cyberneticlibrary

Verify security vulnerabilities automatically

vuln-verifiersubagentsetup L378
letsrevel/revel-backend
What it does

Adjudicate single security finding candidate for real exploitability

Best for

Disparity gate after vuln-hunter: independently verify a candidate is a real, present-day, exploitable issue (not false positive).

Inputs
  • · candidate finding JSON
  • · id/title/severity/category/location/description/attack_scenario
Outputs
  • · verdict report
  • · confidence score 0-100
  • · false-positive determination
Preconditions

Single candidate provided; code accessible; project .claude/agent-memory/ files available

Failure modes

Unverified preconditions; by-design feature mistaken for bug; hypothetical future bugs; missing control flow trace

Trust signals
  • · Default posture: skeptical of candidate claims
  • · Checks false-positive rules and memory patterns
  • · Reconstructs complete exploit end-to-end