Mintlify API
macro-inc/macro
Interact with the Mintlify REST API to manage deployments, trigger builds, and query documentation site metadata programmatically.
Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either…
$ npx skills add HacktronAI/skills --skill finding-triage -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install HacktronAI/skills finding-triage --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/HacktronAI/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/finding-triage .claude/skills/finding-triage && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "finding-triage" agent skill from https://github.com/HacktronAI/skills/tree/main/finding-triage into .claude/skills/finding-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "finding-triage", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/HacktronAI/skills/tree/main/finding-triageType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add HacktronAI/skills --skill finding-triage -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install HacktronAI/skills finding-triage --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HacktronAI/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/finding-triage .agents/skills/finding-triage && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "finding-triage" agent skill from https://github.com/HacktronAI/skills/tree/main/finding-triage into .agents/skills/finding-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "finding-triage", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add HacktronAI/skills --skill finding-triage -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install HacktronAI/skills finding-triage --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HacktronAI/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/finding-triage .cursor/skills/finding-triage && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "finding-triage" agent skill from https://github.com/HacktronAI/skills/tree/main/finding-triage into .cursor/skills/finding-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "finding-triage", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/HacktronAI/skills.git --path finding-triage--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add HacktronAI/skills --skill finding-triage -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install HacktronAI/skills finding-triage --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HacktronAI/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/finding-triage .gemini/skills/finding-triage && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "finding-triage" agent skill from https://github.com/HacktronAI/skills/tree/main/finding-triage into .gemini/skills/finding-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "finding-triage", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install HacktronAI/skills finding-triageInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add HacktronAI/skills --skill finding-triage -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/HacktronAI/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/finding-triage .github/skills/finding-triage && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "finding-triage" agent skill from https://github.com/HacktronAI/skills/tree/main/finding-triage into .github/skills/finding-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "finding-triage", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add HacktronAI/skills --skill finding-triage -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install HacktronAI/skills finding-triage --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/HacktronAI/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/finding-triage .opencode/skills/finding-triage && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "finding-triage" agent skill from https://github.com/HacktronAI/skills/tree/main/finding-triage into .opencode/skills/finding-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "finding-triage", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
finding-triageInteractively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either…
Finding Triage is an agent skill from HacktronAI/skills. Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either propose fixes and commit them or set the finding's state in Hacktron (truepositive, falsepositive, acceptedrisk, resolved). Talks to the Hacktron REST API with curl, reading the latest API docs at runtime. Use when the user asks to validate, triage, confirm, filter, or fix Hacktron scan or PR-review findings, or mentions…
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `README.md`). Compatibility notes: Requires curl and jq, plus network access to api.hacktron.ai and docs.hacktron.ai, a Hacktron API key, and a local checkout of the affected source. Deployment…
It sits in Backend & APIs, covering Pull requests, Technical documentation and REST APIs. The repository describes itself as: This repository consists of extensions, that hacktron uses to execute specific workflows in CLI. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 17ae4af. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(*)ReadGrepGlobWriteFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curljqgitFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.hacktron.aidocs.hacktron.aiFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
HACKTRON_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires curl and jq, plus network access to api.hacktron.ai and docs.hacktron.ai, a Hacktron API key, and a local checkout of the affected source. Deployment access is optional for dynamic validation.
From compatibility in the SKILL.md frontmatter.
Finding Triage loads about 2.9k tokens when it runs. Until then it costs about 143 tokens; SKILL.md has 1,139 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash(*), Read, Grep, Glob, WriteAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from HacktronAI/skills at commit 17ae4af, republished under its MIT licence (© HacktronAI). 1,139 words, ~2,892 tokens.
.claude/skills/finding-triage/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.An interactive assistant for triaging Hacktron findings. You drive a conversation: fetch the findings, confirm where the source lives, optionally validate against a live deployment, triage each finding, then either propose fixes and commit them or update the finding's state in Hacktron. You are the validator and the fixer — you read the code and reason yourself.
This skill does not ship API client scripts. The Hacktron REST API is the
source of truth and may change, so you read the live docs and call it with
curl. Stop and ask the user at each decision point below — do not run end
to end silently.
X-Api-Key header. Have the user export it; never
hardcode or echo it:export HACKTRON_API_KEY="hacktron_..."200 with data/total/page/limit means it works):curl -s -o /dev/null -w "%{http_code}\n" \
"https://api.hacktron.ai/v1/scans?limit=1" \
-H "X-Api-Key: $HACKTRON_API_KEY"curl -s https://docs.hacktron.ai/llms.txtRead the relevant .md pages from that index as needed, especially:
api-reference/findings/list-findings.md — list/filter findings org-wideapi-reference/findings/update-finding.md — change state/severityapi-reference/scans/export-scan-findings.md — SARIF/CSV/JSON exportapi-reference/pagination-filtering.md — paging & filter conventionsThe curl snippets below are a convenience; if the docs disagree, follow the docs.
- [ ] Step 1: Fetch findings
- [ ] Step 2: Confirm the source location
- [ ] Step 3: Ask about live-deployment validation (optional)
- [ ] Step 4: Triage each finding (static + optional dynamic)
- [ ] Step 5: Present results, ask what to do next
- [ ] Step 6a: Propose fixes and commit (if they want fixes)
- [ ] Step 6b: Set finding state in Hacktron (if they don't)
- [ ] Step 7: Write the triage reportAll unresolved findings org-wide (default state=open), newest first. Findings
list endpoints page with page/limit (max limit=100) and report total:
curl -s "https://api.hacktron.ai/v1/findings?state=open&limit=100&page=1" \
-H "X-Api-Key: $HACKTRON_API_KEY" | jq '.total, (.data | length)'Iterate pages until you have all total items. Narrow with filters (AND
semantics) — e.g. &severity=critical or &scan_id=<uuid>:
curl -s "https://api.hacktron.ai/v1/findings?state=open&severity=critical&limit=100&page=1" \
-H "X-Api-Key: $HACKTRON_API_KEY" | jq '.data[] | {id, severity, title, affected_file}'If the user wants a SARIF for a specific scan, export it:
curl -s "https://api.hacktron.ai/v1/scans/<scan-id>/findings/export?format=sarif" \
-H "X-Api-Key: $HACKTRON_API_KEY" > findings.sarifThe list endpoint returns a summary per finding (id, title, category,
severity, state, description, affected_file — a repo-relative path that
may include a :line-start-line-end suffix — affected_code,
proof_of_concept). For full triage context, fetch the finding by id — it
adds reachability evidence you should use in Step 4:
curl -s "https://api.hacktron.ai/v1/findings/<finding-id>" \
-H "X-Api-Key: $HACKTRON_API_KEY" | jq '{repo_url, scan_type, taint_path, call_graph, mermaid_trace, triage_thread, occurrence_count}'Key extra fields: repo_url (which repo the path belongs to), taint_path /
call_graph / mermaid_trace (the source→sink data flow the scanner traced),
and triage_thread (prior triage comments). Show the user the queue and confirm
which findings to work through.
The affected_file paths are repo-relative; the finding's repo_url tells you
which repo they belong to. Find the local checkout:
repo_url and the
affected_file paths resolve under the pwd, use it — tell the user "using the
source in the current directory."repo_url so they grab the right repo).low confidence — say so.Ask: "Validate these against a live deployment, or source-only?"
If they want dynamic validation, gather and confirm:
Safety rules for dynamic validation:
If they decline, do source-only validation and note reachability is inferred from code, not confirmed live.
For each finding, do the work yourself — do not trust the scanner's claim.
Static (always):
Grep/Glob: is the path reachable from
attacker-controlled input? Use the finding's taint_path / call_graph /
mermaid_trace as the scanner's hypothesis, then verify each hop in the
real code — don't take the trace on faith. Unreachable code is usually a
false positive.Dynamic (only if Step 3 was approved):
5. Reproduce the finding's proof_of_concept against the deployment within the
agreed scope. A confirmed live repro is strong evidence of a true positive.
Then assign, per finding:
true_positive | false_positivehigh (conclusive) | medium (strong but uncertain) | low
(could not fully validate — file missing, ambiguous, needs a human)critical | high | medium | low | info, based on
realistic exploitability — attack prerequisites, impact scope, exploitation
difficulty — not the scanner's default.Show a short per-finding summary (verdict, confidence, severity, one-line reasoning). Then ask how to proceed:
Fix only high-confidence true_positive findings. For each:
remediation as a
starting point but verify it against the real code and match existing style.
Fix the root cause, not the symptom. Don't refactor unrelated code.git add <changed-files>
git commit -m "$(cat <<'EOF'
fix(security): <short description of the fix>
Addresses Hacktron finding <finding-id> (<category>, <severity>).
<one line on the root cause and how the fix removes it>
EOF
)"PATCH /v1/findings/{id} with at least one of state / severity. Use reason
when one justification covers both, or state_reason / severity_reason when
they differ (max 2000 chars each):
curl -s -X PATCH "https://api.hacktron.ai/v1/findings/<finding-id>" \
-H "X-Api-Key: $HACKTRON_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"state": "false_positive",
"severity": "low",
"reason": "Query uses bound parameters; user input never concatenated. Not exploitable as reported."
}'State meaning (the Hacktron triage states):
true_positive — confirmed real (fix pending elsewhere)false_positive — not a real issueaccepted_risk — real but the user chooses to accept itresolved — set after a Step 6a fix is merged/deployedseverity uses info (not informational).high/medium-confidence verdicts. Leave low for human review.The PATCH response returns only the updated state and severity. Confirm with
GET /v1/findings/{id} if you need the full record.
# Triage Report — <scan-id or "org-wide, state=open">
## Summary
- Triaged: N | TP: N | FP: N | High confidence: N
- Dynamic validation: yes/no (target: <env>)
- Fixed & committed: N | State updated in Hacktron: N
## Findings
### [SEVERITY→adjusted] <title> (`finding-id`)
- Verdict: true_positive | false_positive (confidence: high/medium/low)
- File: path:line-range
- Evidence: <static reasoning; live repro result if dynamic>
- Mitigations found: <defensive code that reduces/removes the risk, or "none">
- Action: fixed (<commit sha>) | state set to <state> | left for human reviewllms.txt + the endpoint docs
before calling, and follow the docs over the snippets here if they differ.$HACKTRON_API_KEY.high-confidence true_positive findings, only when asked, and never
push or open a PR without explicit instruction.low-confidence verdict; surface it for a human.low confidence and note the mismatch.© HacktronAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in finding-triage of HacktronAI/skills.
Open the folder on GitHubat commit 17ae4af
Finding Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Finding Triage this skillHacktronAI/skills | 115 | — | ~2.9k | Automated safety check: Notes | MIT | |
| Mintlify APImacro-inc/macro | 4.6k | 2 repos | ~333 | Automated safety check: Pass | MIT | |
| Kql ValidatorAzure/azqr | 794 | — | ~703 | Automated safety check: Pass | MIT | |
| Ship Coolifykovrichard/catalyst | 470 | — | ~1.9k | Automated safety check: Notes | None | |
| Readme Generator Probeizhi23/README-Generator-Pro | 113 | — | ~472 | Automated safety check: Notes | None | |
| Frappe Ops Website DeployImpertio-Studio/Frappe_Claude_Skill_Package | 187 | — | ~2.5k | Automated safety check: Pass | MIT |
macro-inc/macro
Interact with the Mintlify REST API to manage deployments, trigger builds, and query documentation site metadata programmatically.
Azure/azqr
Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions.
kovrichard/catalyst
Verify a Coolify deploy end-to-end after a push — wait for GitHub CI, then the Coolify deployment, confirm the commit is live, and run a visual check.
beizhi23/README-Generator-Pro
Generate, modify, and render professional README.md files and project introduction HTML pages using the bundled README Generator Pro FastAPI application.
Impertio-Studio/Frappe_Claude_Skill_Package
Deploy HTML/CSS websites to ERPNext/Frappe (v15/v16) as Web Pages via the REST API.
bitrix24/b24phpsdk
A skill your agent uses whenever working with GitHub issues in the bitrix24/b24phpsdk repository: creating new issues, reading existing ones, planning implementation from an issue, referencing an…
HacktronAI/skills
Specialized in reverse-engineering compiled binaries (JARs, DLLs).
Categories
Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either…. Finding Triage is an agent skill from HacktronAI/skills. Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either propose fixes and commit them or set the finding's state in Hacktron (truepositive, falsepositive, acceptedrisk, resolved).
Finding Triage fits situations like: the user asks to validate; fix Hacktron scan; PR-review findings; mentions false positives in a Hacktron scan.
Run `npx skills add HacktronAI/skills --skill finding-triage -a claude-code`. Or copy the skill folder (finding-triage in HacktronAI/skills) into .claude/skills/finding-triage in your project. Claude Code loads it when a task matches its description.
Run `npx skills add HacktronAI/skills --skill finding-triage -a codex`. Or copy the skill folder (finding-triage in HacktronAI/skills) into .agents/skills/finding-triage in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HacktronAI/skills --skill finding-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/finding-triage, .gemini/skills/finding-triage, .github/skills/finding-triage and .opencode/skills/finding-triage in your project.
Going by SKILL.md and its folder, Finding Triage needs the command-line tools its instructions call (curl, jq and git) and credentials named HACKTRON_API_KEY. Our summary lists: A credential in HACKTRON_API_KEY. Its frontmatter pre-approves these tools: Bash(*), Read, Grep, Glob, Write. Compatibility (from SKILL.md): Requires curl and jq, plus network access to api.hacktron.ai and docs.hacktron.ai, a Hacktron API key, and a local checkout of the affected source. Deployment access is optional for dynamic validation..
SKILL.md names 2 domains. In commands or code: api.hacktron.ai and docs.hacktron.ai; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Finding Triage is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Finding Triage: Mintlify API (macro-inc/macro, 4.6k stars), Kql Validator (Azure/azqr, 794 stars), Ship Coolify (kovrichard/catalyst, 470 stars) and Readme Generator Pro (beizhi23/README-Generator-Pro, 113 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
HacktronAI (a GitHub organization) maintains it in HacktronAI/skills, which has 115 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on June 4, 2026.
Source: HacktronAI/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.