bughunters-microsoft
Microsoft bug bounty — MSRC program, PPE environment attack surface (*.microsoft-ppe.com), MSAL.js token extraction, Swagger/OpenAPI exposure, unauthenticated AI agent endpoints, identity injection (roles/claims), Azure App Service hostname disclosure, source maps with Azure AD clientIds, telemetry ARIA API keys in traffic, React Fiber environment switching. Real findings from storedeveloper.microsoft-ppe.com (Nova) and api.offerscopilot.microsoft-ppe.com. Spanish triggers — "microsoft bug bounty", "microsoft vrp", "msrc", "microsoft ppe", "microsoft-ppe.com", "msal token", "azure ad clientid", "offers copilot microsoft", "nova microsoft store", "microsoft store developer", "swagger microsoft ppe", "azure app service hostname", "microsoft ai agent unauth".
Ecosystem Scores - What Happened to it
PROTOCOL WARRANT
This score reflects origin + ecosystem signals. It is not a code audit.
Agent Lineage Map
Spatial graph · creator origin → derivative agents
