oracle-verification-technique

Installation
SKILL.md

Oracle Verification Technique

Goal: A finding is a candidate until a named machine oracle reproduces it against the live target N-out-of-N times AND a negative control fails on a safe surface. Only then is it VERIFIED, shipped with a proof capsule anyone can replay. An LLM assertion, a scanner hit, or a single lucky exploit is never proof on its own.

When this technique applies

  • Before reporting any web/API/auth/injection finding as confirmed.
  • Triaging third-party scanner output (nuclei, nikto, zap, sqlmap, dalfox) — hold it back until re-proven.
  • An LLM or delegated sub-agent claims a vulnerability without a reproducible receipt.
  • A report must split VERIFIED from candidate, or a CI gate must break only on proven findings.
  • Multi-step chains where each hop must be independently proven before the chain is claimed.

Do not use this to find bugs — it only decides whether a suspected bug is real. Discovery stays with the web-exploit / vuln-exploit / recon techniques; this gates their output.

Core rule (enforce, don't just intend)

No verdict without a named oracle. A VERIFIED badge that cannot name the oracle that earned it is rejected and downgraded to candidate. The model coordinates; the oracle decides what is true.

Encode this as a hard check in your workflow and in report generation, not as a hope.

Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
oracle-verification-technique — aeondave/malskill