How one bug bounty researcher chooses the features they investigate
GitHub's top security researcher shares insights on how she selects areas to investigate in the platform's ecosystem.
Intelligence analysis by Qwen 2.5 (3B)

GitHub's bug bounty program has a new focus on rewarding high-quality, high-impact work. Shilpa Kumari, a top researcher, discusses her approach to choosing areas for investigation and the tools she uses.
Shilpa looks for tricky parts of GitHub to check. She uses her experience to find interesting stuff. She uses AI to help, but she always checks the AI's work.
Analysis
Shilpa's Approach to Target Selection
Shilpa starts by identifying complex and hard-to-understand areas within GitHub's ecosystem. She uses her experience to quickly assess whether a feature is worth her time. Once she finds something interesting, she spends time exploring the feature until something unusual happens. She then tests for different types of bugs.
Leveraging AI in Bug Bounty
Shilpa uses AI to save time and increase her productivity. However, she emphasizes the importance of verifying AI-generated findings and never submitting a finding without confirmation.
The Future of Bug Bounty
As more AI-powered features are released, Shilpa believes the mindset for testing these features remains similar to traditional web bugs. She advises researchers to always verify AI-generated findings.
Key points
- Shilpa starts by looking for tricky parts of GitHub to check.
- She uses her experience to find interesting stuff.
- She uses AI to help, but always verifies the findings.
- As more AI features are added, the skills for finding bugs remain similar.
- Researchers should always verify AI-generated findings.
As more AI features are added, researchers can use similar skills to find bugs. This will help keep the security of GitHub and other platforms strong.
If researchers don't verify AI-generated findings, they might miss important bugs.