triage-validation

Validate security findings through a 7-question gate and pre-submission checklist.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/pdparchitect/rook --skill triage-validation-pdparchitect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: triage-validation
Source: https://github.com/pdparchitect/rook/tree/main/skills/triage-validation
Command: npx skills add https://github.com/pdparchitect/rook --skill triage-validation-pdparchitect

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill eliminates low-quality security reports and false positives by enforcing a rigorous, multi-stage validation process before any finding is submitted.

Core Features & Use Cases

  • 7-Question Gate: A mandatory sequence of checks to confirm exploitability, scope, and impact.
  • Pre-Submission Gates: A 4-step checklist covering reality checks, impact validation, deduplication, and report quality.
  • Use Case: Use this skill during a bug bounty engagement to filter out non-actionable findings, ensuring that only high-impact, reproducible vulnerabilities are reported, thereby protecting your validity ratio.

Quick Start

Run the triage-validation skill to audit your current finding against the 7-question gate and pre-submission requirements.

Frequently Asked Questions about triage-validation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate security findings to filter out false positives before reporting?

To validate security findings, you can use a structured 7-question gate that verifies exploitability, scope, and impact. This eliminates false positives by enforcing strict reproducibility and impact demonstration standards before drafting a report.

What is the best way to improve my validity ratio in bug bounty hunting?

The best way to improve your validity ratio is applying a pre-submission checklist during bug bounty hunting. It enforces reality checks, impact validation, deduplication, and report quality to ensure only high-impact, reproducible vulnerabilities are submitted.

How does a pre-submission checklist work for penetration testing reports?

A pre-submission checklist for penetration testing works by applying a 4-step validation process covering reality checks, impact validation, deduplication, and report quality. It ensures findings are actionable and reproducible before submission.

Can I use this validation process for non-actionable vulnerabilities found during pentesting?

You should not use this validation process for non-actionable vulnerabilities. It specifically filters out non-actionable findings by requiring strict scope verification and impact demonstration, ensuring only exploitable security vulnerabilities pass.

When do I need to verify scope and impact demonstration for a security vulnerability?

You need to verify scope and impact demonstration for a security vulnerability before drafting any report. Applying a 7-question gate ensures the finding is within scope, reproducible, and demonstrates clear impact prior to submission.

Why does my bug bounty report keep getting marked as a false positive?

Your bug bounty report may be marked as a false positive due to missing reproducibility or impact demonstration. Applying a multi-stage validation process with a 7-question gate confirms exploitability before submission, preventing low-quality reports.