“XBOW submitted nearly 1,060 vulnerabilities. All findings were fully automated, though our security team reviewed them pre-submission to comply with HackerOne’s policy on automated tools.”
An AI pentester hit number one on HackerOne’s US leaderboard. Humans reviewed every report before it went out. Of 1,060 submissions, 208 were duplicates and 209 were marked informative. Bug bounty triage teams now process machine output at scale, and one program kicked XBOW out for breaking its no-scanners rule.