evidence-before-claims
Installation
SKILL.md
Evidence Before Claims
Use this skill when a conclusion could mislead an operator, reviewer, or report reader if it is overstated.
Activation triggers
- Reporting exploitability, vulnerability impact, credential validity, bypass success, persistence, or cleanup.
- Summarizing scanner output, fuzzing crashes, reverse-engineering findings, malware behavior, or OSINT pivots.
- Saying a bug is fixed, a target is safe, a false positive is dismissed, or a root cause is known.
Evidence ladder
Prefer the strongest evidence that is practical and authorized. Scale the bar to the claim's stakes: high-impact, irreversible, or report-bound claims demand the top tiers; reversible local notes do not.
- Observed behavior: a recorded command/API/action and result for the relevant environment. Repeat nondeterministic checks according to the uncertainty; a fixed number of passes does not prove reliability.
- Primary artifact: logs, packet capture, crash trace, hash, file path, HTTP transcript, debugger output. Preserve provenance and context; prefer searchable originals for textual evidence, while screenshots can be primary evidence for visual behavior.
- Independent corroboration: second tool, manual replay, source review, negative control, or version check.
- Reasoned hypothesis: clearly marked as likely/plausible and not final.
- Unverified lead: useful for next steps only, never reported as confirmed. Includes any LLM/subagent assertion not yet checked against a primary artifact.