Here is my application: [describe it, or paste the routes, API surface and integrations].<br/><br/>Find every feature where a user supplies a URL or an address and my server fetches it. Link previews, citation and metadata fetchers, webhook testers and endpoints, image proxies, RSS or feed importers, URL unfurlers, avatar imports, PDF or document fetchers, OAuth redirect handling, anything that validates a remote resource.<br/><br/>For each, tell me what the server can reach when it makes that request - internal services, cloud metadata endpoints, other customers' hosts, the public internet.<br/><br/>Anything on that list is a proxy. Treat the list as the finding.
Here are my current rate limits and quotas: [paste them]. Here is my normal traffic shape: [requests per day, peak concurrency, typical session].<br/><br/>Tell me what each limit implies about who it was written for, then model what happens under agent traffic: sustained parallel requests, no think time between calls, retries without backoff, and a crawl that walks every link it finds.<br/><br/>Identify which limit breaks first and what it takes down with it. Be specific about the resource that actually exhausts - connections, database, memory, a downstream API quota.
My current bot detection is: [describe it - user agent checks, robots.txt, rate limits, CAPTCHA, fingerprinting].<br/><br/>Explain why each of those fails against a well-behaved agent that identifies itself honestly, respects robots.txt, stays under per-minute limits, and makes requests that look individually reasonable.<br/><br/>Then tell me what signal WOULD distinguish it: request patterns, breadth of traversal, timing regularity, the ratio of reads to writes, sequences no human session produces.<br/><br/>I want detection based on behaviour, not identity.
Here are the endpoints where users can write configuration, settings or content: [paste or describe them].<br/><br/>For each field, tell me whether its value is ever interpreted rather than just stored - fetched as a URL, executed as a template, parsed as a query, used as a path, passed to another service.<br/><br/>Those fields are the ones to worry about. Rank them by what an attacker gains from controlling the value, and tell me what validation each needs.<br/><br/>Include fields that look inert, like display names and descriptions, if anything downstream renders or resolves them.
My service is: [describe it, and who uses it].<br/><br/>Help me decide a position on AI agents rather than drifting into one. Argue each honestly:<br/>- allow and serve them properly, with a documented API and sane limits<br/>- allow but meter, with identification and a quota<br/>- block what I can and accept the arms race<br/>- charge for programmatic access<br/><br/>Tell me which my situation supports given my costs, my users, and whether agent traffic creates value for me or only consumes capacity.
Draft the template I would use to disclose an incident caused by automated traffic against my service.<br/><br/>It should cover: what was observed, what was affected, what I can and cannot attribute, what I have changed, and what I am asking of the party involved.<br/><br/>Build in a clear separation between what I MEASURED and what I BELIEVE. If I name a company, the note must make clear which it is.<br/><br/>Keep it factual. No outrage, no speculation dressed as finding.