No reproducer, no finding.
Every issue ships with the exact script that triggers it. If we can't reproduce it on demand, we don't report it. This is the single biggest filter between real work and a glossy deck — and it's what the current OWASP guidance for AI testing explicitly requires.
