What problem does it solve?
Security researchers, bug bounty hunters, and red teamers often track vulnerabilities, exploit gadgets, and security-relevant discoveries in ad-hoc notes or disconnected tools, making it hard to maintain a consistent, searchable record of findings tied to their assessment work. This Skill integrates with jxscout to provide a structured, centralized way to document and manage all security discoveries.
Core Features & Use Cases
- Structured Finding Creation: Log confirmed vulnerabilities, useful exploit gadgets, security misconfigurations, and sensitive data exposures with custom severity levels, descriptive categories, and structured metadata.
- Finding Management: List, filter, and paginate existing findings by severity or kind, and retrieve full details of specific findings for review or reporting.
- Use Case: A bug bounty hunter discovers a stored XSS vulnerability on a user profile endpoint, uses the Skill to create a high-severity finding with a detailed description, deduplication key, and metadata linking to captured HTTP evidence, then later filters all critical and high findings to prioritize their report submissions.
Quick Start
Use the jxscout-findings skill to create a high-severity finding for a stored XSS vulnerability on the /api/user-profile endpoint with a description of the impact and relevant metadata linking to captured request evidence.