triage-validation

Validate bug submissions against criteria and validation gates.

3|Updated Jul 6, 2026
One-click install
npx skills add https://github.com/hataiit9x/Bbkit-AI --skill triage-validation-hataiit9x
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: triage-validation
Source: https://github.com/hataiit9x/Bbkit-AI/tree/main/ref/claude-bug-bounty/skills/triage-validation
Command: npx skills add https://github.com/hataiit9x/Bbkit-AI --skill triage-validation-hataiit9x

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill assists in validating bug findings before submitting reports, reducing N/A ratio and ensuring submissions meet the necessary criteria.

Core Features & Use Cases

  • 7-Question Gate: A step-by-step validation process to ensure findings are actionable and meet specific criteria.
  • 4 Pre-Submission Gates: Checks for real-world impact, deduplication, and report quality.
  • Never Submit List: A comprehensive list of findings that should never be submitted.
  • Conditionally Valid - Chain Required: Guidance on bugs that require a chain of additional findings to be considered valid.
  • CVSS 3.1 Quick Reference: A reference for determining the severity of bugs based on CVSS 3.1 scoring.

Quick Start

Run the triage-validation skill to check your bug findings before reporting.

Frequently Asked Questions about triage-validation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate bug bounty findings before reporting to reduce N/A submissions?

To validate bug bounty findings before reporting, you can use a 7-Question Gate process and 4 pre-submission checks to ensure findings have real-world impact, avoid deduplication, and meet report quality criteria. This reduces N/A ratios.

What security findings should never be submitted in a bug bounty program?

A comprehensive Never Submit List identifies specific security findings that should never be submitted. By checking your findings against this list before reporting, you ensure submissions are actionable and meet necessary criteria.

When do I need a bug chain for conditionally valid security findings?

Conditionally valid security findings require a chain of additional findings to be considered valid. The validation process provides specific guidance on when a bug chain is required to prove the real-world impact of your submission.

How do I determine the severity of a bug using CVSS 3.1 scoring?

To determine bug severity using CVSS 3.1 scoring, you can reference the provided CVSS 3.1 Quick Reference. This helps ensure accurate severity ratings during the bug validation and triage process before submission.

Can I use this triage validation for security research outside of bug bounty programs?

Yes, this triage validation applies to security researchers and bug bounty hunters. It validates the validity of bug submissions by ensuring they meet specific criteria and rules through careful analysis of findings.

What are the best pre-submission checks for security testing reports?

The best pre-submission checks for security testing reports include 4 pre-submission gates that verify real-world impact, check for deduplication, and ensure report quality. These gates apply after a 7-Question validation process.