Skip to content

Auditor onboarding + PoC template #123

Description

@truthixify

Tier: S (1-2 days) | Type: docs

Context. reference/security-disclosure.mdx and reference/threat-model.mdx landed in Wave 7 but there is no on-ramp for a researcher who wants to actually file a finding: no repro-repo template, no severity matrix, no reward posture spelled out. Auditors expect a one-page "start here" that mirrors what large protocols publish.

Scope.

  • New reference/auditor-guide.mdx.
  • Severity matrix (Critical/High/Medium/Low) with concrete Wraith-shaped examples.
  • Reward posture (or explicit "reputation-only" if that is the current state).
  • PoC repo template link + expected structure (README, repro script, expected output).
  • SLA table (ack, triage, fix, disclosure).
  • Cross-link with security-disclosure.mdx and threat-model.mdx.

Acceptance.

  • Severity examples reviewed by contracts maintainer
  • Template repo link resolves
  • Renders in mint dev
  • Passes Compile docs snippets CI
  • Linked from both security-disclosure.mdx and per-repo SECURITY.md

Files. reference/auditor-guide.mdx (new), reference/security-disclosure.mdx.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Stellar WaveIssues in the Stellar wave programdocsDocumentationdripsFunded via Drips Networkhelp wantedExtra attention is neededsecuritySecurity-sensitive workstellar-waveAuto-created for Wave 8wave-8Auto-created for Wave 8writing

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions