Tier: S (1-2 days) | Type: docs
Context. reference/security-disclosure.mdx and reference/threat-model.mdx landed in Wave 7 but there is no on-ramp for a researcher who wants to actually file a finding: no repro-repo template, no severity matrix, no reward posture spelled out. Auditors expect a one-page "start here" that mirrors what large protocols publish.
Scope.
- New
reference/auditor-guide.mdx.
- Severity matrix (Critical/High/Medium/Low) with concrete Wraith-shaped examples.
- Reward posture (or explicit "reputation-only" if that is the current state).
- PoC repo template link + expected structure (README, repro script, expected output).
- SLA table (ack, triage, fix, disclosure).
- Cross-link with
security-disclosure.mdx and threat-model.mdx.
Acceptance.
Files. reference/auditor-guide.mdx (new), reference/security-disclosure.mdx.
Tier: S (1-2 days) | Type: docs
Context.
reference/security-disclosure.mdxandreference/threat-model.mdxlanded in Wave 7 but there is no on-ramp for a researcher who wants to actually file a finding: no repro-repo template, no severity matrix, no reward posture spelled out. Auditors expect a one-page "start here" that mirrors what large protocols publish.Scope.
reference/auditor-guide.mdx.security-disclosure.mdxandthreat-model.mdx.Acceptance.
mint devCompile docs snippetsCIsecurity-disclosure.mdxand per-repoSECURITY.mdFiles.
reference/auditor-guide.mdx(new),reference/security-disclosure.mdx.