What problem does it solve?
Security teams drown in raw findings from automated vulnerability discovery pipelines, CVE feeds, and bug bounty submissions, many of which are invalid or not actionable. This Skill provides a systematic, defensible method to filter those reports before committing auditor time, documenting exactly why each finding was accepted or dismissed.
Core Features & Use Cases
- 7-Brocard Evaluation: Tests each report against threat model coherence, attacker capability vs. impact, real-world reachability, standard behavior, documented behavior, remediation cost, and report sufficiency.
- Structured Verdicts: Produces PASS, DISMISS, or NEEDS-MORE-INFO verdicts per brocard with a summary table, overall verdict, and next step.
- Rationalization Guards: Lists common reasoning failures in both directions to prevent wrongly dismissing valid findings or accepting invalid ones.
- Use Case: An agentic vulnerability discovery pipeline produces 50 raw findings overnight. Run each through the 7 brocards to dismiss the majority with documented reasoning and escalate only the survivors to PoC development.
Quick Start
Triage this vulnerability report against the 7 brocards and tell me whether to accept, dismiss, or request more information.