# Hexvoyant alpha: five tasks and feedback

This is an unfilled template, not a record of completed testing. Download or
copy it locally. Nothing is submitted automatically, and no analytics are
collected. Use only the repository-owned demo fixture for this first session.

You can stop at any point. Setup failure, confusing wording, and deciding not
to continue are useful feedback; you are testing the product, not yourself.

## Before you start

Get the reviewed source folder from the maintainer, follow the website's
first-session build commands, and open the fixture in the native desktop.
Source builds require macOS, the repository-selected Rust toolchain, Xcode
Command Line Tools, and Python 3. Record setup time separately from task time.

Try the tasks below without a walkthrough first. If you use a hint or ask for
help, record it; do not count that task as unaided. Do not spend more than
20 minutes on the task session unless you want to. There is no speed target.

## Tasks

1. Identify the fixture's format and architecture. Find its SHA-256.
2. Find `HEXVOYANT_BENIGN_DEMO_NO_NETWORK` and inspect bytes at its location.
3. Locate `main` (a leading underscore is fine), inspect its instructions,
   and find a conditional path in its control-flow view.
4. Save a note and bookmark at a chosen address. Close/reopen the saved project
   and confirm the note is still there. Keep the original binary and the
   companion report artifact; the desktop verifies the source hash on reopen.
5. Export an analysis report to a new Markdown file. Identify one limitation or
   coverage statement. Explain why a missing finding does not prove safety.

## Your session

- Tester alias (optional; no real name needed):
- Date:
- Source commit (`git rev-parse --short HEAD`) or maintainer's source snapshot ID:
- macOS version and Apple Silicon / Intel (no serial number):
- Prior binary-analysis experience: none / learning / regular use
- UI size selected: 100% / 110% / 125%
- Setup: completed / completed with help / blocked / stopped
- Setup time (rough estimate is fine):
- Setup difficulty or error (remove personal paths/tokens):

| Task | Outcome: unaided / with hint / failed / skipped | Approx. time | Where I got stuck; hints used |
| --- | --- | --- | --- |
| 1. Identity | | | |
| 2. String → bytes | | | |
| 3. Function → flow | | | |
| 4. Note → save → reopen | | | |
| 5. Export → interpret | | | |

- What did you expect the website to do before you started?
- What, if anything, was useful in the desktop?
- What was the single most annoying interaction?
- Any clipped text, inaccessible scrolling, keyboard problem, crash, or hang?
- Were you able to distinguish VA from file offset, and unknown from absent?
- Would you choose this for another task? Why or why not?
- What task would that be? “None” is a useful answer.
- What would you use instead, if anything?
- Optional later follow-up: did you actually return for a separate task? What
  was it, and did Hexvoyant help? Leave blank until that happens.

## Share safely

Send the redacted sheet to the person who invited you through your existing
agreed contact channel. There is no configured public feedback inbox yet.
Sharing is optional; ask before recording a session or publishing a quote.

Do not attach private/proprietary binaries, full analysis/project reports,
unredacted logs, usernames, local paths, credentials, or unrelated screenshots.
Use a small owned-source reproduction for ordinary bugs. For suspected security
issues, ask the maintainer for a private reporting channel; do not post exploit
details in a public issue. No need to disable Gatekeeper, SIP, or other security
controls for this source-build test.
