validate

Installation
SKILL.md

Validate finding: $ARGUMENTS

This is the MOST IMPORTANT command. Run it BEFORE writing any report. It takes 30 seconds to kill a bad lead. A report takes 30 minutes.

Step 1: Identify

Read findings.md and brain data. Locate the finding matching "$ARGUMENTS". Show finding details and ask user to confirm.

Step 2: Run 7-Question Gate

Launch validator agent: "Validate this finding through the 7-Question Gate and 4-gate checklist: [finding details]. Check rules/hunting.md Rule 19 for the never-submit list AND rules/mistakes.md (REPORTING + METHODOLOGY sections) for lessons agents commonly miss — especially: (a) theoretical vs confirmed exploits, (b) file-path hallucinations, (c) CVSS-version mismatch per platform, (d) status-code asymmetry ≠ proven bug, (e) single-account IDOR ≠ cross-account leak. Output PASS, KILL, DOWNGRADE, or CHAIN REQUIRED with specific reason."

Step 3: Act on Result

Installs
16
GitHub Stars
812
First Seen
May 10, 2026
validate — h-mmer/pentest-agents