How tots works
A CVE is a statement, not a verdict. Scanners repeat it, maintainers argue with it, and the version range drifts between databases. Given one CVE and one package version, tots asks the two questions a security engineer would: does the code actually do this? and what do the people who own it say?
New to security, or want the background? See how a CVE goes from discovery to disclosure, dispute, and patch, plus a glossary of every acronym on this page.Anatomy of a CVE →The pipeline
One durable eve workflow runs every assessment. Each box is a step that survives restarts: if a model call fails halfway, the run resumes where it stopped instead of starting over.
in parallel · neither sees the other's work
The labels
- INSUFFICIENT EVIDENCEChecked first: not enough concrete evidence to decide.
- DISPUTEDA credible dispute that the PoC doesn't settle either way.
- LIKELY INVALIDThe target looks unaffected: the PoC works on a vulnerable version but not the target, or maintainers dispute it.
- LIKELY OVERSTATEDThe bug is real on the target, but the claimed impact isn't what the evidence shows.
- SUPPORTEDReproduced on the target version, and no claim is credibly disputed.
- LIKELY SUPPORTEDProbably affected, but not reproduced, with no strong dispute.
The official CVE status is always shown next to the label. The CVE Program has the final word; tots says how well the public evidence supports the claim for this version.
A real one
→ DISPUTED: credible_dispute_exists 0.95 ≥ 0.60 and no stronger rule applied
This is the case tots exists for. Scanners flag it, the maintainers say it doesn't apply, and the sandbox shows the behaviour is still there. Neither side is simply right, and the report shows both.
Under the hood
Everything in tots is built on Vercel. The site, the agent, the durable workflow, the sandbox, every model call, the feature flag, and the database all live in one Vercel project. The Vercel services authenticate with the project's OIDC token, so there are no AI provider keys to manage.
- eveVercel's framework for durable agents: the workflow tool, both subagents, and their sandboxes
- Vercel WorkflowEach run is a durable workflow; a crash or redeploy resumes it mid-step
- Vercel SandboxIsolated microVMs for PoCs, egress limited to npm and GitHub
- Vercel AI GatewayOne endpoint for Claude, OpenAI, and Jev, billed and observed in one place
- Vercel FlagsLive runs are off by default; only a flag-checked server action can queue one
- Neon via Vercel MarketplacePostgres provisioned from the Vercel dashboard, env vars injected
- Next.js on VercelThis site, deployed alongside the agent with withEve
- Vercel OIDCShort-lived project tokens for the Gateway, Sandbox, and Flags; no provider API keys
Where this could go
GET api.tots.dev/CVE-2024-10491?purl=pkg:npm/express@5.2.1
{
"label": "DISPUTED",
"code": "reproduces on 5.2.1",
"maintainers": "dispute",
"report": "https://tots-security.vercel.app/CVE-2024-10491/express@5.2.1"
}