At Pokee AI, security is a top priority. We value the work of security researchers who help us keep our platform and users safe. If you discover a security vulnerability, we want to hear from you.
Bounties are awarded based on the severity of the verified vulnerability. All reports are evaluated on a case-by-case basis.
Minor issues with limited impact, such as non-sensitive information disclosure, low-risk misconfigurations, or UI-level bugs with minimal security implications.
Issues that could lead to limited data exposure, privilege escalation in restricted contexts, or meaningful bypasses of non-critical security controls.
Severe vulnerabilities such as remote code execution, authentication bypass, SQL injection, access to sensitive user data, or full account takeover.
Pokee AI reserves the right to determine the final severity classification and reward amount for all reported vulnerabilities. Exceptional findings may receive higher rewards at our discretion.
Skills published to the Skill Marketplace are written by third parties, not by Pokee AI. Installing a Skill lets it act inside your own workspace on your behalf, and that decision — as with any third-party extension or package — rests with the user who installs it. We review submissions and apply confinement controls to limit what a malicious Skill can reach, but no review process can anticipate every possible attack, and we make no representation that any given Skill is safe.
Reports whose exploit path requires a user to install or run a Skill, and whose impact is limited to the data and privileges that user already holds, are therefore not eligible for a payout. This includes a malicious Skill reading, modifying, or exfiltrating to an external destination the installing user's own files, workspace contents, chat history, or connected-account credentials. A Skill you install acts with your access, and demonstrating that it can send your own data somewhere is a property of that decision rather than a vulnerability in Pokee AI.
This exclusion is about user choice, not about our confinement boundaries. Where a Skill reaches beyond the installing user's own access, we want to hear about it. The following remain fully in scope and eligible:
We are interested in vulnerabilities that have a real security impact. Examples include, but are not limited to:
Send your report to support@pokee.ai with "Bug Bounty" in the subject line.
Please include the following in your report:
We will acknowledge receipt of your report as soon as possible.
Our security team will review and attempt to reproduce the issue. We may reach out for additional information. Please allow us reasonable time to investigate and verify.
We will classify the severity based on factors including exploitability, impact, and affected scope. We do our best to evaluate every report fairly, and we welcome your input, but the final determination of severity and reward amount rests with Pokee AI.
Once the vulnerability is confirmed and patched, we will reach out to discuss and arrange the bounty payment.
When we extend a reward offer, it remains open for 72 hours. To accept, you must send a valid invoice within that window. If no invoice is received within 72 hours, the entire offer is voided in full and we are under no obligation to honor it. Any bugs that were to be rewarded as part of the same batch will need to be reassessed, and their severity and reward amounts may change as a result. This is, above all, a matter of fairness: the same vulnerability is frequently reported by more than one researcher. Voiding a lapsed offer lets us extend the reward to another eligible reporter who reported the same issue, so no one who reports in good faith is shut out.
We consider security research conducted in accordance with this policy to be authorized. We will not pursue legal action against researchers who discover and report vulnerabilities responsibly and in compliance with the rules above. If legal action is initiated by a third party against you for activities conducted in accordance with this policy, we will make it known that your actions were authorized by Pokee AI.
Help us keep Pokee AI safe. Report a vulnerability today.