AI-powered guidance

AI Security Mentor

A lab-aware AI mentor that guides your bug bounty learning without spoiling answers. Four modes let you choose how much help you need, from concept explanations to reasoning review.

Four mentor modes

Switch between modes depending on where you are in the learning process. Each mode adjusts the level of guidance to match your needs.

Explain Simply

Ask the mentor to break down a security concept in plain language. If you do not understand what SSRF means or how CSP headers work, this mode gives you a clear explanation with examples before you attempt the lab.

Concept clarity No spoilers Beginner-friendly

Nudge

Stuck on a lab step? The Nudge mode gives you a directional hint without revealing the solution. It might point you toward the right file to examine, suggest a technique to try, or ask a guiding question that narrows your focus.

Directional hints Guided questions Progressive help

Review Reasoning

After you submit an answer, ask the mentor to review your reasoning. It will evaluate your logic, identify gaps in your analysis, and explain where your thinking was correct or off-track without just telling you the right answer.

Post-submission Logic evaluation Gap analysis

Solution Policy

Once you have completed a lab or explicitly revealed the solution, this mode provides a full walkthrough. It covers the vulnerability, exploitation path, impact assessment, and remediation with code examples.

Full walkthrough Post-completion Remediation code

Lab-aware context

The mentor does not give generic advice. It understands the specific lab you are working on and tailors its guidance to the challenge at hand.

Knows your current lab

When you ask a question during a lab, the mentor has access to the lab’s scenario, the technology stack, the vulnerability category, and which step you are on. It uses this context to give relevant guidance.

Tracks your progress

The mentor knows which labs you have completed, which paths you are enrolled in, and what your quiz scores look like. It can recommend related labs or suggest revisiting concepts you have struggled with.

Adapts to difficulty

On beginner labs, the mentor explains more and nudges gently. On advanced labs, it assumes you know the basics and focuses on edge cases, novel techniques, or methodology refinements.

Safety guardrails

The mentor is designed for authorized security practice only. It enforces strict boundaries to prevent misuse.

Authorized practice only

The mentor will refuse to help with targeting real-world systems you do not own or do not have explicit permission to test. If you ask how to exploit a vulnerability against a live third-party website, it will decline and redirect you to the relevant BountyLabs lab instead.

No weaponization

The mentor will not generate malicious payloads for real-world use, provide exploit chains for unpatched vulnerabilities, or assist with any activity that falls outside authorized educational practice.

Ethics-first responses

When discussing sensitive topics like authentication bypass or data exfiltration, the mentor always frames its guidance in the context of responsible disclosure, authorized testing, and educational understanding.

Scope awareness

The mentor respects the BountyLabs scope. It encourages you to practice within contained labs and will not help you extend techniques to out-of-scope targets or real infrastructure.

What the mentor can and cannot do

Clear boundaries help you know when to ask the mentor and when to figure things out yourself.

Can do

  • Explain security concepts in plain language
  • Provide directional hints when you are stuck
  • Review your submitted answers and reasoning
  • Walk through solutions after lab completion
  • Recommend labs and paths based on your progress
  • Clarify vulnerability classifications and severity
  • Explain remediation patterns with code examples
  • Answer questions about bug bounty methodology

Cannot do

  • Help target real-world systems without authorization
  • Generate payloads for use against live targets
  • Spoil lab answers before you attempt them
  • Guarantee that a technique will work on any specific target
  • Provide legal advice on testing authorization
  • Access external systems or APIs on your behalf
  • Replace hands-on practice with theoretical answers
  • Claim to be a substitute for professional security training

Example mentor interactions

See how the mentor responds in real learning scenarios across its four modes.

Explain Simply — SSRF question

You: What is SSRF and why does it matter?

Mentor: SSRF stands for Server-Side Request Forgery. It happens when an application makes a network request to a URL that an attacker can control. The danger is that the server can reach internal services that are not exposed to the public internet — like cloud metadata endpoints, internal APIs, or databases. An attacker can use SSRF to read internal data, scan internal networks, or pivot to other services.

Nudge — Stuck on a lab

You: I cannot find the injection point in this PHP lab.

Mentor: Look at how the application handles the file parameter in the include statement. Where does user input first enter the application, and does it reach the include without sanitization? Try tracing from the query string to the sink.

Review Reasoning — Post-submission

You: I said this is a stored XSS because the comment is saved and rendered on another page.

Mentor: Your classification is correct. The input is stored and reflected without encoding. However, your impact assessment understates the risk — consider that an attacker can steal session tokens from any user who views the comment, not just the poster. Also, check whether the Content-Security-Policy header would block inline script execution.

Solution Policy — Full walkthrough

You: Show me the full solution for the IDOR lab.

Mentor: The vulnerability is in /api/orders/{id}. The endpoint checks authentication but not authorization. Changing the order ID in the URL to another user’s order ID returns their data. The fix: verify that the authenticated user owns the requested order before returning it. Use a server-side ownership check, not client-side filtering.

Get guided, not spoiled.

The AI mentor helps you learn security concepts deeply while keeping the challenge intact. Start a lab and ask the mentor whenever you need a nudge.

Start Training with the Mentor