Downloads · 30 days
0
macmacmacmac/VibeThinker-3B-BugBounty-Triage
VibeThinker-3B-BugBounty-Triage is a text generation model from macmacmacmac. Use it when you need the model to write or continue text. It is set up for mlx. The card lists the license as mit.
A LoRA fine-tune of WeiboAI/VibeThinker-3B that triages bug-bounty / vulnerability-disclosure submissions into a structured verdict — disposition, severity, confidence, and a rationale — and is hardened against prompt…
Downloads · 30 days
0
Access
Public
Updated Jun 21, 2026
Repo size
947 MB
Likes
3
Public
Click a slice to open those files.
.safetensors120 MB · 100%
From the Hugging Face model README
A LoRA fine-tune of WeiboAI/VibeThinker-3B that triages bug-bounty / vulnerability-disclosure submissions into a structured verdict — disposition, severity, confidence, and a rationale — and is hardened against prompt-injection and AI-generated "slop" reports.
Project name: VibeBounty. This repo hosts the trained LoRA adapter (mlx-lm format); fuse it onto the base model to get a standalone model.
Given a report (title, asset, description, steps, impact), it emits a JSON verdict over a 9-class disposition taxonomy:
valid_impactful · valid_low · corroborated_surge · likely_duplicate · out_of_scope · theoretical_no_poc · self_inflicted · accepted_risk · slop
plus a severity estimate, a confidence gated by claim-reliability, and questions for the researcher.
| file | purpose |
|---|---|
adapters/adapters.safetensors | final LoRA adapter (iter 2000, mlx-lm) |
adapters/adapter_config.json | adapter / training config |
lora_config.yaml | full mlx-lm LoRA recipe |
pip install mlx-lm huggingface_hub
hf download macmacmacmac/vibebounty --local-dir vibebounty
# fuse adapter -> standalone model
mlx_lm.fuse --model WeiboAI/VibeThinker-3B \
--adapter-path vibebounty/adapters --save-path vibethinker-bbtriage
# generate
mlx_lm.generate --model vibethinker-bbtriage \
--prompt "Triage this report: IDOR in invoice download ..."
Or load the base + adapter directly with mlx-lm without fusing
(--adapter-path vibebounty/adapters).
mask_prompt// IDOR: GET /api/v2/invoices/{id} returns other tenants' invoices
{"disposition": "valid_impactful", "severity_estimate": "high",
"reasoning": "IDOR / broken-authz against an authenticated API; incrementing id
walks the table -> crosses a real trust boundary with demonstrated impact.",
"confidence": 0.9}
// Log4Shell report with an EXTERNAL CORROBORATION block (CVE-2021-44228, CISA KEV)
{"disposition": "corroborated_surge", "severity_estimate": "critical",
"reasoning": "Maps to a publicly disclosed advisory confirmed by the live feed
(actively exploited) -> corroborated, not spam.",
"used_external_corroboration": true, "confidence": 0.9}
| metric | heuristic + defense baseline |
|---|---|
| accept / reject accuracy | 97.3% |
| disposition accuracy (9-class) | 56.3% |
| macro-F1 | 0.191 |
| severity within-1 | 71.0% |
| adversarial defense suite | 6 / 6 pass |
Verdicts are guarded by ground-truth checks the model can't talk past:
prompt-injection isolation, claim-level verification (fabricated code symbols → slop),
and threat-intel corroboration (CVE/KEV/OSV → corroborated_surge, never spam).
Offline adversarial suite: 6/6.
~18k bug-bounty / vulnerability-disclosure reports compiled from publicly
disclosed sources — primarily disclosed HackerOne reports plus additional
public bug-bounty and Web3 disclosure corpora. Every example's label is
derived from the real adjudicated outcome recorded in the data (HackerOne
substate, severity, bounty amount, vote count, and any associated CVE) and
mapped onto the 9-class disposition taxonomy — the labels are not synthetic.
Each report is rendered as chat (system + user report → assistant reasoning +
verdict JSON); when a CVE is present, a live threat-intel corroboration block is
rendered exactly as the inference pipeline emits it. ~300 reports are held out as
a test split for evaluation.
The triage flow and its defenses are grounded in recent literature:
slop), not detection.Decision-support "sidecar" for analysts, not an autonomous adjudicator. It reflects the biases of the disclosure outcomes it was trained on; always keep a human in the loop for accept/reject and severity. License inherits from the base model — verify before redistribution.