triage-validation

Validate bug bounty findings using a structured 7-question process.

Updated Jun 18, 2026
One-click install
npx skills add https://github.com/Kisilev13/Hermes-Agent-Workspace --skill triage-validation-kisilev13
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: triage-validation
Source: https://github.com/Kisilev13/Hermes-Agent-Workspace/tree/main/skills/triage-validation
Command: npx skills add https://github.com/Kisilev13/Hermes-Agent-Workspace --skill triage-validation-kisilev13

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires bugcrowd-reporting, security-arsenal, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill validates bug bounty findings using a comprehensive 7-Question gate, ensuring that findings meet criteria for submission with accurate severity levels.

Core Features & Use Cases

  • 7-Question Validation: A structured process to validate findings against 7 critical questions.
  • Impact Assessment: Evaluates the real-world impact of a finding.
  • Severity Determination: Assists in assigning the correct severity level based on CVSS 3.1 score and program definitions.
  • Use Case: Before submitting a bug bounty finding, use this Skill to ensure it meets the necessary criteria and provide a clear severity determination.

Quick Start

Run the triage-validation skill to validate the impact and severity of a potential bug finding.

Frequently Asked Questions about triage-validation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate bug bounty findings before submitting a report?▼

Bug bounty findings are validated using a structured 7-question gate to ensure they meet submission criteria. This process evaluates real-world impact and checks for always-rejected conditions before submission.

How do I assess the severity of a security vulnerability using CVSS 3.1?▼

Severity assessment for a security vulnerability uses CVSS 3.1 scoring combined with specific program definitions. This determines the accurate severity level by evaluating the real-world impact of the finding alongside its base score.

What is a security triage validation gate and when do I need it?▼

A security triage validation gate is a 7-question process used to verify the validity and severity of potential bug findings. It is needed before submitting a bug bounty finding to ensure it meets necessary acceptance criteria.

Does bug bounty triage require specific environment setup or dependencies?▼

Bug bounty triage requires the bugcrowd-reporting skill for generating reports and the security-arsenal skill for always-rejected checks. These dependencies ensure findings are properly documented and filtered before submission.

What is the best way to determine real-world impact for vulnerability severity assessment?▼

The best way to determine real-world impact is through a structured impact assessment during security triage. This evaluates the practical consequences of the finding to assign a correct severity level based on CVSS 3.1 and program definitions.