Agent skill

Program Rubric Lookup

by mtarcure in mtarcure/claude-vibe-squad

A skill your agent uses when you have a candidate finding and must map it to the bounty program's own accepted vulnerability classes, severity language, payout tiers, and submission requirements —…

MITAuto-check passedEducation

Install Program Rubric Lookup

skills CLI
$ npx skills add mtarcure/claude-vibe-squad --skill program-rubric-lookup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mtarcure/claude-vibe-squad program-rubric-lookup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mtarcure/claude-vibe-squad.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/program-rubric-lookup .claude/skills/program-rubric-lookup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
program-rubric-lookup
GitHub stars
163
Token cost
~1k tokens
SKILL.md length
473 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when you have a candidate finding and must map it to the bounty program's own accepted vulnerability classes, severity language, payout tiers, and submission requirements —…

  • Works in 5 steps: Confirm the asset and vulnerability… → Extract the program's controlling… → Map each claimed impact to one quoted or… → …
  • You have a candidate finding and must map it to the bounty programs own accepted vulnerability classes
  • SKILL.md covers Inputs, Method, Acceptance and Payout topology (AUD-11)
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Program Rubric Lookup is an agent skill from mtarcure/claude-vibe-squad. Use when you have a candidate finding and must map it to the bounty program's own accepted vulnerability classes, severity language, payout tiers, and submission requirements — confirm the asset is in scope, cite the exact governing policy clause for each claimed impact, and score conservatively where program rules override generic scoring.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Education, covering Quizzes and assessments. The repository describes itself as: Multi-model AI orchestration where behaviour is Markdown, not code. One coordinator routes scoped task packets to 71 role-based specialists across 5 model families (Codex /… The licence is MIT.

When your agent uses it

  • You have a candidate finding and must map it to the bounty programs own accepted vulnerability classes
  • Severity language
  • Submission requirements — confirm the asset is in scope
  • Cite the exact governing policy clause for each claimed impact

Example prompts

  • “/program-rubric-lookup”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Confirm the asset and vulnerability class are in scope before scoring.
  2. Extract the program's controlling severity rubric and any class-specific caps.
  3. Map each claimed impact to one quoted or precisely cited rubric clause.
  4. Record exclusions, prerequisites, and ambiguity separately from the score.
  5. Produce a conservative classification and identify what evidence would raise or lower it.

What it can do on your machine

Read from SKILL.md and the folder at commit 7bd69f8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Program Rubric Lookup loads about 1k tokens when it runs. Until then it costs about 91 tokens; SKILL.md has 473 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mtarcure/claude-vibe-squad at commit 7bd69f8, republished under its MIT licence (© mtarcure). 473 words, ~1,007 tokens.

Download SKILL.mdSave it as .claude/skills/program-rubric-lookup/SKILL.md (or your agent's skills folder).
name
program-rubric-lookup
description
Use when you have a candidate finding and must map it to the bounty program's own accepted vulnerability classes, severity language, payout tiers, and submission requirements — confirm the asset is in scope, cite the exact governing policy clause for each claimed impact, and score conservatively where program rules override generic scoring.
audience
specialist

Program Rubric Lookup

Map a finding to the target program's accepted vulnerability classes, severity language, payout rubric, and submission requirements.

Inputs

  • The exact program policy or ruleset, with retrieval date and provenance.
  • A concise finding statement, affected asset, impact, and prerequisites.
  • Any explicit exclusions, safe-harbor conditions, or severity overrides.

Method

  1. Confirm the asset and vulnerability class are in scope before scoring.
  2. Extract the program's controlling severity rubric and any class-specific caps.
  3. Map each claimed impact to one quoted or precisely cited rubric clause.
  4. Record exclusions, prerequisites, and ambiguity separately from the score.
  5. Produce a conservative classification and identify what evidence would raise or lower it.

Acceptance

  • Every classification cites the governing policy text and retrieval date.
  • Scope, severity, payout eligibility, and submission requirements are distinct fields.
  • Unsupported impact is marked unproven rather than inferred.
  • Conflicts between generic scoring and program-specific rules resolve in favor of the program rules.
  • The evidence contract is an output, not an assumption. Record, as separate fields: the program type and payout model; the authoritative target and what makes it authoritative (repo@commit, deployed address, host or build, binary hash); the PoC forms the program's own text accepts; and the forms it explicitly forbids, each tied to the clause that says so.
  • Where the program is silent, write "not stated" — never infer a restriction. A generic or internal grading heuristic is not a program rule. Do not conclude from one that a live-chain transaction, a particular tool, or a production crash is required when the program's published text asks only for a working proof of concept. Inferring such a requirement has already sent a campaign chasing evidence nobody asked for.
Show full SKILL.md (195 more words)Show less

Payout topology (AUD-11)

There is no universal severity-to-dollar table — rewards are program-specific. Record, alongside the rubric:

payout_model: fixed_per_severity | range_per_severity | critical_only | contest_pool | unknown
payout_source: exact program clause + retrieval date
marginal_reward_notes: duplicate handling, pool dilution/uniqueness rules, PoC eligibility conditions

Payout topology is an operator SELECTION fact, never a pre-hunt kill list. It informs which program to enter; it never prunes what may be hunted, chained, or banked inside one.

critical_only programs — the disqualifier checklist (AUD-12)

On a critical_only program the grader closes a genuine sub-Critical finding as Informative, not out-of-scope, when “the trigger is not attacker-controlled, impact is off-chain/liveness/MEV, PoC exercises out-of-scope contracts, or the finding requires developer error as proximate cause.” Produce this checklist at Phase 1, so the hunt aims at the step function rather than discovering it at submission time. The finding must survive all four:

  • Attacker-controlled trigger — not a privileged, accidental, or operator-only one.
  • Direct user fund loss or permanent lock — not liveness, not MEV, not off-chain, and not a protocol-insolvency abstraction.
  • In-scope-only PoC surface — the PoC exercises no out-of-scope contract.
  • No dependence on an assumed developer or configuration error as proximate cause.

This is impact-validator's G1 applied with the program's own words. It sets what a hunt aims at; it is not a fifth exclusion ground and it never removes a banked primitive.

© mtarcure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/program-rubric-lookup of mtarcure/claude-vibe-squad.

Open the folder on GitHubat commit 7bd69f8

Compare with similar skills

Program Rubric Lookup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Program Rubric Lookup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Program Rubric Lookup this skillmtarcure/claude-vibe-squad163—~1kAutomated safety check: PassMIT
DeepTutor CLIHKUDS/DeepTutor41k—~2.8kAutomated safety check: PassApache-2.0
AI Engineering Placement Quizrohitg00/ai-engineering-from-scratch66k—~2kAutomated safety check: PassMIT
Codebase to Coursezarazhangrui/codebase-to-course5.7k—~4.4kAutomated safety check: PassNone
AI Engineering Phase Quizrohitg00/ai-engineering-from-scratch66k—~2.1kAutomated safety check: PassMIT
Scholar EvaluationK-Dense-AI/claude-scientific-writer2.4k2 repos~2.9kAutomated safety check: NotesMIT

Similar skills

  • DeepTutor CLI

    HKUDS/DeepTutor

    Teaches the agent to set up and run DeepTutor from the command line: chat and capabilities, knowledge bases, partners, memory, sessions, notebooks and the server or Web app.

    41k GitHub stars~2.8k tokensUpdated today
    EducationAuto-check passed
  • AI Engineering Placement Quiz

    rohitg00/ai-engineering-from-scratch

    Runs a 10-question quiz across five areas to place a learner in the AI Engineering from Scratch curriculum, so they skip what they already know.

    66k GitHub stars~2k tokensUpdated yesterday
    EducationAuto-check passed
  • Codebase to Course

    zarazhangrui/codebase-to-course

    Turns a codebase into an interactive single-page HTML course for non-technical learners, with scroll modules, animated diagrams, quizzes and plain-English code translations.

    5.7k GitHub stars~4.4k tokensUpdated 6 mo ago
    EducationAuto-check passed
  • AI Engineering Phase Quiz

    rohitg00/ai-engineering-from-scratch

    Quizzes you on a completed phase of the AI Engineering from Scratch course, taking a phase number or name and mapping it to that phase's directory.

    66k GitHub stars~2.1k tokensUpdated yesterday
    EducationAuto-check passed
  • Scholar Evaluation

    K-Dense-AI/claude-scientific-writer

    Provide qualitative-first, evidence-traceable developmental review of scholarly works and audit low-stakes research-assessment rubrics with optional local quality controls.

    2.4k GitHub starsUsed in 2 repos~2.9k tokens
    EducationAuto-check: notes
  • Evaluation

    guanyang/open-agent-hub

    This skill should be used when building agent evaluation systems: deterministic checks, regression suites, multi-dimensional rubrics, quality gates, production monitoring, baseline comparison, and…

    975 GitHub starsUsed in 2 repos~4.2k tokens
    EducationAuto-check passed

More from mtarcure/claude-vibe-squad

All 17 skills in this repo
  • Systematic Attacking

    mtarcure/claude-vibe-squad

    A skill your agent uses for ALL authorized offensive-security / bug-bounty work — the single method to find, chain, prove, dedup, and package the highest-value (High/Critical) findings across every…

    163 GitHub stars~3.6k tokensUpdated 17 days ago
    Auto-check passed
  • Blind Rediscovery

    mtarcure/claude-vibe-squad

    Operational checklist + helper for blind-rediscovery fan-out work.

    163 GitHub stars~1.6k tokensUpdated 17 days ago
    Auto-check passed
  • Chain Construct Smart Contract

    mtarcure/claude-vibe-squad

    A skill your agent uses when you have a confirmed on-chain vulnerability hypothesis and must demonstrate it with a passing proof-of-concept — author an attacker contract or crafted instruction…

    163 GitHub stars~1.5k tokensUpdated 17 days ago
    Auto-check passed
  • Compact Now

    mtarcure/claude-vibe-squad

    Operator-triggered proactive compaction — Chrono externalizes load-bearing state (active decisions, open tasks, next action) to a snapshot + a durable Vault learning note before invoking Claude…

    163 GitHub stars~1.6k tokensUpdated 17 days ago
    Auto-check passed
  • Agent Prompt Engineering

    mtarcure/claude-vibe-squad

    A skill your agent uses when building or revising the system prompt for a product agent and you need an eval-backed boundary, tool-use, grounding, and output contract.

    163 GitHub stars~872 tokensUpdated 17 days ago
    Auto-check: warnings
  • Defi Invariant Check

    mtarcure/claude-vibe-squad

    A skill your agent uses when the audit target is a DeFi protocol — AMM, lending market, yield vault, stablecoin, or perps — and you must author the economic properties generic campaigns miss, such…

    163 GitHub stars~2.5k tokensUpdated 17 days ago
    Auto-check passed

Categories

Questions about Program Rubric Lookup

What does Program Rubric Lookup do?

A skill your agent uses when you have a candidate finding and must map it to the bounty program's own accepted vulnerability classes, severity language, payout tiers, and submission requirements —…. Program Rubric Lookup is an agent skill from mtarcure/claude-vibe-squad. Use when you have a candidate finding and must map it to the bounty program's own accepted vulnerability classes, severity language, payout tiers, and submission requirements — confirm the asset is in scope, cite the exact governing policy clause for each claimed impact, and score conservatively where program rules override generic scoring.

When should I use Program Rubric Lookup?

Program Rubric Lookup fits situations like: you have a candidate finding and must map it to the bounty programs own accepted vulnerability classes; severity language; submission requirements — confirm the asset is in scope; cite the exact governing policy clause for each claimed impact.

How do I install Program Rubric Lookup in Claude Code?

Run `npx skills add mtarcure/claude-vibe-squad --skill program-rubric-lookup -a claude-code`. Or copy the skill folder (.agents/skills/program-rubric-lookup in mtarcure/claude-vibe-squad) into .claude/skills/program-rubric-lookup in your project. Claude Code loads it when a task matches its description.

How do I install Program Rubric Lookup in Codex?

Run `npx skills add mtarcure/claude-vibe-squad --skill program-rubric-lookup -a codex`. Or copy the skill folder (.agents/skills/program-rubric-lookup in mtarcure/claude-vibe-squad) into .agents/skills/program-rubric-lookup in your project. Codex loads it when a task matches its description.

Can I use Program Rubric Lookup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mtarcure/claude-vibe-squad --skill program-rubric-lookup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/program-rubric-lookup, .gemini/skills/program-rubric-lookup, .github/skills/program-rubric-lookup and .opencode/skills/program-rubric-lookup in your project.

What does Program Rubric Lookup need to run?

SKILL.md names no scripts, command-line tools or credentials: Program Rubric Lookup is instructions for the agent only.

Does Program Rubric Lookup access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Program Rubric Lookup safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Program Rubric Lookup use?

Program Rubric Lookup is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Program Rubric Lookup use?

About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Program Rubric Lookup?

Skills that share tags, products or a category with Program Rubric Lookup: DeepTutor CLI (HKUDS/DeepTutor, 41k stars), AI Engineering Placement Quiz (rohitg00/ai-engineering-from-scratch, 66k stars), Codebase to Course (zarazhangrui/codebase-to-course, 5.7k stars) and AI Engineering Phase Quiz (rohitg00/ai-engineering-from-scratch, 66k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Program Rubric Lookup?

mtarcure (a GitHub user) maintains it in mtarcure/claude-vibe-squad, which has 163 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on September 21, 2026.

Source: mtarcure/claude-vibe-squad on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.