security-review-feedback

Verify security review findings and assign verdicts based on reachability and exploitability.

2|Updated Jan 7, 2026
One-click install
npx skills add https://github.com/Integralist/agent-skills --skill security-review-feedback
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review-feedback
Source: https://github.com/Integralist/agent-skills/tree/main/.agents/skills/security-review-feedback
Command: npx skills add https://github.com/Integralist/agent-skills --skill security-review-feedback

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps in evaluating security review findings to determine their validity and impact, reducing false positives and severity inflation.

Core Features & Use Cases

  • Evidence-Based Verification: Provides a structured process to verify the reachability, attacker control, and exploitability of security findings.
  • Verdict Workflow: Offers a step-by-step workflow to assign a verdict to each finding, ensuring thorough analysis before implementing any fix.
  • False Positive Detection: Assists in identifying false positives and severity inflation, promoting evidence-based decision-making.

Quick Start

Apply the security-review-feedback skill to the latest security review report to verify and assign verdicts to each finding.

Frequently Asked Questions about security-review-feedback

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I verify security review findings to reduce false positives?

Verify security review findings by evaluating reachability, attacker control, and exploitability to reduce false positives. This evidence-based approach requires analyzing code and system configurations to ensure accurate verdicts before implementing any fixes.

What is evidence-based analysis for vulnerability assessments?

Evidence-based analysis for vulnerability assessments is a structured process to validate the impact of security findings. It applies a step-by-step workflow to evaluate exploitability and reachability, ensuring thorough analysis and reducing severity inflation.

How do I assign a verdict to security audit findings?

Assign a verdict to security audit findings by applying a structured workflow that focuses on reachability and attacker control. This process evaluates code and system configurations to confirm exploitability and promotes evidence-based decision-making.

Does security verification work with existing code and system configurations?

Security verification works directly with existing code and system configurations to evaluate finding validity. It requires analyzing these elements to determine exploitability and identify false positives without needing external dependencies.

What is the best way to detect false positives in a vulnerability assessment?

The best way to detect false positives in a vulnerability assessment is to verify the reachability and attacker control of each finding. This evidence-based verification checks actual exploitability rather than relying on initial scan reports.