triage-validation

Validate security findings against program scope, impact, and authenticity criteria.

Updated Jul 1, 2026
One-click install
npx skills add https://github.com/bpnrockstar/UnifiedBugHunter --skill triage-validation-bpnrockstar
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: triage-validation
Source: https://github.com/bpnrockstar/UnifiedBugHunter/tree/main/skills/triage-validation
Command: npx skills add https://github.com/bpnrockstar/UnifiedBugHunter --skill triage-validation-bpnrockstar

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill ensures the accuracy and validity of security findings before reporting them, reducing false positives and improving the overall quality of submissions.

Core Features & Use Cases

  • 7-Question Gate: A comprehensive validation process to assess the viability of a security finding.
  • 4 Pre-Submission Gates: Ensures the finding meets all criteria for submission.
  • Never Submit List: A list of findings that should never be submitted.
  • CVSS 3.1 Quick Reference: Provides a guide to CVSS scoring for severity assessment.

Quick Start

Run the triage-validation skill to validate your security finding before submitting a report.

Frequently Asked Questions about triage-validation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate security findings before submitting a bug bounty report?

Validate security findings by applying a strict set of criteria to ensure they meet program scope, impact, and authenticity before submission. This process reduces false positives and improves the overall quality of vulnerability reports.

What is the best way to reduce false positives in vulnerability analysis reporting?

Reduce false positives in vulnerability analysis by running findings through a 7-question gate and 4 pre-submission gates. This strict validation process checks for authenticity and program scope before you report.

How does the 7-question gate work for security vulnerability validation?

The 7-question gate works by applying a comprehensive validation process to assess the viability of a security finding. It ensures the vulnerability meets strict criteria for scope, impact, and authenticity before submission.

Can I use a never submit list to filter out invalid bug bounty findings?

Yes, you can use a defined Never Submit List to filter out invalid bug bounty findings. This list identifies specific vulnerability types that should never be submitted, reducing false positives and saving time.

How do I assess vulnerability severity using CVSS 3.1 during security reporting?

Assess vulnerability severity using the provided CVSS 3.1 Quick Reference guide during security reporting. This reference helps bug bounty hunters accurately score and communicate the impact of validated findings.

Are there limitations to automated security finding validation for bug bounty programs?

Security finding validation limits depend on the strict criteria applied to program scope and impact authenticity. Findings on the Never Submit List are automatically filtered out, and those failing the pre-submission gates are blocked to ensure report precision.