verdict-gate

Validate bug bounty submissions against a 7-question gate and four pre-submission checks.

1|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/mlvpatel/sentinel-ai-offensive --skill verdict-gate-mlvpatel
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: verdict-gate
Source: https://github.com/mlvpatel/sentinel-ai-offensive/tree/main/skills/verdict-gate
Command: npx skills add https://github.com/mlvpatel/sentinel-ai-offensive --skill verdict-gate-mlvpatel

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage and validate bug bounty submissions with a rigorous, repeatable gate sequence to reduce false positives and wasted effort.

Core Features & Use Cases

  • Enforces a 7-question gate to assess exploitability, impact, scope, and reproducibility.
  • Includes four pre-submission gates to ensure submissions are real, in scope, deduplicated, and of high report quality.
  • Useful for security program operators, triagers, and researchers who need consistent, auditable decision criteria.

Quick Start

Review each report against the gates and proceed only with submissions that pass all checks.

Frequently Asked Questions about verdict-gate

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage bug bounty submissions to filter out false positives?

Bug bounty triage filters false positives by enforcing a formal 7-question gate assessing exploitability, impact, scope, and reproducibility, alongside four pre-submission checks to validate submissions before review.

What is a gate-based triage process for security reports?

Gate-based triage is a rigorous validation process that requires security reports to pass sequential checks for scope alignment, reproducible proof, and impact mapping to severity definitions before being accepted.

How do I validate reproducible proof in vulnerability reports?

Validating reproducible proof in vulnerability reports requires structured evidence including reproduction steps, requests and responses, and remediation guidance to pass formal impact and exploitability assessments.

Can I use automated triage for security assessments requiring severity mapping?

Automated triage supports security assessments by enforcing consistent decision criteria that map submissions directly to a program's severity definitions, ensuring auditable outcomes for researchers and triagers.

What are the limitations of using formal gates for bug report validation?

Formal gate validation requires submissions to include complete reproduction steps and structured remediation guidance, meaning incomplete reports or findings lacking reproducible proof will fail the pre-submission checks.

What's the best way to ensure bug bounty reports are high quality before submission?

Ensuring high-quality bug bounty reports requires applying four pre-submission checks that verify submissions are real, in scope, deduplicated, and contain complete structured evidence before entering the triage queue.