MONK BUG BOUNTY · 17 JULY – 10 AUGUST 2026

    Coding with an agent? Make Monk sweat and bank cash.

    Monk is the only AI DevOps engineer your coding agent needs 🐬 - and the new plugin just dropped. Stress-test it, report bugs, win prizes up to $500 - cash + months of Monk free.

    Bug bounty ends in
    --d
    --h
    --m
    --s
    Signing up starts your free 5-day Monk Pro trial. Submissions close 10 August, 12:00 UTC.
    Monk dolphin under stress, sweating
    Works with your favorite coding agent
    Claude CodeClaude CodeCursorCursorCodexCodexAntigravityAntigravity
    Hunt starts
    17 July 2026
    Monk Pro trial
    5 days
    Free - starts when you sign up
    Hunt ends
    10 August 2026
    Submissions close 12:00 UTC
    01 /The pot

    Find bugs. Win cash + Monk Pro Subscription.

    Every confirmed finding earns points - the three highest totals take the pot. Bring friends and we will unlock a 4th prize + a wildcard draw.

    1st
    First place
    $500
    ($350 in cash + 3 months Monk Pro subscription)
    2nd
    Second place
    $200
    ($100 in cash + 2 months Monk Pro subscription)
    3rd
    Third place
    $100
    ($50 in cash + 1 month Monk Pro subscription)
    5 / 150 hunters

    Bring your friends. At 150 hunters, we unlock a 4th prize + a wildcard draw - every valid bug is one entry. What's in them stays secret until we unlock them.

    02 /A new category

    The autonomous DevOps agent - now a plugin for your coding agent.

    Monk works with any coding agent - your agent writes the code, and Monk deploys and runs it in production, autonomously, across your own cloud. The plugin just dropped, and we want you to battle-test it.

    What is Monk? Learn more →
    03 /How it works

    You prompt. Agents work. You approve.

    Connect your coding agent and Monk, then let them work. Your job is the easy part.

    01
    You prompt
    Describe what you want in your coding agent - like always.
    02
    Agents work
    Your agent writes the code; Monk deploys and runs it across your own cloud.
    03
    You approve
    Review, approve, and let Monk keep it running - CI/CD, watchers, ongoing ops.
    Person relaxing on a beach while the work gets done
    Your role, basically.

    The agents sweat the deploys, ops, and watchers - you just prompt and approve.

    Watch Monk run the lifecycle
    04 /The hunt

    Take Monk through the full lifecycle - end to end.

    Run the gauntlet
    1. 1Install the Monk plugin (instructions in your dashboard after sign-up)
    2. 2Connect your coding agent
    3. 3Build or bring a full-stack app
    4. 4Deploy your app with Monk
    5. 5Let Monk operate your app (ops, CI, add the watcher)
    6. 6Push a change - watch Monk handle the diff
    Then report
    Bugs at every stage
    Blockers, performance, rough user experience.
    Feature requests & missing integrations
    Tell us what you reached for and couldn't find.
    Pull requests
    Fix it yourself? Even better. A merged PR adds 3 pts on top of the issue.
    Create content about your run
    Blog it, stream it, tweet it - file an issue with the link so it scores.
    05 /How to submit

    Report it on GitHub.

    Sign up for Monk with the same GitHub account you'll report from - that's what makes your findings score. Then file each bug as an issue on the plugin repo. One exception: security and data-loss findings go to security@monk.io, not the public tracker.

    Every issue is public. The community can see, reproduce, and upvote. The Monk team triages, scores, and posts scoring notes back on the issue - full transparency.

    We've got an issue template ready - it walks you through everything you need.

    While you're there, a star on the repo is appreciated - it helps us gauge interest. Not required, and it doesn't affect scoring.

    Open an issue on GitHub →
    Include in every issue
    ·Stage install, connect, build, deploy, or operate
    ·Coding agent Claude Code, Cursor, Codex, or Antigravity
    ·Repro steps what you did, what you expected, what happened
    ·Setup OS, versions, target cloud, integration
    ·Severity (your guess) crash, blocker, major, minor
    ·One bug per issue duplicates merge to the first reporter

    Security and data-loss findings: email security@monk.io - do not open a public issue. They count toward the bounty like any other bug, and severe vulnerabilities score double points. We'll confirm receipt within 24h.

    What we're looking for

    Each confirmed finding earns points toward your total - go deep rather than spam the easy stuff. The Monk team makes the final call on scoring.

    Best findings - 3pts
    • ·Security & data-loss bugs (report privately to security@monk.io) - severe vulnerabilities score double
    • ·Broken full-lifecycle runs (build → deploy → operate)
    • ·Merged PRs that fix a real issue - 3 pts on top of the linked issue
    Great findings - 2pts
    • ·Performance regressions & flaky behavior
    • ·Missing integrations you reached for
    • ·Confusing or rough UX at any stage
    • ·Content about your run (blog, stream, tweet) - file an issue with the link
    Good findings - 1pt
    • ·Cosmetic / copy nits
    • ·One-off install hiccups with an easy workaround
    06 /The fine print

    The rules & fine print

    ·In scope: the Monk plugin (skills + MCP) from github.com/monk-io/monk-plugin.
    ·One GitHub account per hunter; no alts.
    ·To be scored, sign in at monk.io with the same GitHub account you file issues and PRs from. Submissions from accounts without a linked Monk account are welcome but won't be scored.
    ·Findings should come from using the product - install the plugin and run it against a real app. Pure code-reading findings (no run) are welcome but won't be scored.
    ·Bugs must be reproducible.
    ·The Monk team has final say on scoring.
    ·Ties break by higher-value findings first, then earliest submission.
    ·Winners announced within 48h of close.
    ·You deploy to your own cloud and cover those costs - quick test runs cost single-digit dollars.
    ·Security bugs reported publicly instead of via security@monk.io may be disqualified.
    ·Questions? Open an issue on the plugin repo.

    Full eligibility and prize terms: Bug Bounty Terms.

    Join the hunt. Make Monk sweat.

    Connect the plugin to your coding agent, run the full lifecycle, and file what breaks. 17 July – 10 August.

    Install the plugin for
    Claude CodeCursorCodexAntigravity
    Report bugs on GitHub →