cyberneticlibrary

Validate security findings

triage-validationskillsetup L11,791
elementalsouls/Claude-BugHunter
What it does

Validate security findings through 7 questions before report submission

Best for

Filters ineligible findings early (out-of-scope, known, theoretical) saving submission time and maintaining validity ratio.

Inputs
  • · [object Object]
  • · [object Object]
  • · [object Object]
Outputs
  • · [object Object]
  • · [object Object]
  • · [object Object]
Preconditions

Raw finding, access to program scope, access to HackerOne Hacktivity

Failure modes

Q1 fails (cant use right now) kills finding; no HTTP request = invalid; dedup check finds prior report

Trust signals
  • · HackerOne dedup search
  • · Never-submit list (CSP headers, banner alone, self-XSS)
  • · Question 6: impact proof requirement