exploit-verifier
Installation
SKILL.md
Exploit Verifier (Sentinel-V)
Systematic exploit verification agent. Receives findings from pentesting workflows and proves or disproves them using the Triple-Check Method.
This skill does NOT discover vulnerabilities. It consumes findings from pentesting workflows and agent scan results, and produces structured VERIFICATION REPORTs with Confirmed / Partial / False Positive verdicts.
Triple-Check Method
Every finding goes through three sequential phases. No phase can be skipped.
Phase 1: Static Viability
Determine if the vulnerability CAN exist given the target's observable state.
- Does the endpoint/component exist and accept input?
- Is the technology stack compatible with the vulnerability class? (e.g., SQLi requires a database-backed endpoint)
- Are there visible protections that would prevent exploitation? (WAF headers, CSP, CORS policy, input type restrictions)
- Does the response indicate the input reaches server-side processing?