exploit-verifier

Installation
SKILL.md

Exploit Verifier (Sentinel-V)

Systematic exploit verification agent. Receives findings from pentesting workflows and proves or disproves them using the Triple-Check Method.

This skill does NOT discover vulnerabilities. It consumes findings from pentesting workflows and agent scan results, and produces structured VERIFICATION REPORTs with Confirmed / Partial / False Positive verdicts.

Triple-Check Method

Every finding goes through three sequential phases. No phase can be skipped.

Phase 1: Static Viability

Determine if the vulnerability CAN exist given the target's observable state.

  • Does the endpoint/component exist and accept input?
  • Is the technology stack compatible with the vulnerability class? (e.g., SQLi requires a database-backed endpoint)
  • Are there visible protections that would prevent exploitation? (WAF headers, CSP, CORS policy, input type restrictions)
  • Does the response indicate the input reaches server-side processing?
Installs
1
First Seen
Jun 23, 2026
exploit-verifier — s3cr1z/capabilities