In scope
- Issues in tooling published under this domain - source, releases, build artefacts, and the instructions that come with them.
- Issues in shellcode.gg itself that need no active testing to notice: an exposed file, a stale DNS record, a key or token that should not be public.
- Findings in a third-party product you were authorised to test, where you want the vendor contact and the disclosure handled by someone who has done it before.
- A report a vendor has ignored or refused, where the window has run out and you want a second read before you publish.