TasksSecurityEngineering track

Spot the JWT mistakes

eng-sec-05suite v1.0code

Quality15%judge panel
Correctness60%deterministic · vuln-checklist
Completeness25%judge panel

Exact prompt sent to every model

Below is a Python authentication middleware that validates JWTs issued by the same service. Users report nothing wrong. Find every security flaw, explain the attack for each, and return a fixed version with # file: <path> first line. Keep the same public interface.

A private fixture (eng-sec-05/src) is shown to the model but not published.

Responses

Latest published run: gemini-3.8-flash. For each model the repeat closest to its published median is shown; every repeat is in the repository.

No published attempts for this task yet

When the run is published, every model's raw response, per-dimension scores, judge rationales, human review notes and rendered artifacts appear here side by side.