An experiment
Hypothesis: if we list the security assumptions and tradoffs that cause the most confusion in bug reports, we will get fewer false positive bug reports from both human and LLM bughunters. We'd detail both the design decision ("all journalists can see all submissions") and the consequences ("we do not validate reply_uuid belongs to source_uuid").
We could list them in:
The plan:
An experiment
Hypothesis: if we list the security assumptions and tradoffs that cause the most confusion in bug reports, we will get fewer false positive bug reports from both human and LLM bughunters. We'd detail both the design decision ("all journalists can see all submissions") and the consequences ("we do not validate reply_uuid belongs to source_uuid").
We could list them in:
AGENTS.mdSECURITY.mdThe plan: