finding-review

Triage cybersecurity findings for validity, exploitability, impact, and evidence quality.

16|2|Updated May 26, 2026
One-click install
npx skills add https://github.com/mindfortai/security-skills --skill finding-review-mindfortai
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: finding-review
Source: https://github.com/mindfortai/security-skills/tree/main/skills/finding-review
Command: npx skills add https://github.com/mindfortai/security-skills --skill finding-review-mindfortai

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This Skill simplifies the triage of cybersecurity findings, ensuring that only valid and impactful vulnerabilities are reported.

Core Features & Use Cases

  • Finding Triage: Evaluate the validity, exploitability, and impact of cybersecurity findings.
  • Evidence Quality: Focus on evidence quality and reproducibility over generic severity labels.
  • Use Case: Use this Skill to review vulnerability reports, scanner output, pentest findings, or bug bounty submissions, prioritizing findings based on evidence and impact.

Quick Start

Run the 'finding-review' skill on your findings to get a detailed triage report.

Frequently Asked Questions about finding-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage cybersecurity findings from vulnerability scanners?

Triage cybersecurity findings by evaluating validity, exploitability, impact, and evidence quality to prioritize vulnerabilities. This skill analyzes scanner output, pentest findings, and bug bounty submissions to focus on reproducible evidence over generic severity labels.

What is the best way to review bug bounty submissions for valid vulnerabilities?

Review bug bounty submissions by analyzing evidence quality and impact to ensure only valid vulnerabilities are reported. This triage process assesses exploitability and reproducibility, prioritizing findings based on concrete evidence rather than standard severity scores.

Can I use this to prioritize pentest findings based on exploitability?

Yes, you can prioritize pentest findings by running this triage to evaluate exploitability and impact. It assesses the evidence provided in pentest reports to determine which vulnerabilities are valid and require immediate attention.

Does evidence quality matter more than severity labels when triaging security vulnerabilities?

Evidence quality matters significantly because generic severity labels often lack context for true risk. Triage vulnerabilities by focusing on the reproducibility and quality of the evidence to accurately prioritize valid and impactful security findings.

How do I validate vulnerability reports before reporting them?

Validate vulnerability reports by running a triage process that checks for exploitability and impact. This skill analyzes the provided evidence to determine if the cybersecurity finding is valid and reproducible before it gets reported.