triage-validation

Validate security findings through a seven-question gate before submission.

Updated Jun 5, 2026
One-click install
npx skills add https://github.com/sseshachala/Claude-BugHunter-archive --skill triage-validation-sseshachala
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: triage-validation
Source: https://github.com/sseshachala/Claude-BugHunter-archive/tree/main/skills/triage-validation
Command: npx skills add https://github.com/sseshachala/Claude-BugHunter-archive --skill triage-validation-sseshachala

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill helps security professionals ensure every finding is thoroughly validated before submission, preventing low-quality or invalid reports with a structured 7-Question Gate.

Core Features & Use Cases

  • Enforces a 7-question gate to verify real-world impact, deduplicate findings, and ensure evidence quality.
  • Provides four pre-submission gates to filter out non-actionable issues, with a clear "Never Submit" policy.
  • Supports retraction discipline and appendix-based documentation to maintain report integrity and traceability.
  • Designed for red-team engagements and bug-bounty workflows where high-signal findings are essential.

Quick Start

Answer Q1 through Q7 in order and complete Gates 0–3 before drafting a report.

Frequently Asked Questions about triage-validation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate security findings before submitting a bug bounty report?

You validate security findings by applying a structured 7-question gate that verifies real-world impact, deduplicates results, and pairs evidence before reporting. This process filters out non-actionable issues to ensure high-signal submissions.

What is a triage gate in red-team engagements and how does it work?

A triage gate is a structured validation checkpoint that prevents invalid submissions in red-team engagements. It works by enforcing a reality check, impact validation, deduplication, and report quality assessment before reporting findings.

How do I prevent invalid bug bounty submissions and low-quality security reports?

You prevent invalid bug bounty submissions by enforcing pre-submission policies like a Never Submit List and retraction discipline. Applying a 7-question validation gate ensures findings are checked, deduplicated, and paired with evidence.

Can I use a triage validation workflow for both bug-bounty and red-team engagements?

Yes, you can use a triage validation workflow for both bug-bounty and red-team engagements. The 7-question validation gate is designed to validate findings, deduplicate results, and ensure evidence quality across both security workflows.

What are the mandatory steps for security finding deduplication and impact validation?

The mandatory steps for deduplication and impact validation are Gate 0 Reality Check, Gate 1 Impact Validation, Gate 2 Deduplication, and Gate 3 Report Quality. Completing these four gates before drafting a report ensures submission integrity.

When should I retract a security finding during a bug-bounty workflow?

You should retract a security finding when it fails the 7-question validation gate or violates pre-submission policies. Maintaining retraction discipline and using appendix-based documentation preserves report integrity and traceability.