Bugmine
Demilade Ayeku · Team Bugzy
Submitted to The Secure Program Synthesis Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.
A commit-grounded pipeline for turning Code4rena access-control reports into self-validated Halmos property tests.

Reviews
Thank you for this great work!
This is super relevant to security engineers who – now in a Mythos world – sit on a huge amount of vulnerability reports but are bottlenecked on translating those into formal / code-based validators. I'd recommend strengthening the framing as to how this work relates to wider AI Safety.
Otherwise, this is a pleasure to read with a crystal-clear structure, strong methodology and interesting findings. Thank you also for the video walkthrough which was super helpful.
Aside from somewhat uncertain impact potential concerns, I would have also been interested to see use of stronger models/agent loops, or ablations with several intermediate steps in the pipeline removed. I'm sceptical that Opus would particularly benefit, for example, from the extract step.
Cite this project
@misc{ayeku2026bugmine,
title = {{Bugmine}},
author = {Demilade Ayeku},
year = {2026},
month = may,
note = {Submitted to The Secure Program Synthesis Hackathon, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/bugmine-ycye}},
url = {https://apartresearch.com/sprints/projects/bugmine-ycye}
}More from The Secure Program Synthesis Hackathon
- View project: Vibe-Coding Specs: Eliciting, Editing, and Verifying Specifications for AI Coding Agents
Vibe-Coding Specs: Eliciting, Editing, and Verifying Specifications for AI Coding Agents
Lida Safety
Specifications for real systems do not exist as one-shot artifacts: the user's intent emerges as they discover edge cases, rewrite drafts, and react to failing tests. We present an iterative pipeline that takes this …
- View project: AgentSpecGap
AgentSpecGap
solo-team
This prototype extracts rules from system prompts, tool descriptions, and runtime config. Rules are classified into one of interface validation, authorization check, workflow ordering validation, runtime validation, …
- View project: SpecGap Arena
SpecGap Arena
Obligation Cartographers
SpecGap Arena is a benchmark and framework that exposes how incomplete specifications let plausible but incorrect code pass public tests. It synthesizes missing semantic obligations (security boundaries, invariants, …