urumaworks · exploit receipt
Prove a web vulnerability, don’t just claim it.
urumaworks reproduces an XSS finding in an isolated sandbox, drives a real browser through the exact attack, and returns a signed, replayable verdict — VERIFIED, NOT REPRODUCED, or INCONCLUSIVE. Its trust comes from an independent oracle, not from how clever an AI is.
The AI drafts, it never decides
A model turns your finding into a typed reproduction plan. A deterministic browser oracle renders the verdict — the AI is never the judge.
Signed, re-checkable evidence
Every run emits an .xproof anyone can replay to recompute the verdict and re-verify the signature, with no access to our infrastructure.
Runs on your machine, free
The engine is open source and runs locally. Hosted compile and the results dashboard are the paid conveniences on top.
Open the dashboard
npx exploit-receipt verify proof.yml --push