CtrlK
BlogDocsLog inGet started
Tessl Logo

triage-validation

Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit checklist. Use BEFORE writing any report. One wrong answer = kill the finding and move on. Saves N/A ratio.

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a tight, highly actionable validation playbook with copy-paste templates, explicit feedback loops, and no concept padding. It is well-structured for a single-file checklist skill, with only minor room to split reference material into separate files.

DimensionReasoningScore

Conciseness

Mostly lean checklists, tables, and kill rules with no pedagogical padding about what vulnerabilities are; a few sections (CVSS quick reference, multi-row kill-signal tables) could be tightened but largely earn their tokens.

4 / 5

Actionability

Provides copy-paste-ready templates (the Q1 HTTP request template), concrete kill-signal tables, and specific decision rules that cover the common triage cases directly.

5 / 5

Workflow Clarity

Clear ordered sequences with explicit validation checkpoints ('Ask IN ORDER. One wrong answer = STOP', '4 PRE-SUBMISSION GATES ... ALL 4 must PASS') and feedback loops (kill/downgrade/re-run under each identity).

5 / 5

Progressive Disclosure

Single-file skill (no references/ bundle) with well-organized section headers and tables; structure is clear though it is a longer monolithic document that could optionally split the reference tables out.

4 / 5

Total

18

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong, pairing concrete validation artifacts with an explicit 'Use BEFORE writing any report' trigger and a clearly bounded niche. Specificity and trigger-term coverage sit just below ceiling due to modest synonym breadth and reliance on internal labels.

DimensionReasoningScore

Specificity

Lists several concrete validation components ('7-Question Gate', '4 pre-submission gates', 'always-rejected list', 'conditionally valid with chain table', 'CVSS 3.1 quick reference', 'severity decision guide', 'report title formula', '60-second pre-submit checklist'), with only minor gaps in how they interrelate.

4 / 5

Completeness

Explicitly answers both what ('Finding validation before writing any report — 7-Question Gate ...') and when ('Use BEFORE writing any report') with concrete trigger phrasing.

5 / 5

Trigger Term Quality

Includes natural user phrases ('writing any report', 'Use BEFORE writing any report') but leans on internal skill labels rather than a broad spread of synonyms users would naturally say.

4 / 5

Distinctiveness Conflict Risk

Scoped tightly to bug-bounty report validation/triage methodology with distinct triggers, making overlap with unrelated skills minimal.

5 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
shuvonsec/claude-bug-bounty
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.