What problem does it solve? Security teams receive scanner findings and audit requests that mix confirmed risks, false positives, and stale data, making it hard to decide what to fix, what to accept, and how to prove closure. This Skill turns raw scanner and audit claims into validated, owned risk decisions with verifiable evidence. ## Core Features & Use Cases - Finding Validation: Confirm asset scope, affected versions, exposure, and exploitability before classifying findings as confirmed, not applicable, mitigated, false positive, or needs review. - Remediation Planning: Build fix plans with dependencies, rollback, pilot waves, verification tests, owners, and due conditions—without assuming patch success equals closure. - Exception & Compliance Management: Create time-bound risk exceptions with compensating controls and map audit evidence to requested controls without overclaiming certification. - Use Case: A scanner flags a CVE on a production server. Use this Skill to verify the affected version is actually present, assess real exploitability, plan the patch rollout with rollback, and define the exact evidence needed to close the finding. ## Quick Start Validate this vulnerability scan finding for our production web servers and produce a remediation plan with verification evidence and owner assignments.