Vulnerability Triage Brocards

by trailofbits82fe82262526No license7.4K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated yesterday

This skill should be used when the user asks to "triage a vulnerability report", "assess a CVE", "evaluate a bug bounty submission", "decide if a finding is valid", "review a security finding", "dismiss a vulnerability", "should we fix this CVE", "prioritize a vulnerability report", or needs to determine whether an incoming vulnerability report warrants investigation. Applies 7 brocards (rules of thumb) to systematically accept, dismiss, or request more information on vulnerability reports, or needs to filter raw findings from agentic vulnerability discovery pipelines before human review.

Instructions onlySecurity
  1. 82fe82262526Currentcommit 82fe822Published Oct 8, 2026

Source and attribution

Source:trailofbits/skillsinplugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocardsat commit82fe822

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal