triage-validation
Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit checklist.
Install / Use
npx skills add elementalsouls/Claude-BugHunter --skill triage-validationInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Content & MediaSupported Platforms
Tags
Our assessment of triage-validation
triage-validation scores 96/100 on our quality scale, 51st of 735 Content & Media skills we index (top 7%).
Its SKILL.md is 22 KB long, well organised into 37 sections with 9 code examples: a thorough specification that gives an agent plenty to work with.
With 4,669 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 2 days ago, so triage-validation is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
triage-validation compared with similar skills
All 4 of these similar skills score higher than triage-validation; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| triage-validation (this skill)by elementalsouls | 96 | 4.7k | 2d ago | SKILL.md |
| siyuanby siyuan-note | 100 | 46.5k | today | MCP Server |
| algorithmic-artby anthropics | 100 | 177.9k | 5d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 5d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 7d ago | SKILL.md |
Frequently asked questions
- How do I install triage-validation?
- Run
npx skills add elementalsouls/Claude-BugHunter --skill triage-validation. The install tabs above show the steps for each supported agent. - Which AI agents does triage-validation work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is triage-validation safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is triage-validation still maintained?
- The repository was last updated 2 days ago, so triage-validation is actively maintained.
Skill content
View source on GitHubname: triage-validation description: Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit checklist. Use BEFORE writing any report. One wrong answer = kill the finding and move on. Saves N/A ratio. sources: community, operator_experience
TRIAGE & VALIDATION
One wrong answer = STOP this finding. Kill the finding. Move on to the next test class.
Scope of "STOP" in this skill: This skill's gates kill INDIVIDUAL FINDINGS that fail validation. They do NOT authorize stopping the engagement. Killing a finding via the 7-Question Gate just means that finding doesn't get submitted — every other test class in the engagement is still pending. See
redteam-mindset"DO NOT STOP primary directive" for the coverage-axis rule.
"N/A hurts your validity ratio. Informative is neutral. Only submit what passes all 7 questions."
THE 7-QUESTION GATE
Ask IN ORDER. One wrong answer = STOP immediately.
Q1: Can an attacker use this RIGHT NOW, step by step?
Complete this template:
1. Setup: I need [own account / another user's ID / no account]
2. Request: [exact HTTP method, URL, headers, body — copy-paste ready]
3. Result: I can [read / modify / delete] [exact data shown in response]
4. Impact: The real-world consequence is [account takeover / PII read / money stolen]
5. Cost: Time: [X minutes], Capital: [$0 / $X subscription required]
If you CANNOT write step 2 as a real HTTP request → KILL IT.
Q2: Is the impact on the program's accepted impact list?
Go to the program page. Find "Vulnerability Types" or "Out of Scope."
Common tiers:
- Critical: Any-user ATO without interaction, RCE, SQLi with data exfil, admin auth bypass
- High: Mass PII exfil, privilege escalation, internal SSRF with data, stored XSS all users
- Medium: IDOR on specific user non-critical data, XSS on sensitive page requiring click
- Low: Non-sensitive info disclosure, clickjacking with PoC
If your bug maps to a listed exclusion → KILL IT.
Q3: Is the root cause in an in-scope asset?
Confirm:
- Vulnerable domain is on the in-scope list (not
*.internal.target.com) - It's a production asset (not staging/dev unless explicitly in scope)
- It's not a third-party service the company just uses (not Stripe, Salesforce, Google Auth)
If out-of-scope → KILL IT.
Q4: Does it require privileged access that an attacker can't realistically get?
- "Admin can do X" = centralization risk = KILL IT (on 99% of programs)
- "Non-admin can do X that only admin should do" = valid
- "Requires physical access / MFA device" = usually invalid
- "Requires compromised victim account to work" = questionable, low severity at best
Q5: Is this already known or accepted behavior?
Search:
- Program's HackerOne/Bugcrowd disclosed reports: Ctrl+F endpoint name + bug class
- GitHub issues on target repo:
is:issue label:security ENDPOINT_NAME - Changelog/CHANGELOG.md — does it mention this behavior?
- API docs / design docs — is it documented as intended?
If acknowledged/design decision → KILL IT.
Q6: Can you prove impact beyond "technically possible"?
- XSS → show actual cookie theft or session hijack, not just
alert(1)oralert(document.domain) - SSRF → hit an internal endpoint that returns data, not just DNS ping
- SQLi → show actual data exfil from a real table, not just error message
- IDOR → show actual other-user's data in response, not just a 200 status code
If you can only show "technically possible" → DOWNGRADE severity, not kill.
Q7: Is this a known-invalid bug class?
Check the NEVER SUBMIT list below. If it's on this list without a chain → KILL IT.
THE LAYER-ORDERING TRAP — read before claiming any auth bypass
A validation error does NOT prove you passed authentication.
This is the highest-confidence false positive in the auth-bypass class, because the evidence looks concrete. The reasoning that fails:
"I sent an unauthenticated request and got back
400 — field X is required. A validation error means the request cleared auth and reached business logic. Therefore auth is missing."
That inference is only valid if auth runs before input handling. Many stacks put a global input sanitiser, body parser, or schema filter in front of the auth middleware. A malformed body is then rejected before auth is ever consulted, and the response is indistinguishable from "auth passed, validation failed."
The test: re-send with a minimal WELL-FORMED body.
# malformed body — trips the sanitiser, which runs FIRST
curl -s -X POST https://target/api/v1/resource -d '{'
# 400 {"code":"ERR-INPUT-0001","message":"Invalid text. Only permitted
# characters are allowed"} <- looks like auth bypass
# same endpoint, well-formed empty object — now auth is reached
curl -s -X POST https://target/api/v1/resource -H 'Content-Type: application/json' -d '{}'
# 401 {"code":"ERR-AUTH-0001","message":"Not authenticated. Please log in."}
Only the second response tells you where the auth layer sits.
Lesson from an authorized engagement. On a production API, a malformed body
returned a validation-shaped 400 on the large majority of endpoints tested. Read
as an auth bypass, that is a Critical filed against production infrastructure
covering financial and administrative operations. It was a sanitiser reacting to
the { character before auth ran — every one of those endpoints returned 401 to
a well-formed {}. The false Critical was avoided only because someone re-tested.
Rules:
- Layer ordering is not observable from a single response. Never infer it.
- Probe auth with the simplest valid body the parser will accept, not a malformed one.
- If the error text is about input shape or character class, you are talking to a parser or sanitiser, not to business logic.
- If the error text names a domain field (
accountId is required) AND a well-formed body still returns it, that is a real signal — proceed to Q6. - Applies equally to WAF and CDN layers: an edge block is not an origin response.
4 PRE-SUBMISSION GATES
Run in sequence. ALL 4 must PASS.
Gate 0: Reality Check (30 seconds)
[ ] Bug is REAL — confirmed with actual HTTP requests, not code reading alone
[ ] Bug is IN SCOPE — checked program scope page explicitly
[ ] Reproducible from scratch — can reproduce starting from fresh session
[ ] Evidence ready — screenshot, response body, or video
Gate 1: Impact Validation (2 minutes)
[ ] Can answer: "What can attacker DO that they couldn't before?"
[ ] Answer is more than "see non-sensitive data" (unless program pays for info disclosure)
[ ] Real victim: another user's data, company's data, financial loss
[ ] Not relying on victim doing something unlikely
Gate 2: Deduplication Check (5 minutes)
[ ] Searched HackerOne Hacktivity for this program + similar bug title/endpoint
[ ] Searched GitHub issues for target repo
[ ] Read most recent 5 disclosed reports for this program
[ ] Not a "known issue" in their changelog or public docs
[ ] Google: "TARGET_NAME ENDPOINT_NAME bug bounty"
Gate 3: Report Quality (10 minutes)
[ ] Title: [Bug Class] in [Endpoint] allows [actor] to [impact]
[ ] Steps to Reproduce: copy-pasteable HTTP request
[ ] Evidence: screenshot/video of actual impact (not just 200 status)
[ ] Severity: matches CVSS 3.1 score AND program's severity definitions
[ ] Remediation: 1-2 sentences of concrete fix
[ ] NEVER used "could potentially" or "may allow"
NEVER SUBMIT LIST
Submitting these destroys your validity ratio.
Missing CSP / HSTS / security headers
Missing SPF / DKIM / DMARC
GraphQL introspection alone (no auth bypass, no IDOR demonstrated)
Banner / version disclosure without working CVE exploit
Clickjacking on non-sensitive pages (no sensitive action PoC)
Tabnabbing
CSV injection (no actual code execution shown)
CORS wildcard (*) without credential exfil proof of concept
Logout CSRF
Self-XSS (only exploits own account)
Open redirect alone (no ATO or OAuth theft chain)
OAuth client_secret in mobile app (known, expected)
SSRF DNS callback only (no internal service access or data)
Host header injection alone (no password reset poisoning PoC)
Rate limit on non-critical forms (search, contact, login with Cloudflare)
Session not invalidated on logout
Concurrent sessions
Internal IP in error message
Mixed content
SSL weak ciphers
Missing HttpOnly / Secure cookie flags alone
Broken external links
Autocomplete on password fields
Pre-account takeover (usually — very specific conditions required)
CONDITIONALLY VALID — CHAIN REQUIRED
Build the chain first, prove it works end to end, THEN report.
| Standalone Finding | Chain Required | Valid Result | |---|---|---| | Open redirect | + OAuth redirect_uri → auth code theft | ATO (Critical) | | Clickjacking | + sensitive action + working PoC | Medium | | CORS wildcard | + credentialed request exfils user PII | High | | CSRF | + sensitive action (transfer funds, change email, delete account) | High | | Rate limit bypass | + OTP/reset token brute force succeeds | Medium/High | | SSRF DNS-only | + internal service access + data returned | Medium | | Host header injection | + password reset email uses injected host | High | | Prompt injection | + reads other user's data (IDOR) | High | | S3 bucket listing | + JS bundles contain API keys or OAuth secrets | Medium/High | | Self-XSS | + CSRF to trigger it on victim without their knowledge | Medium | | Subdomain takeover | + OAuth redirect_uri registered at that subdomain | Critical | | GraphQL introspection | + auth bypass mutation or IDOR on node() | High |
CVSS 3.1 QUICK REFERENCE
Common Score Examples
| Finding | Score | Severity | Vector | |---|---|---|---| | IDOR read PII, any user, auth required | 6.5 | Medium | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N | | IDOR write/delete, any user | 7.5 | High | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N | | Auth bypass → admin panel | 9.8 | Critical | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | | Stored XSS → cookie theft, stored | 8.5 | High | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N | | SQLi → full DB dump | 9.1 | Critical | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N | | SSRF → cloud metadata | 9.1 | Critical | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N | | Race → double spend | 7.5 | High | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N | | GraphQL auth bypass | 8.1 | High | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N | | JWT none algorithm | 9.1 | Critical | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
UI for stored XSS is a judgment call. Stored XSS that fires on page view is a long-standing CVSS gray area — NVD/FIRST frequently score it UI:R (which drops the stored-XSS row above to ~7.6). The UI:N above models "no extra action beyond normal page use"; if your triager expects UI:R, defend the choice or re-score before copying the number into a report.
Metric Quick Guide
| What you have | Metric | Value | |---|---|---| | Exploitable over internet | AV | Network (N) | | No special timing or race | AC | Low (L) | | Free account needed | PR | Low (L) | | No login needed | PR | None (N) | | Admin needed | PR | High (H) | | No victim action | UI | None (N) | | Victim must click | UI | Required (R) | | Reads all data | C | High (H) | | Reads some data | C | Low (L) | | Modifies all data | I | High (H) | | Crashes service | A | High (H) | | Affects only app | S | Unchanged (U) | | Affects browser/OS/cloud | S | Changed (C) |
KILL FAST RULES
The goal is to QUICKLY disqualify bad leads so you hunt real bugs:
- 5-minute rule: If you can't fill in Q1's template in 5 minutes → move on
- **Precondition cou
Truncated for display — read the full file on GitHub.
Related Skills
siyuan
46.5kAn open-source, privacy-first, self-hosted knowledge workspace where humans and AI agents work together 开源、隐私优先、自托管的知识工作空间,让人与智能体在此协作
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
