common-architecture-di…
Draw architecture diagrams as editable draw.io files with a fixed house style, C4 levels, and evidence-tagged shapes. Use when producing a system context,…
Enforce "No Exploit, No Report" policy with PoC construction standards, false-positive filtering, and evidence collection per vulnerability class across backend, frontend, and mobile. Use when validating security findings, constructing exploit proofs, filtering false positives,
$ npx -y skills add hoangnguyen0403/agent-skills-standard --skill common-exploit-verification --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/common-exploit-verificationContext preview
The summary Claude sees to decide when to auto-load this skill.
Enforce "No Exploit, No Report" policy with PoC construction standards, false-positive filtering, and evidence collection per vulnerability class across backend, frontend, and mobile. Use when validating security findings, constructing exploit proofs, filtering false positives,
name: common-exploit-verification
description: Enforce "No Exploit, No Report" policy with PoC construction standards, false-positive filtering, and evidence collection per vulnerability class across backend, frontend, and mobile. Use when validating security findings, constructing exploit proofs, filtering false positives, or writing pentest findings.
metadata:
triggers:
keywords:
- exploit verification
- proof of concept
- PoC
- false positive
- validate finding
- exploit proof
- pentest finding
- security evidenceEvery confirmed finding must include all fields:
ID: [unique identifier] Vulnerability: [CWE-XXX: type name] Platform: [backend|frontend|mobile-ios|mobile-android] Component: [file:line or endpoint] Severity: [Critical|High|Medium|Low] (CVSS: X.X) OWASP: [mapping — e.g., A03:2021, API1:2023, M4:2024] -- Proof of Concept -- Preconditions: [required state, auth level, config] Steps: 1. [exact step with command/payload] 2. [expected vs actual result] Payload: [exact input — copy-paste ready] Evidence: [response body, status code, data returned] -- Impact -- Impact: [what attacker gains — data, access, control] Blast Radius: [lateral movement, escalation paths] -- Remediation -- Fix: [specific code change, not generic advice]
| Result | Action | Criteria | |---|---|---| | ✅ Confirmed | Include in report | PoC reproduces, impact demonstrated | | ⚠️ Conditional | Include with conditions | Requires specific config/timing/race | | ❌ Unconfirmed | **Discard** | Cannot reproduce despite 3 attempts | | 🔄 Degraded | Downgrade severity | Partial impact, mitigating controls exist |
See [false-positive-checklist](references/false-positive-checklist.md) for platform-specific filters.
Quick checks before reporting:
The portable SDLC standards layer for AI coding agents. Sync once, then work in your own runtime.
Repo: hoangnguyen0403/agent-skills-standard
Draw architecture diagrams as editable draw.io files with a fixed house style, C4 levels, and evidence-tagged shapes. Use when producing a system context,…
Enforce SOLID principles, guard-clause style, function size limits, and intention-revealing naming across all languages. Use when refactoring for readability,…
Standardize BRD and BRD-lite discovery for business goals, stakeholder impact, current-to-future state, and measurable value outcomes. Use when creating BRD,…
Conduct high-quality, persona-driven code reviews. Use when reviewing PRs, critiquing code quality, or analyzing changes for team feedback.
Maximize context window efficiency, reduce latency, and prevent lost-in-middle issues through strategic masking and compaction. Use when token budgets are…
Standardize dynamic application security testing for backend APIs, frontend web apps, and mobile clients. Covers ZAP, Nuclei, Nikto, sqlmap, ffuf, browser…