Silens

The work after
the finding.

We turn confirmed evidence into a focused vulnerability report, keep every claim traceable, and gives triage a quality report.

Preview

Summary

An authenticated user can replace the export identifier in a download request and retrieve a CSV generated by a second researcher-owned test account. The response returns 200 and includes that controlled account’s email address.

Steps to Reproduce

  1. 01Create one export from each of two researcher-owned test accounts.
  2. 02Copy Account A’s authenticated download request.
  3. 03Replace only the export identifier with Account B’s identifier.
  4. 04Send the request and observe Account B’s controlled record in the response.

Impact

A user can access a private record belonging to another account without authorization.

A clear chain from proof to triage.

The finding is already hard enough. The handoff should make the vulnerable behavior, demonstrated impact, and supporting material immediately understandable.

  1. 01

    Evidence automatically attached

    Requests, responses, screenshots, video, files, and notes stay beside the exact claims they support.

  2. 02

    Reports in your style

    Edit the Markdown, title, program format, and every proposed update before anything changes.

  3. 03

    Reportability

    Incomplete, unsupported, or likely non-reportable findings are flagged before you submit.

Works where the research happens.

When a finding is confirmed, the report arrives in your own format, evidence, and poc ready for triage.

$

Codex

Invoke $silens from the research conversation.

/

Claude Code

Invoke /silens with the same local workflow.

One workspace.
No submission lock-in.

Stronger reports. Faster handoffs. Silens flags missing evidence, unsupported claims, and incomplete reproduction before they reach triage.

Researcher

$0for 7 days

Then $10 / month. Cancel anytime.

Free trial
  • ✓Desktop workspace
  • ✓Codex & Claude integrations
  • ✓Program-aware formats
  • ✓Evidence and portable proofs