What problem does it solve?
Bug bounty researchers frequently waste time and damage their reputation and payout potential by submitting findings that fail program scope checks, lack proven real-world impact, or are already publicly known issues. This Skill eliminates that waste by enforcing strict, structured validation gates before any report is drafted, ensuring only high-quality, actionable findings are submitted.
Core Features & Use Cases
- 7-Question Gate: A step-by-step checklist that kills invalid findings immediately if any answer fails, covering exploitability, scope alignment, impact tangibility, and uniqueness.
- Pre-Submission Validation: 4 sequential time-boxed gates that confirm the bug is real, in scope, reproducible from scratch, and has concrete impact before report writing begins.
- Reference Libraries: Built-in never-submit lists of low-value findings, CVSS 3.1 quick reference tables, conditionally valid bug chain requirements, and retraction discipline templates to avoid common costly reporting mistakes.
- Use Case: A researcher finds a potential open redirect, runs the 7-Question Gate, sees it requires a chain to OAuth redirect_uri theft to be valid, builds and tests the full chain end-to-end before submitting a high-severity finding instead of a low-value standalone report that would be rejected as informative.
Quick Start
Use the triage-validation skill to run the 7-Question Gate on your potential bug bounty finding before you start drafting any report.