triage-validation

Validate reported bugs using a 7-question gate and pre-submission checks.

3|Updated Nov 12, 2025
One-click install
npx skills add https://github.com/cmndcntrlcyber/rtpi --skill triage-validation-cmndcntrlcyber
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: triage-validation
Source: https://github.com/cmndcntrlcyber/rtpi/tree/main/knowledge_seed/bug_hunter_skills/triage-validation
Command: npx skills add https://github.com/cmndcntrlcyber/rtpi --skill triage-validation-cmndcntrlcyber

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps streamline the bug validation process by using a 7-Question Gate and 4 pre-submission checks to ensure the accuracy and validity of reported bugs before they are submitted.

Core Features & Use Cases

  • 7-Question Gate: A series of questions to quickly validate a bug's validity and impact.
  • Pre-submission Checks: Four sequential checks to ensure the bug report meets quality standards.
  • Never Submit List: A comprehensive list of bugs that should never be submitted.
  • Conditional Validity: Certain bugs can be submitted only if they are part of a validated chain.
  • CVSS 3.1 Quick Reference: A reference guide for understanding CVSS scores and severity levels.

Quick Start

Run the triage-validation skill to validate a bug report using the provided checklist and criteria.

Frequently Asked Questions about triage-validation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate bug bounty findings before submitting a report?

You can validate bug bounty findings by applying a structured 7-question gate and four pre-submission checks to verify the accuracy, relevance, and quality of the bug before reporting it.

What is the best way to filter out invalid bugs during red teaming security analysis?

The best way to filter invalid bugs during red teaming security analysis is to cross-reference findings against a comprehensive never submit list and evaluate their conditional validity within an attack chain.

Can I submit a low severity vulnerability if it is part of a larger exploit chain?

Yes, certain low severity vulnerabilities have conditional validity and can be submitted if they are proven to be a necessary part of a validated, higher-impact exploit chain.

How do I ensure my security testing reports meet quality standards?

You ensure security testing reports meet quality standards by running them through four sequential pre-submission checks that verify the accuracy and relevance of the reported vulnerabilities.

What is a 7-question gate for bug validation?

A 7-question gate for bug validation is a structured checklist used to quickly assess a bug's validity and impact, ensuring red team operations submit accurate and relevant findings.

How do I assess CVSS 3.1 severity levels for security vulnerabilities?

You assess CVSS 3.1 severity levels for security vulnerabilities by using a quick reference guide to understand the base scores and determine the accurate severity level for your bug report.