Vulnerability Validation

codexstar69/bug-hunter/skills/vulnerability-validation

作者 codexstar693be69733a27aa04d4f5620df203c05350d162067无许可证519 个星标收录于 2026年10月9日更新于 2026年10月9日仓库7周前更新

Validate security findings for exploitability, reachability, and real-world impact using Bug Hunter-native findings artifacts. Use after security scans, before patch generation, or whenever the user wants confirmation that a suspected vulnerability is actually exploitable.

仅含说明Security
AI 生成的概览

验证疑似安全发现的可达性、可利用性与实际影响,并给出 CVSS 评分和概念验证说明。

功能
该技能接收疑似或已确认的安全发现(优先使用 Bug Hunter 产物,如 hunter-findings.json 和 threat-model.md),并筛选出与安全相关的部分。它会追踪漏洞路径是否可达(外部、已认证、内部或不可达)以及可利用程度(容易、中等、困难或不可利用),并检查代码、框架行为或部署假设中已有的缓解措施。对于已确认的高危或严重漏洞,它会生成利用路径、无害的概念验证以及 CVSS 向量和评分,并将结果写入与 Bug Hunter 兼容的产物,如 referee.json、report.md 或 validated-findings.json。
适用场景
适用于安全扫描之后、生成补丁之前,或任何需要确认疑似漏洞是否真的可被利用的场景。它适合已经使用 Bug Hunter 原生发现的流程,并希望对误报给出明确推理。
运行要求
仅为说明文档,不附带脚本。它期望 .bug-hunter 目录下存在 Bug Hunter 原生产物(例如 hunter-findings.json、threat-model.md、security-config.json,以及可选的 dep-findings.json),并将输出写回该目录。

Vulnerability Validation

This is a bundled local Bug Hunter companion skill. It strengthens the security-specific parts of the Skeptic/Referee process.

Purpose

Take suspected or confirmed security findings and answer:

  • Is the vulnerable path reachable?
  • Can an attacker control the input?
  • Are there existing mitigations?
  • How exploitable is it really?
  • What is the CVSS / PoC / impact level?

Inputs

Prefer Bug Hunter-native artifacts:

  • .bug-hunter/hunter-findings.json
  • .bug-hunter/threat-model.md
  • .bug-hunter/security-config.json
  • .bug-hunter/dep-findings.json when dependency issues are involved

Workflow

  1. Read the findings and isolate the security ones.
  2. Trace reachability:
    • EXTERNAL
    • AUTHENTICATED
    • INTERNAL
    • UNREACHABLE
  3. Trace exploitability:
    • EASY
    • MEDIUM
    • HARD
    • NOT_EXPLOITABLE
  4. Check for mitigations already present in code, framework behavior, or deployment assumptions.
  5. For confirmed HIGH/CRITICAL security bugs, generate:
    • exploitation path
    • benign proof of concept
    • CVSS vector + score
  6. Feed the result back into Bug Hunter-native verdicting.

Outputs

When used as a companion to the main pipeline, keep outputs compatible with:

  • .bug-hunter/referee.json
  • .bug-hunter/report.md

If a separate validation artifact is helpful for the run, place it under .bug-hunter/validated-findings.json.

Important constraints

  • This skill validates findings; it does not replace the normal fix pipeline.
  • Keep outputs portable and self-contained under .bug-hunter/.
  • Prefer explicit reasoning for false positives so the user can trust dismissals.

来源与署名

来源:codexstar69/bug-hunter位于skills/vulnerability-validation提交3be6973

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架