oracle-verification-technique
Oracle Verification Technique
Goal: A finding is a candidate until a named machine oracle reproduces it against the live target N-out-of-N times AND a negative control fails on a safe surface. Only then is it VERIFIED, shipped with a proof capsule anyone can replay. An LLM assertion, a scanner hit, or a single lucky exploit is never proof on its own.
When this technique applies
- Before reporting any web/API/auth/injection finding as confirmed.
- Triaging third-party scanner output (nuclei, nikto, zap, sqlmap, dalfox) — hold it back until re-proven.
- An LLM or delegated sub-agent claims a vulnerability without a reproducible receipt.
- A report must split VERIFIED from candidate, or a CI gate must break only on proven findings.
- Multi-step chains where each hop must be independently proven before the chain is claimed.
Do not use this to find bugs — it only decides whether a suspected bug is real. Discovery stays with the web-exploit / vuln-exploit / recon techniques; this gates their output.
Core rule (enforce, don't just intend)
No verdict without a named oracle. A
VERIFIEDbadge that cannot name the oracle that earned it is rejected and downgraded tocandidate. The model coordinates; the oracle decides what is true.
Encode this as a hard check in your workflow and in report generation, not as a hope.