Counter-Analysis

Guides structured validation of vulnerability findings through critical disproof and deduplication.

39|4|Updated May 6, 2026
One-click install
npx skills add https://github.com/pruiz/CodeCome --skill counter-analysis
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Counter-Analysis
Source: https://github.com/pruiz/CodeCome/tree/main/.opencode/skills/counter-analysis
Command: npx skills add https://github.com/pruiz/CodeCome --skill counter-analysis

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps security analysts systematically disprove or validate vulnerability findings to improve accuracy and reduce false positives.

Core Features & Use Cases

  • Evaluate findings critically to determine their plausibility and relevance.
  • Guide counter-analysis workflows by providing structured review questions and documentation templates.
  • Use case: During a vulnerability audit, the analyst reviews a suspect finding and uses this skill to systematically validate or reject the claim, streamlining the triage process.

Quick Start

Provide the details of the finding under review and let the AI assist in evaluating its validity step-by-step.

Frequently Asked Questions about Counter-Analysis

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I reduce false positives in vulnerability assessments during code review?

To reduce false positives in vulnerability assessments, critically evaluate findings by applying structured counter-analysis workflows that guide you through disproof, deduplication, and clarification steps to validate or reject claims efficiently.

What is counter-analysis in penetration testing and when should I use it?

Counter-analysis in penetration testing is a skeptical evaluation process used to systematically disprove or validate suspect security findings. Use it during vulnerability audits to streamline triage and ensure documentation standards are met.

How do I deduplicate and clarify security findings from a vulnerability audit?

Deduplicate and clarify security findings by applying a structured review mindset that evaluates plausibility and relevance. This counter-analysis process systematically disproves invalid claims and streamlines the triage of vulnerability assessments.

What are the limitations of using automated counter-analysis for security validation?

Limitations of counter-analysis include its reliance on the analyst's adherence to a skeptical review mindset. The process facilitates structured disproof and validation but cannot replace the comprehensive decision-making required in complex penetration testing workflows.