From hackenproof-triage
Triages HackenProof bug bounty reports: validates scope, commit/version, PoC evidence, duplicates; assigns severity, state, labels, and comments.
npx claudepluginhub hackenproof-public/skills --plugin hackenproof-triageThis skill uses the workspace's default tool permissions.
Execute consistent, evidence-based triage for HackenProof bug bounty reports.
Bulk triages open reports across assigned HackenProof programs: discovers reports via API, syncs local git repos, analyzes each, outputs structured recommendations for human review.
Automates HackerOne bug bounty workflows: parses scope CSVs, deploys parallel pentesting agents per asset, validates PoCs with poc.py and output, generates submission reports. Use for HackerOne program testing.
Hunts exploitable, bounty-worthy security issues in repositories. Focuses on remotely reachable vulnerabilities qualifying for reports to Huntr, HackerOne, skipping local-only noise.
Share bugs, ideas, or general feedback.
Execute consistent, evidence-based triage for HackenProof bug bounty reports.
references/hackenproof-global-policy.md.get_program_info for scope and reward context.get_program_info (for example: web, mobile, smart-contract, blockchain).references/hackenproof-global-policy.md.get_report_details to extract target, asset, and reported commit/version.get_attachments; if no PoC evidence exists, set Need more info immediately.fetch_attachment to confirm commit/version evidence in PoC files.list_reports/search_comments to check duplicate candidates before validation.get_comments before posting to avoid contradictory messaging.severity, state, labels, and add comments.Need more info and request exact commit evidence.Out of scope with explicit rule reference.dup-{report_id} label when marking Duplicate.Need more info and request concrete PoC evidence.Need more info when PoC is missing, commit/version evidence is missing, or reproduction steps are incomplete with no verifiable PoC.Out of scope when target or impact is excluded by program scope/rules.Duplicate only when matching root cause and impact are confirmed; add dup-{report_id} label.Informative/Not applicable for weak-impact findings that do not meet bounty criteria.Triaged with severity aligned to program policy and demonstrated impact.Use references/severity-mapping.md for impact-to-severity normalization.
Use references/hackenproof-global-policy.md for HackenProof-wide scope and severity baseline.
Use references/triage-comment-templates.md for consistent responder tone and structure.
Need more info) over premature invalidation when uncertainty is material.