Review stage 01
Public-surface review boundary
A safe public review starts with the network boundary—not with a clever detector.
No target fetch is active
The proposed reviewer accepts only a public HTTPS authority, uses a strict versioned POST contract, validates Turnstile and rate limits before resolution, checks every A/AAAA answer, and revalidates redirects. The selected Cloudflare runtime cannot pin an arbitrary outbound hostname to the exact address set validated before connection. That leaves a DNS-rebinding gap, so the production handler returns a disabled result and performs no outbound target request.
Use the no-network workspaceDocumented single bounded review
Would inspect
- Submitted public HTML page
- Response and security headers
- Direct same-origin notice, terms, contact and rights links
- Visible form labels and collection context
Would never do
- Execute target JavaScript or submit forms
- Authenticate, accept cookies or send user headers
- Scan ports, test vulnerabilities or evade robots
- Store URLs, bodies, answers or reports