Vulnerability Validation

codexstar69/bug-hunter/skills/vulnerability-validation

作者 codexstar693be69733a27aa04d4f5620df203c05350d162067無授權條款519 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫7 週前更新

Validate security findings for exploitability, reachability, and real-world impact using Bug Hunter-native findings artifacts. Use after security scans, before patch generation, or whenever the user wants confirmation that a suspected vulnerability is actually exploitable.

僅含說明Security
AI 產生的概覽

驗證疑似安全發現的可達性、可利用性與實際影響,並產出 CVSS 評分與概念驗證說明。

功能
此技能接收疑似或已確認的安全發現(優先使用 Bug Hunter 產物,例如 hunter-findings.json 與 threat-model.md),並篩選出與安全相關的部分。它會追蹤漏洞路徑是否可達(外部、已驗證、內部或不可達)以及可利用程度(容易、中等、困難或不可利用),並檢查程式碼、框架行為或部署假設中既有的緩解措施。對於已確認的高風險或嚴重漏洞,它會產生利用路徑、無害的概念驗證,以及 CVSS 向量與評分,並將結果寫入與 Bug Hunter 相容的產物,例如 referee.json、report.md 或 validated-findings.json。
適用情境
適用於安全掃描之後、產生修補程式之前,或任何需要確認疑似漏洞是否真的可被利用的情境。它適合已使用 Bug Hunter 原生發現的流程,並希望對誤報給出明確推理。
執行需求
僅為說明文件,不附帶指令碼。它預期 .bug-hunter 目錄下存在 Bug Hunter 原生產物(例如 hunter-findings.json、threat-model.md、security-config.json,以及選用的 dep-findings.json),並將輸出寫回該目錄。

Vulnerability Validation

This is a bundled local Bug Hunter companion skill. It strengthens the security-specific parts of the Skeptic/Referee process.

Purpose

Take suspected or confirmed security findings and answer:

  • Is the vulnerable path reachable?
  • Can an attacker control the input?
  • Are there existing mitigations?
  • How exploitable is it really?
  • What is the CVSS / PoC / impact level?

Inputs

Prefer Bug Hunter-native artifacts:

  • .bug-hunter/hunter-findings.json
  • .bug-hunter/threat-model.md
  • .bug-hunter/security-config.json
  • .bug-hunter/dep-findings.json when dependency issues are involved

Workflow

  1. Read the findings and isolate the security ones.
  2. Trace reachability:
    • EXTERNAL
    • AUTHENTICATED
    • INTERNAL
    • UNREACHABLE
  3. Trace exploitability:
    • EASY
    • MEDIUM
    • HARD
    • NOT_EXPLOITABLE
  4. Check for mitigations already present in code, framework behavior, or deployment assumptions.
  5. For confirmed HIGH/CRITICAL security bugs, generate:
    • exploitation path
    • benign proof of concept
    • CVSS vector + score
  6. Feed the result back into Bug Hunter-native verdicting.

Outputs

When used as a companion to the main pipeline, keep outputs compatible with:

  • .bug-hunter/referee.json
  • .bug-hunter/report.md

If a separate validation artifact is helpful for the run, place it under .bug-hunter/validated-findings.json.

Important constraints

  • This skill validates findings; it does not replace the normal fix pipeline.
  • Keep outputs portable and self-contained under .bug-hunter/.
  • Prefer explicit reasoning for false positives so the user can trust dismissals.

來源與署名

來源:codexstar69/bug-hunter位於skills/vulnerability-validation提交3be6973

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架