Skip to content

Auditor onboarding + PoC template #123

Description

@truthixify

Tier: S (1-2 days) | Type: docs

Context. reference/security-disclosure.mdx and reference/threat-model.mdx landed in Wave 7 but there is no on-ramp for a researcher who wants to actually file a finding: no repro-repo template, no severity matrix, no reward posture spelled out. Auditors expect a one-page "start here" that mirrors what large protocols publish.

Scope.

  • New reference/auditor-guide.mdx.
  • Severity matrix (Critical/High/Medium/Low) with concrete Wraith-shaped examples.
  • Reward posture (or explicit "reputation-only" if that is the current state).
  • PoC repo template link + expected structure (README, repro script, expected output).
  • SLA table (ack, triage, fix, disclosure).
  • Cross-link with security-disclosure.mdx and threat-model.mdx.

Acceptance.

  • Severity examples reviewed by contracts maintainer
  • Template repo link resolves
  • Renders in mint dev
  • Passes Compile docs snippets CI
  • Linked from both security-disclosure.mdx and per-repo SECURITY.md

Files. reference/auditor-guide.mdx (new), reference/security-disclosure.mdx.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave programdocsDocumentationdripsFunded via Drips Networkhelp wantedExtra attention is neededsecuritySecurity-sensitive workstellar-waveAuto-created for Wave 8wave-8Auto-created for Wave 8writing

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions