Cross-cutting methodology for the CVE-hunting pipeline (ported from find-cve-agent): when a bug is design-vs-real, false-positive avoidance, version checking before reporting, responsible disclosure norms, acceptance-rate expectations per vuln class, vulnerability chaining playbook, known false-positive patterns, maintainer-response patterns, secure-pattern reference (what NOT to flag), and a self-criticism checklist to run before claiming a finding. Use this alongside the cve-hunter/cve-expl...
Installs into .claude/skills of the current project.
Are you the author of Cve Hunting Methodology?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/ajtazer-cve-hunting-methodology)
---
name: cve-hunting-methodology
description: "Cross-cutting methodology for the CVE-hunting pipeline (ported from find-cve-agent): when a bug is design-vs-real, false-positive avoidance, version checking before reporting, responsible disclosure norms, acceptance-rate expectations per vuln class, vulnerability chaining playbook, known false-positive patterns, maintainer-response patterns, secure-pattern reference (what NOT to flag), and a self-criticism checklist to run before claiming a finding. Use this alongside the cve-hunter/cve-exploiter/cve-validator agents and the /cve-hunt pipeline — load it whenever judging if a finding is real, worth reporting, or already fixed."
---
# CVE Hunting Methodology
Reference material for judgment calls during the CVE-hunting pipeline (`/cve-recon` → `/cve-hunt` → cve-hunter → cve-exploiter → cve-validator → `/cve-registry`). This skill has no scripts to run — it's the accumulated judgment layer. Read the relevant reference file at the matching decision point:
## Rules (apply before calling anything a finding)
- `references/design-vs-bug.md` — is this actually a bug, or intended behavior/documented limitation?
- `references/false-positive-avoidance.md` — the checks to run before writing up a finding
- `references/version-checking.md` — confirm the vulnerable code path still exists in the current released version, not just in history
## Knowledge (context for prioritization and write-ups)
- `references/acceptance-rates.md` — which vuln classes actually get accepted/paid, to prioritize hunting effort
- `references/chaining-playbook.md` — how to escalate a low-impact finding into something that matters by chaining
- `references/false-positive-patterns.md` — catalog of common FP shapes per vuln class
- `references/rejection-taxonomy.md` — why maintainers/triagers reject reports, categorized
- `references/maintainer-responses.md` — patterns in how maintainers respond, and how to read them
- `references/secure-patterns.md` — code patterns that are ALREADY safe — don't flag these
- `references/self-criticism-checklist.md` — devil's-advocate pass to run on yourself before submitting a verdict
- `references/disclosure-channels.md` — picking HackerOne vs GHSA vs direct email vs full disclosure
- `references/responsible-disclosure.md` — timelines and etiquette for coordinated disclosure
## When to use this
- Before the cve-validator agent signs off on a finding → read `false-positive-avoidance.md` + `self-criticism-checklist.md`.
- Before picking a target category in `/cve-recon` → read `acceptance-rates.md`.
- After confirming one bug → read `chaining-playbook.md` before stopping.
- Before drafting a disclosure → read `disclosure-channels.md` + `responsible-disclosure.md`.