24/7 deep multi-model bug-hunting automation for OneCode GmbH (Oliver Maicher bug-bounty hub).
Scope: *.onecode.de, kurs.onecode.de; All company-owned infrastructure, web applications, APIs, development platforms, cloud environments, customer portals, websites, and domains operated by OneCode GmbH
(full exclusion + rules list in scope.yml)
Pipeline (all workflows run every 20 minutes):
- Deep Hunt (
hunt.yml): analyst hunts the discovered inventory + hypotheses, emits structured leads, chains primitives, self-critiques. Models: mimo. - Triager (
triage.yml): second-model 7-Question Gate validation + live passive probe; keeps running count inreports/valid-bugs.md. - Reposcan (
reposcan.yml): deep source scan of any public GitHub org (if configured). - Sync Issues (
sync-issues.yml): mirrors leads to GitHub issues.
Testing discipline: rate-limited (1 rps), no DoS/account-lockout, writes only on non-prod/test assets, no exposure of customer/employee/financial/auth data, secrets committed only as hashes.
IMPORTANT: the pipeline produces CANDIDATE leads. A reportable, validated finding requires human triage + proof against the program's gate. No finding is fabricated; scanner output alone is never accepted.
Artifacts:
| Artifact | Purpose |
|---|---|
leads/ |
Candidate findings (UNVALIDATED) |
triage/ |
Validation verdicts |
reports/valid-bugs.md |
Validated findings + running count |
scope.yml |
Program scope and exclusions (edit to adjust) |
Program description: German software development company providing mobile app development, backend engineering, DevOps, and custom software solutions