triage-validation

Validate security findings through ordered Q1–Q7 checks and pre-submission gates.

3.3k|507|Updated May 5, 2026
One-click install
npx skills add https://github.com/elementalsouls/Claude-BugHunter --skill triage-validation-elementalsouls
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: triage-validation
Source: https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/triage-validation
Command: npx skills add https://github.com/elementalsouls/Claude-BugHunter --skill triage-validation-elementalsouls

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Helps security researchers and triagers validate and qualify bug findings using a structured 7-question gate and pre-submission checks to maintain report quality.

Core Features & Use Cases

  • 7-Question Gate checks in strict order ensure every finding is evaluated thoroughly.
  • 4 pre-submission gates prevent premature submissions and enforce evidence readiness.
  • Lifecycle guidance from discovery to reporting, including Never Submit lists and pre-severity gating.

Quick Start

Describe your initial finding and walk through Q1 to Q7 to decide if it should be submitted.

Frequently Asked Questions about triage-validation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate security findings before submitting a bug bounty report?

Pre-severity gating enforces evidence-ready reporting by ranking validated findings during the triage lifecycle, ensuring submitted security reports meet quality thresholds.

What are the pre-submission gates for bug bounty triage?

Pre-submission gates enforce evidence readiness by applying four specific checkpoints alongside a never-submit list, preventing premature bug bounty report submissions.

How does the 7-Question Gate work for security assessments?

The 7-Question Gate evaluates findings across multiple test classes during security assessments, applying ordered checks and pre-severity gating to qualify bug evidence.

What happens to security findings that fail validation checks?

The never-submit list provides lifecycle guidance that flags findings failing pre-submission checks, preventing invalid security reports from progressing to formal submission.

When do I need pre-severity gating for security reporting?

Pre-severity gating enforces evidence-ready reporting by ranking validated findings during the triage lifecycle, ensuring submitted security reports meet quality thresholds.