Use when Codex is already in the validation phase of a security scan or the user explicitly asks to determine whether one or more candidate security findings are valid. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
67
80%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Fix and improve this skill with Tessl
tessl review fix ./plugins/codex-security/skills/validation/SKILL.mdTake candidate findings from discovery and produce the strongest evidence-backed validation assessment you can. Prefer targeted, non-interactive reproduction or falsification when it is feasible and proportionate, but use focused code tracing when dynamic execution is blocked by missing services, unavailable infrastructure, or excessive setup relative to the candidate and scan scope.
The path references in this skill are the default locations for this phase.
If the user explicitly provides a different path for a required input or output, use the user-provided path instead of the corresponding default path referenced in this skill.
If a required input is still missing, stop and ask the user for it before continuing.
Use the shared scan artifact path conventions in ../../references/scan-artifacts.md.
../../references/static-finding-assessment.md to trace source, control, sink, reachability, boundary evidence, counterevidence, and proof gaps.../../references/scan-artifacts.md.../../references/scan-artifacts.md.../../references/scan-artifacts.md. The receipt must record the validation method, evidence or exact proof gap, disposition, and validation artifact/report reference for that candidate finding.Follow the instance-preserving validation rules, validation checklist, and confidence guidance in references/validation-guidance.md.
When validation falls back to static code understanding, or when static evidence is proportionate for large internal repositories, use the shared source/control/sink, boundary, counterevidence, and proof-gap guidance in ../../references/static-finding-assessment.md.
For each candidate finding, include:
- [x] or - [ ] itemsFor repository-wide and scoped-path scans, also include a validation closure table with columns:
reportable, suppressed, not_applicable, or deferredyes, no, or uncertain../../references/scan-artifacts.md, even when the result is suppressed, uncertain, or deferred.../../references/scan-artifacts.md so the full scan bundle lives together.AGENTS.md, README.md, setup docs, test docs, build files, and package-manager metadata to identify the required dependencies, generated files, services, and setup steps.11c74d6
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.