Cloudflare on their vulnerabilty discovery harness
- Recon: Read the codebase, return an architecture doc
- Hunt: ~50 agents look for bugs concurrently
- Validate: Independent agents try to disprove findings
- Gapfill: Areas that need a 2nd pass are flagged
- Dedup: Findings with the same root cause combined
- Trace: Confirms if attacker input reaches the bug
- Feedback: If reachable, becomes new hunt tasks
- Report: Write report with predefined schema
