Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Reporting Triage Validation

ASecurity

Validate a finding BEFORE you write it up — kill false positives, confirm real impact, check scope, and deduplicate. Load after a candidate bug and before reporting-bug-bounty-writeup or reporting-pentest-report. Signals: "I think I found", "is this reportable", a scanner hit, a reflected value, a 500 error, an open redirect, a CORS wildcard, "should I submit this".

20 stars
0 votes
0 copies
0 views
Added 9/22/2026
ai-agentsgo

Works with

cli

Security Analysis

A100/100

Scanned 9/22/2026

$npx -y skills add NoorQureshi/SploitAgent --skill reporting-triage-validation --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Reporting Triage Validation?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Reporting Triage Validation
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-reporting-triage-validation/badge)](https://www.skillsdirectory.com/skills/noorqureshi-reporting-triage-validation)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: reporting-triage-validation
description: >
  Validate a finding BEFORE you write it up — kill false positives, confirm real impact,
  check scope, and deduplicate. Load after a candidate bug and before reporting-bug-bounty-writeup
  or reporting-pentest-report. Signals: "I think I found", "is this reportable", a scanner hit,
  a reflected value, a 500 error, an open redirect, a CORS wildcard, "should I submit this".
domain: reporting
type: methodology
stability: learning
modes: [bugbounty, pentest]
severity: info
schema_version: 1
---

# Triage & validation — earn the right to report

## When it applies
You have a *candidate* finding and you are about to spend an hour writing it up. Run this gate
first. It applies double on bug bounty (an invalid/duplicate report costs your signal and the
triager's time) and still matters on a pentest (a false positive in the report costs your
credibility with the client).

## Why it works
Most "findings" die on one of a few predictable questions. Asking them up front — cheaply, in
order — kills the weak ones before they cost report-writing time, and forces the survivors to
carry the evidence a triager actually needs. The rule is simple: **one failed gate = stop.**

## Method — four gates, in order

**Gate 0 — Is it real and in scope?**
1. Reproduce it as a raw HTTP request (or exact steps) from a clean session — not from your
   proxy's replay of a stateful flow. If you can't write the request that proves it, it isn't a
   finding yet.
2. Confirm the vulnerable asset is in `scope.txt` and the vuln class is one the program accepts
   (re-read the policy). Staging, third-party, and internal-only hosts are out.

**Gate 1 — Is there real impact?**
Name what the attacker *walks away with*. "Technically possible" is not impact. Common kills:
- **XSS** with no session/action proof — show cookie theft, an action as the victim, or a
  sensitive-context payload; a reflected `alert(1)` on a JSON endpoint that sets
  `Content-Type: application/json` usually doesn't execute.
- **SSRF** that only resolves DNS — get an HTTP response body or reach an internal service
  (`web-ssrf`, `web-ssrf-gopher-redis-rce`), or it's a blind curiosity.
- **IDOR** on *your own* data, or cross-account with identical data — prove access to *another*
  tenant's object (`web-idor`).
- **CORS** wildcard without `Allow-Credentials` and a credentialed, sensitive response — no
  exfil path, no bug.
- **Open redirect / self-XSS / missing headers / version banners** — N/A alone; only count when
  chained (open redirect → OAuth token theft, `web-oauth`; version → a *working* CVE PoC).

**Gate 2 — Is it a duplicate or known behavior?**
Search the program's disclosed reports, your own past submissions, the changelog, and the web
for the same class on the same asset. Confirm it isn't documented intended behavior. Bump the
version and retest if a fix may have landed since you found it.

**Gate 3 — Is the evidence report-grade?**
- Copy-pasteable reproduction (numbered steps or a single request), no manual proxy state.
- A severity you can defend: build the CVSS 3.1 vector and sanity-check the score against the
  impact you actually proved (e.g. cross-tenant read ≈ 6.5; unauthenticated auth bypass ≈ 9.8).
- Redacted proof only — the minimum data that proves it, never hoarded real PII.

## Gotchas
- **Chains need every link proven.** "Open redirect + hypothetical token leak" is one proven bug
  and one guess = still N/A. Prove the leak or don't claim the chain.
- **Two or more preconditions that must all hold** (victim must be admin *and* click a link
  *and* be on an old client) usually means low/again-N/A — say so honestly.
- **Scanner output is a lead, not a finding.** Every automated hit re-enters at Gate 0.
- Don't let sunk cost carry a dead finding forward — a fast N/A you never submit beats a slow one
  the triager closes.

## Verify success
Every gate passes and you can state, in one sentence, the concrete impact and who is affected —
then hand off to `reporting-bug-bounty-writeup` or `reporting-pentest-report`.

## References
CVSS 3.1 specification; program policy and disclosed reports; HackerOne/Bugcrowd triage guidance.

Attribution

NoorQureshiNoorQureshi
View sourceSee grades on GitHubMore from NoorQureshi →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →