

3

Keep the evidence

Download the review, next steps and exact file manifest. Continue from a clear record.

Your next review

One review. Three simple steps.

Files stay in this tab until you run a review

Choose the material to review

  • No files selected.
Paste code instead
Import a GitHub file

Only this file is read, at an exact commit. GitHub requests go directly from your browser. Use a fine-grained token with read-only Contents access to the selected repository.

Add scope & evidence notes For code or report reviews

Scope, version, and prior art have not been established.

Privacy checks run in your browser. Preview the exact request before you send it.

Run the review

Free · 1/day

Choose where the review runs. Your checked request is ready to preview.

Your key and files pass through our server to the selected provider. We do not save them. Provider usage is billed by that provider.

Sign in with a passkey to use your free daily AI review.

Your review will appear here.

It will reference the supplied files, flag uncertain claims, and suggest fixes.

Choose your pace

Pay for the workspace.
Choose your own AI.

Keep your choice of model.
All profiles and AI connections on both plans.

Free

For an occasional review
$0

No card. No expiry.

  • One hosted AI review per UTC day
  • All three specialist review profiles
  • Web and MCP share the same daily allowance
  • Local privacy check and prompt export
  • Downloadable review and file manifest
Start free

Your AI provider bills its usage separately. US$10/week, renewing weekly until cancelled. Cancel online; keep access through your paid period. File limits and fair use apply. Any applicable tax is shown at checkout.

What the workbench adds

Your AI does the analysis.
The workflow keeps it grounded.

Control

See exactly what leaves.

Check for secrets, preview the full request, and send only the selected files. The manifest records their hashes.

Evidence

Make the gaps visible.

Keep scope, version, local proof, and prior art alongside the code. Missing evidence and same-root overlap stay explicit.

Counterarguments

Ask for the case against it.

Every review asks for the strongest counterargument, code references, defensive fixes, and unresolved questions.

Handoff

Leave with a usable packet.

Download the review, supplied evidence notes, and exact file manifest together. Carry the context into your next review.

Spend less time rebuilding context. Keep the files, evidence, counterarguments, and next steps together.

Public research record

Built by an active researcher.

Research by Tradi3. Published competition results and findings are linked below.

High + Medium

Revert Finance

Publicly confirmed findings from the StableSwap Hooks competition on Cantina.

Published results ↗

Also published: Metric findings on Sherlock · Full audit portfolio

ENS: competition complete. Results coming next. Current programme status ↗

Published researcher results · Updated 2 October 2026.

A useful place to start.

Turn scattered notes into a clear report. The guide and template are free.

Open the report guideUse it from your AI client

Good to know

Can I use ChatGPT or Claude subscriptions?

Yes, through prompt export: check your files, download the prompt, and paste it into your chat app. A chat subscription is separate from API billing. Hosted reviews require an OpenAI or OpenRouter API key.

What do you keep?

Account and passkey records, hashed session and AI connection tokens, review activity, and billing references. We do not store uploaded code, prompts, API keys, or review results. The provider you choose has its own data and retention policies.

What does a review include?

Code references, evidence gaps, counterarguments, suggested fixes, and a downloadable review packet. Add your scope, version, and proof to give your model the context it needs.

What are the review limits?

Each review accepts up to 20 text files: 120 KB per file and 240 KB combined, with a two-minute provider timeout. Operator removes the daily review cap and runs one review at a time. It is for individual use; automated bulk use and account sharing are excluded.

Is the open-source kit still free?

Yes. The command-line kit remains free. The subscription pays for repeated reviews through the hosted website. You can use the kit with your own API endpoint or local model.

Your account

Your Operator portal

Use a passkey to sign in. No password or email needed.

Use a recovery code

Before you send

The exact review request.

This contains your selected text and evidence notes. The API key is excluded from this preview.