triage-validation

Validate security findings through a seven-question gate before submission.

Updated Jun 5, 2026
One-click install
npx skills add https://github.com/sseshachala/Claude-BugHunter-archive --skill triage-validation-sseshachala
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: triage-validation
Source: https://github.com/sseshachala/Claude-BugHunter-archive/tree/main/skills/triage-validation
Command: npx skills add https://github.com/sseshachala/Claude-BugHunter-archive --skill triage-validation-sseshachala

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill helps security professionals ensure every finding is thoroughly validated before submission, preventing low-quality or invalid reports with a structured 7-Question Gate.

Core Features & Use Cases

  • Enforces a 7-question gate to verify real-world impact, deduplicate findings, and ensure evidence quality.
  • Provides four pre-submission gates to filter out non-actionable issues, with a clear "Never Submit" policy.
  • Supports retraction discipline and appendix-based documentation to maintain report integrity and traceability.
  • Designed for red-team engagements and bug-bounty workflows where high-signal findings are essential.

Quick Start

Answer Q1 through Q7 in order and complete Gates 0–3 before drafting a report.

Frequently Asked Questions about triage-validation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate security findings before submitting a bug bounty report?▼

You validate security findings by applying a structured 7-question gate that verifies real-world impact, deduplicates results, and pairs evidence before reporting. This process filters out non-actionable issues to ensure high-signal submissions.

What is a triage gate in red-team engagements and how does it work?▼

A triage gate is a structured validation checkpoint that prevents invalid submissions in red-team engagements. It works by enforcing a reality check, impact validation, deduplication, and report quality assessment before reporting findings.

How do I prevent invalid bug bounty submissions and low-quality security reports?▼

You prevent invalid bug bounty submissions by enforcing pre-submission policies like a Never Submit List and retraction discipline. Applying a 7-question validation gate ensures findings are checked, deduplicated, and paired with evidence.

Can I use a triage validation workflow for both bug-bounty and red-team engagements?▼

Yes, you can use a triage validation workflow for both bug-bounty and red-team engagements. The 7-question validation gate is designed to validate findings, deduplicate results, and ensure evidence quality across both security workflows.

What are the mandatory steps for security finding deduplication and impact validation?▼

The mandatory steps for deduplication and impact validation are Gate 0 Reality Check, Gate 1 Impact Validation, Gate 2 Deduplication, and Gate 3 Report Quality. Completing these four gates before drafting a report ensures submission integrity.

When should I retract a security finding during a bug-bounty workflow?▼

You should retract a security finding when it fails the 7-question validation gate or violates pre-submission policies. Maintaining retraction discipline and using appendix-based documentation preserves report integrity and traceability.