Валидация уязвимостей перед отправкой в bug bounty
★ 8.1 · testing
triage-validation is a Claude Code skill that validates security findings before any bug bounty report is written, reducing N/A submissions and protecting the researcher's validity ratio. It contains an 8-question gate (questions asked strictly in order — one wrong answer means killing the finding immediately), four sequential pre-submission gates covering Reality Check, Impact Validation, Deduplication, and Identity verification, an always-rejected vulnerability class list, a conditionally-valid findings table with required exploit chains, a CVSS 3.1 quick reference, a severity decision guide, and a 60-second pre-submit checklist. The Identity Check block (Q8) requires recording which session reproduced the bug and confirming cross-identity behavior — unanswered identity questions auto-fail auth-related findings, which is the most common cause of "confirmed IDOR" reports returning as N/A. The skill is built for bug bounty hunters and security researchers who need a repeatable pre-report gate rather than a post-submission rejection.
- #bug-bounty-validation
- #triage
- #cvss-scoring
- #finding-assessment
- #quality-control
- #pre-submission
- #impact-analysis