```yaml record_type: cyber-evidence engagement_scope_ref: synthetic-exercise/scope-001 skill_version: cyber-evidence (version not supplied) source: synthetic-exercise-runner observed_at: "2026-09-22T00:00:00Z" # assumed timestamp observer: exercise-operator-01 method: redacted HTTP validation; tool output was not independently corroborated observation: > A synthetic request appeared to reach a test endpoint without the expected authorization control. Credentials, tokens, payloads, and persona...
Pro scans all 13 files and shows the line behind each finding
Scanned 9/24/2026
npx -y skills add HoangNguyen0403/agent-skills-standard --skill cyber-evidence --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Cyber Evidence?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-cyber-evidence-d516bb94)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
```yaml
record_type: cyber-evidence
engagement_scope_ref: synthetic-exercise/scope-001
skill_version: cyber-evidence (version not supplied)
source: synthetic-exercise-runner
observed_at: "2026-09-22T00:00:00Z" # assumed timestamp
observer: exercise-operator-01
method: redacted HTTP validation; tool output was not independently corroborated
observation: >
A synthetic request appeared to reach a test endpoint without the expected
authorization control. Credentials, tokens, payloads, and personal data were
excluded from this record.
finding_status: suspected
evidence_refs:
- "synthetic://exercise-001/observation-004"
- "sha256:redacted-evidence-digest"
limitations:
- Synthetic data only; production impact and exploitability are unknown.
- No runtime authorization telemetry or server-side audit logs were available.
- The observation is scanner/tool-derived and lacks independent corroboration.
- Hashes and timestamps support provenance but do not prove trusted origin or efficacy.
- Raw evidence is retained separately from this sanitized record and contains no credentials or real secrets.
ground_truth:
ref: "synthetic://exercise-001/ground-truth-004"
custody: independent-exercise-controller
comparison: pending independent adjudicator review
accountable_owner: application-security-owner
promotion_requirement: >
An independent reviewer must corroborate the observation; the operator who
recorded it cannot approve their own result.
canonical_artifact_action: >
No existing workflow chain owns artifacts/security-review.md; update it only
if this record is later attached to such a chain.
authorization_ref: null
framework_mapping_ref: null
next_steps:
- Obtain sanitized server-side logs or a reproducible synthetic test.
- Have an independent adjudicator compare the observation with ground truth.
- Preserve the suspected status until corroboration or falsification.
```
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!