An app may be able to read files outside of its sandbox
Researcher profile
Security researcher and cloud/DevOps engineer. I break systems responsibly, and I build them to stay up. On the offensive side: 12 published CVEs, with fixes and credits from Apple, CISA, and the NSA, spanning web authentication, SSRF, broken access control, injection, and path traversal, including AI/ML agent frameworks like AutoGPT. On the engineering side: 4+ years building and operating AWS and on-prem infrastructure for a national education platform.
Credibility earned elsewhere: verified platform standing, vendor-confirmed credits and reviewed evidence.
What you’ve added here: reviews written, and how useful others found them.
How this BugScore is built
BugScore weighs signal by how hard it is to fake: HackerOne’s own percentiles, vendor-confirmed credits, and evidence a moderator checked. Writing reviews here does not move it. That is Contribution, below. It is a signal to weigh, not a warranty.
How this Contribution is built
Contribution measures citizenship on BugRater: reviews, helpful votes, breadth, and tenure. It is cheap to earn by design, and it is kept deliberately separate from BugScore so activity here can never stand in for demonstrated skill.
Pavan Nallamothu can attach a fresh, time-limited attestation of this badge to a report on any platform. It attests track record: never a legal identity, and never a guarantee.
Pavan Nallamothu hasn’t published any reviews yet.
Verified on GitHub. Reviews they write will carry extra weight.