Agent skill

Finding Triage

by HacktronAI in HacktronAI/skills

Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either…

MITAuto-check: notesBackend & APIs

Install Finding Triage

skills CLI
$ npx skills add HacktronAI/skills --skill finding-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HacktronAI/skills finding-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HacktronAI/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/finding-triage .claude/skills/finding-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
finding-triage
GitHub stars
115
Token cost
~2.9k tokens
SKILL.md length
1,139 words
Files
2
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either…

  • Works in 6 steps: Fetch findings → Confirm the source location → Ask about live-deployment validation… → …
  • The user asks to validate
  • SKILL.md covers Setup: API key + current API…, Workflow and Rules
  • Calls curl, jq and git; reaches api.hacktron.ai and docs.hacktron.ai; needs HACKTRON_API_KEY

What it does

Finding Triage is an agent skill from HacktronAI/skills. Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either propose fixes and commit them or set the finding's state in Hacktron (truepositive, falsepositive, acceptedrisk, resolved). Talks to the Hacktron REST API with curl, reading the latest API docs at runtime. Use when the user asks to validate, triage, confirm, filter, or fix Hacktron scan or PR-review findings, or mentions…

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `README.md`). Compatibility notes: Requires curl and jq, plus network access to api.hacktron.ai and docs.hacktron.ai, a Hacktron API key, and a local checkout of the affected source. Deployment…

It sits in Backend & APIs, covering Pull requests, Technical documentation and REST APIs. The repository describes itself as: This repository consists of extensions, that hacktron uses to execute specific workflows in CLI. The licence is MIT.

When your agent uses it

  • The user asks to validate
  • Fix Hacktron scan
  • PR-review findings
  • Mentions false positives in a Hacktron scan

Example prompts

  • “/finding-triage”

Requirements

  • A credential in HACKTRON_API_KEY
  • Compatibility (from SKILL.md): Requires curl and jq, plus network access to api.hacktron.ai and docs.hacktron.ai, a Hacktron API key, and a local checkout of the affected source. Deployment access is optional for dynamic validation.
  • Pre-approved tools (allowed-tools): Bash(*), Read, Grep, Glob, Write

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Fetch findings
  2. Confirm the source location
  3. Ask about live-deployment validation (optional)
  4. Triage each finding
  5. Present results, ask what to do next
  6. Write the triage report

What it can do on your machine

Read from SKILL.md and the folder at commit 17ae4af. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(*)
    • Read
    • Grep
    • Glob
    • Write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.hacktron.ai
    • docs.hacktron.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • HACKTRON_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires curl and jq, plus network access to api.hacktron.ai and docs.hacktron.ai, a Hacktron API key, and a local checkout of the affected source. Deployment access is optional for dynamic validation.

    From compatibility in the SKILL.md frontmatter.

Context cost

Finding Triage loads about 2.9k tokens when it runs. Until then it costs about 143 tokens; SKILL.md has 1,139 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~143
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash(*), Read, Grep, Glob, Write

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HacktronAI/skills at commit 17ae4af, republished under its MIT licence (© HacktronAI). 1,139 words, ~2,892 tokens.

Download SKILL.mdSave it as .claude/skills/finding-triage/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
finding-triage
description
Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either propose fixes and commit them or set the finding's state in Hacktron (true_positive, false_positive, accepted_risk, resolved). Talks to the Hacktron REST API with curl, reading the latest API docs at runtime. Use when the user asks to validate, triage, confirm, filter, or fix Hacktron scan or PR-review findings, or mentions false positives in a Hacktron scan.
allowed-tools
Bash(*), Read, Grep, Glob, Write
compatibility
Requires curl and jq, plus network access to api.hacktron.ai and docs.hacktron.ai, a Hacktron API key, and a local checkout of the affected source. Deployment access is optional for dynamic validation.
license
MIT
metadata.author
hacktron
metadata.version
2.0.0
metadata.category
security

Finding Triage

An interactive assistant for triaging Hacktron findings. You drive a conversation: fetch the findings, confirm where the source lives, optionally validate against a live deployment, triage each finding, then either propose fixes and commit them or update the finding's state in Hacktron. You are the validator and the fixer — you read the code and reason yourself.

This skill does not ship API client scripts. The Hacktron REST API is the source of truth and may change, so you read the live docs and call it with curl. Stop and ask the user at each decision point below — do not run end to end silently.

Setup: API key + current API shape

  1. The key goes in the X-Api-Key header. Have the user export it; never hardcode or echo it:
bash
export HACKTRON_API_KEY="hacktron_..."
  1. Smoke-test the key (a 200 with data/total/page/limit means it works):
bash
curl -s -o /dev/null -w "%{http_code}\n" \
  "https://api.hacktron.ai/v1/scans?limit=1" \
  -H "X-Api-Key: $HACKTRON_API_KEY"
  1. Pull the latest API reference before making real calls — endpoints and fields can change. The index lists every page:
bash
curl -s https://docs.hacktron.ai/llms.txt

Read the relevant .md pages from that index as needed, especially:

  • api-reference/findings/list-findings.md — list/filter findings org-wide
  • api-reference/findings/update-finding.md — change state/severity
  • api-reference/scans/export-scan-findings.md — SARIF/CSV/JSON export
  • api-reference/pagination-filtering.md — paging & filter conventions

The curl snippets below are a convenience; if the docs disagree, follow the docs.

Workflow

- [ ] Step 1: Fetch findings
- [ ] Step 2: Confirm the source location
- [ ] Step 3: Ask about live-deployment validation (optional)
- [ ] Step 4: Triage each finding (static + optional dynamic)
- [ ] Step 5: Present results, ask what to do next
- [ ] Step 6a: Propose fixes and commit   (if they want fixes)
- [ ] Step 6b: Set finding state in Hacktron   (if they don't)
- [ ] Step 7: Write the triage report
Step 1: Fetch findings

All unresolved findings org-wide (default state=open), newest first. Findings list endpoints page with page/limit (max limit=100) and report total:

bash
curl -s "https://api.hacktron.ai/v1/findings?state=open&limit=100&page=1" \
  -H "X-Api-Key: $HACKTRON_API_KEY" | jq '.total, (.data | length)'

Iterate pages until you have all total items. Narrow with filters (AND semantics) — e.g. &severity=critical or &scan_id=<uuid>:

bash
curl -s "https://api.hacktron.ai/v1/findings?state=open&severity=critical&limit=100&page=1" \
  -H "X-Api-Key: $HACKTRON_API_KEY" | jq '.data[] | {id, severity, title, affected_file}'

If the user wants a SARIF for a specific scan, export it:

bash
curl -s "https://api.hacktron.ai/v1/scans/<scan-id>/findings/export?format=sarif" \
  -H "X-Api-Key: $HACKTRON_API_KEY" > findings.sarif

The list endpoint returns a summary per finding (id, title, category, severity, state, description, affected_file — a repo-relative path that may include a :line-start-line-end suffix — affected_code, proof_of_concept). For full triage context, fetch the finding by id — it adds reachability evidence you should use in Step 4:

bash
curl -s "https://api.hacktron.ai/v1/findings/<finding-id>" \
  -H "X-Api-Key: $HACKTRON_API_KEY" | jq '{repo_url, scan_type, taint_path, call_graph, mermaid_trace, triage_thread, occurrence_count}'

Key extra fields: repo_url (which repo the path belongs to), taint_path / call_graph / mermaid_trace (the source→sink data flow the scanner traced), and triage_thread (prior triage comments). Show the user the queue and confirm which findings to work through.

Step 2: Confirm the source location

The affected_file paths are repo-relative; the finding's repo_url tells you which repo they belong to. Find the local checkout:

  1. Check the current working directory first. If it matches repo_url and the affected_file paths resolve under the pwd, use it — tell the user "using the source in the current directory."
  2. If they don't resolve, ask the user for the path to the local checkout (mention the repo_url so they grab the right repo).
  3. Confirm the checkout matches the scanned code (same branch/commit if known). Missing files or lines mean those findings are low confidence — say so.
Step 3: Ask about live-deployment validation (optional)

Ask: "Validate these against a live deployment, or source-only?"

If they want dynamic validation, gather and confirm:

  • Base URL / host of the deployment
  • Auth (headers, token, cookies) and which environment it is (prefer staging/test, not production)
  • Scope limits (paths to avoid, rate limits)

Safety rules for dynamic validation:

  • Only run non-destructive, read-only checks unless the user explicitly authorizes active testing of a specific finding.
  • Never run a PoC against production without clear, explicit consent.
  • Stay strictly within the scope and target the user gave you.

If they decline, do source-only validation and note reachability is inferred from code, not confirmed live.

Step 4: Triage each finding

For each finding, do the work yourself — do not trust the scanner's claim.

Static (always):

  1. Read the affected file at the reported lines plus ~20 lines of context. Confirm the flagged code exists as described.
  2. Look for mitigations the scanner missed: bounds checks, input validation, sanitization/encoding, auth/permission checks, allow-lists, safe APIs, parameterized queries, resource limits.
  3. Trace reachability with Grep/Glob: is the path reachable from attacker-controlled input? Use the finding's taint_path / call_graph / mermaid_trace as the scanner's hypothesis, then verify each hop in the real code — don't take the trace on faith. Unreachable code is usually a false positive.
  4. Confirm the bug class fits (e.g. "SQL injection" on a parameterized query is a false positive).

Dynamic (only if Step 3 was approved): 5. Reproduce the finding's proof_of_concept against the deployment within the agreed scope. A confirmed live repro is strong evidence of a true positive.

Then assign, per finding:

  • verdict: true_positive | false_positive
  • confidence: high (conclusive) | medium (strong but uncertain) | low (could not fully validate — file missing, ambiguous, needs a human)
  • adjusted severity: critical | high | medium | low | info, based on realistic exploitability — attack prerequisites, impact scope, exploitation difficulty — not the scanner's default.
Show full SKILL.md (394 more words)Show less
Step 5: Present results, ask what to do next

Show a short per-finding summary (verdict, confidence, severity, one-line reasoning). Then ask how to proceed:

  • "Fix the confirmed true positives?" → Step 6a
  • "Or just record the triage outcome in Hacktron?" → Step 6b
  • Per finding is fine too (fix some, record others).
Step 6a: Propose fixes and commit

Fix only high-confidence true_positive findings. For each:

  1. Propose the fix first — describe the change and show the diff before applying, so the user can approve.
  2. Implement the smallest correct fix. Use the finding's remediation as a starting point but verify it against the real code and match existing style. Fix the root cause, not the symptom. Don't refactor unrelated code.
  3. One commit per finding, so each fix is reviewable and revertible:
bash
git add <changed-files>
git commit -m "$(cat <<'EOF'
fix(security): <short description of the fix>

Addresses Hacktron finding <finding-id> (<category>, <severity>).
<one line on the root cause and how the fix removes it>
EOF
)"
  • Never push or open a PR unless the user explicitly asks.
  • If a fix is risky or needs design decisions, don't guess — leave it and flag it.
Step 6b: Set finding state in Hacktron

PATCH /v1/findings/{id} with at least one of state / severity. Use reason when one justification covers both, or state_reason / severity_reason when they differ (max 2000 chars each):

bash
curl -s -X PATCH "https://api.hacktron.ai/v1/findings/<finding-id>" \
  -H "X-Api-Key: $HACKTRON_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "state": "false_positive",
    "severity": "low",
    "reason": "Query uses bound parameters; user input never concatenated. Not exploitable as reported."
  }'

State meaning (the Hacktron triage states):

  • true_positive — confirmed real (fix pending elsewhere)
  • false_positive — not a real issue
  • accepted_risk — real but the user chooses to accept it
  • resolved — set after a Step 6a fix is merged/deployed
  • severity uses info (not informational).
  • Only sync high/medium-confidence verdicts. Leave low for human review.

The PATCH response returns only the updated state and severity. Confirm with GET /v1/findings/{id} if you need the full record.

Step 7: Write the triage report
markdown
# Triage Report — <scan-id or "org-wide, state=open">

## Summary
- Triaged: N   | TP: N   | FP: N   | High confidence: N
- Dynamic validation: yes/no (target: <env>)
- Fixed & committed: N   | State updated in Hacktron: N

## Findings
### [SEVERITY→adjusted] <title>  (`finding-id`)
- Verdict: true_positive | false_positive  (confidence: high/medium/low)
- File: path:line-range
- Evidence: <static reasoning; live repro result if dynamic>
- Mitigations found: <defensive code that reduces/removes the risk, or "none">
- Action: fixed (<commit sha>) | state set to <state> | left for human review

Rules

  • This flow is interactive — stop and ask at Steps 2, 3, and 5.
  • The Hacktron API is the source of truth: read llms.txt + the endpoint docs before calling, and follow the docs over the snippets here if they differ.
  • Never hardcode or echo the API key; read it from $HACKTRON_API_KEY.
  • Always read the actual source before deciding. No verdict without reading code.
  • Dynamic validation is read-only by default; active testing needs explicit, scoped consent and never targets production without it.
  • Only fix high-confidence true_positive findings, only when asked, and never push or open a PR without explicit instruction.
  • Never set state from a low-confidence verdict; surface it for a human.
  • If the local checkout doesn't match the scanned code, mark affected findings low confidence and note the mismatch.

© HacktronAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in finding-triage of HacktronAI/skills.

  • SKILL.md
  • README.md

Open the folder on GitHubat commit 17ae4af

Compare with similar skills

Finding Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Finding Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Finding Triage this skillHacktronAI/skills115—~2.9kAutomated safety check: NotesMIT
Mintlify APImacro-inc/macro4.6k2 repos~333Automated safety check: PassMIT
Kql ValidatorAzure/azqr794—~703Automated safety check: PassMIT
Ship Coolifykovrichard/catalyst470—~1.9kAutomated safety check: NotesNone
Readme Generator Probeizhi23/README-Generator-Pro113—~472Automated safety check: NotesNone
Frappe Ops Website DeployImpertio-Studio/Frappe_Claude_Skill_Package187—~2.5kAutomated safety check: PassMIT

Similar skills

  • Mintlify API

    macro-inc/macro

    Interact with the Mintlify REST API to manage deployments, trigger builds, and query documentation site metadata programmatically.

    4.6k GitHub starsUsed in 2 repos~333 tokens
    Backend & APIsAuto-check passed
  • Kql Validator

    Azure/azqr

    Official

    Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions.

    794 GitHub stars~703 tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Ship Coolify

    kovrichard/catalyst

    Verify a Coolify deploy end-to-end after a push — wait for GitHub CI, then the Coolify deployment, confirm the commit is live, and run a visual check.

    470 GitHub stars~1.9k tokensUpdated 8 days ago
    Backend & APIsAuto-check: notes
  • Readme Generator Pro

    beizhi23/README-Generator-Pro

    Generate, modify, and render professional README.md files and project introduction HTML pages using the bundled README Generator Pro FastAPI application.

    113 GitHub stars~472 tokensUpdated 3 mo ago
    Backend & APIsAuto-check: notes
  • Frappe Ops Website Deploy

    Impertio-Studio/Frappe_Claude_Skill_Package

    Deploy HTML/CSS websites to ERPNext/Frappe (v15/v16) as Web Pages via the REST API.

    187 GitHub stars~2.5k tokensUpdated 20 days ago
    Backend & APIsAuto-check passed
  • B24phpsdk Maintainer

    bitrix24/b24phpsdk

    A skill your agent uses whenever working with GitHub issues in the bitrix24/b24phpsdk repository: creating new issues, reading existing ones, planning implementation from an issue, referencing an…

    102 GitHub stars~10k tokensUpdated 7 days ago
    Backend & APIsAuto-check: notes

More from HacktronAI/skills

  • Patch Diff Analyzer

    HacktronAI/skills

    Specialized in reverse-engineering compiled binaries (JARs, DLLs).

    115 GitHub stars~2.2k tokensUpdated 4 mo ago
    Auto-check passed

Questions about Finding Triage

What does Finding Triage do?

Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either…. Finding Triage is an agent skill from HacktronAI/skills. Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either propose fixes and commit them or set the finding's state in Hacktron (truepositive, falsepositive, acceptedrisk, resolved).

When should I use Finding Triage?

Finding Triage fits situations like: the user asks to validate; fix Hacktron scan; PR-review findings; mentions false positives in a Hacktron scan.

How do I install Finding Triage in Claude Code?

Run `npx skills add HacktronAI/skills --skill finding-triage -a claude-code`. Or copy the skill folder (finding-triage in HacktronAI/skills) into .claude/skills/finding-triage in your project. Claude Code loads it when a task matches its description.

How do I install Finding Triage in Codex?

Run `npx skills add HacktronAI/skills --skill finding-triage -a codex`. Or copy the skill folder (finding-triage in HacktronAI/skills) into .agents/skills/finding-triage in your project. Codex loads it when a task matches its description.

Can I use Finding Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HacktronAI/skills --skill finding-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/finding-triage, .gemini/skills/finding-triage, .github/skills/finding-triage and .opencode/skills/finding-triage in your project.

What does Finding Triage need to run?

Going by SKILL.md and its folder, Finding Triage needs the command-line tools its instructions call (curl, jq and git) and credentials named HACKTRON_API_KEY. Our summary lists: A credential in HACKTRON_API_KEY. Its frontmatter pre-approves these tools: Bash(*), Read, Grep, Glob, Write. Compatibility (from SKILL.md): Requires curl and jq, plus network access to api.hacktron.ai and docs.hacktron.ai, a Hacktron API key, and a local checkout of the affected source. Deployment access is optional for dynamic validation..

Does Finding Triage access the network?

SKILL.md names 2 domains. In commands or code: api.hacktron.ai and docs.hacktron.ai; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Finding Triage safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Finding Triage use?

Finding Triage is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Finding Triage use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Finding Triage?

Skills that share tags, products or a category with Finding Triage: Mintlify API (macro-inc/macro, 4.6k stars), Kql Validator (Azure/azqr, 794 stars), Ship Coolify (kovrichard/catalyst, 470 stars) and Readme Generator Pro (beizhi23/README-Generator-Pro, 113 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Finding Triage?

HacktronAI (a GitHub organization) maintains it in HacktronAI/skills, which has 115 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on June 4, 2026.

Source: HacktronAI/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.