Official agent skill

Vulnerability Triage Brocards

by trailofbits in trailofbits/skills

Screens vulnerability reports, CVEs and automated findings against seven rules of thumb to accept, dismiss or ask for more information before any deep analysis.

OfficialCC-BY-SA-4.0Auto-check passedSecurity

Install Vulnerability Triage Brocards

skills CLI
$ npx skills add trailofbits/skills --skill vulnerability-triage-brocards -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills vulnerability-triage-brocards --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards .claude/skills/vulnerability-triage-brocards && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vulnerability-triage-brocards
GitHub stars
7.4k
Token cost
~2.2k tokens
SKILL.md length
984 words
Files
2 (incl. references)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Screens vulnerability reports, CVEs and automated findings against seven rules of thumb to accept, dismiss or ask for more information before any deep analysis.

  • Filtering raw findings from an agentic vulnerability discovery pipeline
  • SKILL.md covers When to Use, When NOT to Use, Pipeline Position and Triage Workflow, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Deciding whether a bug bounty submission deserves investigation

What it does

This skill puts incoming vulnerability reports through seven falsifiable tests, called brocards, adapted from William Woodruff's Brocards for vulnerability triage. Each report is checked in order and gets one of three verdicts per test: PASS, DISMISS with the reason written down, or NEEDS-MORE-INFO with what is missing. By default evaluation stops at the first DISMISS, though you can ask for a full run through all seven.

Its main use is as a quality gate between automated vulnerability discovery and human review, where most raw findings fail at least one test and can be dropped without auditor time. It also covers triaging findings during an audit, judging third-party CVEs against a codebase, reviewing bug bounty submissions and writing a defensible case for dismissing a CVE. The first brocard dismisses any report without a coherent threat model. It does not hunt for new bugs, prove exploitability or triage fuzzer crashes, and references/brocards-detail.md holds the longer explanations.

When your agent uses it

  • Filtering raw findings from an agentic vulnerability discovery pipeline
  • Deciding whether a bug bounty submission deserves investigation
  • Assessing whether a third-party CVE affects the code under audit
  • Writing a documented justification for dismissing or deprioritizing a CVE

Example prompts

  • “Triage this bug bounty report against the brocards and tell me whether to escalate it.”
  • “Run the full seven-brocard evaluation on the findings in findings.md without stopping at the first dismissal.”
  • “Assess the CVE advisory in advisory.md against our codebase and say whether it needs a fix.”

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are mermaid).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • vulnbrocards.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vulnerability Triage Brocards loads about 2.2k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 156 tokens; SKILL.md has 984 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~156
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 984 words, ~2,181 tokens.

Download SKILL.mdSave it as .claude/skills/vulnerability-triage-brocards/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
vulnerability-triage-brocards
description
This skill should be used when the user asks to "triage a vulnerability report", "assess a CVE", "evaluate a bug bounty submission", "decide if a finding is valid", "review a security finding", "dismiss a vulnerability", "should we fix this CVE", "prioritize a vulnerability report", or needs to determine whether an incoming vulnerability report warrants investigation. Applies 7 brocards (rules of thumb) to systematically accept, dismiss, or request more information on vulnerability reports, or needs to filter raw findings from agentic vulnerability discovery pipelines before human review.

Vulnerability Triage Brocards

Systematically evaluate incoming vulnerability reports against 7 principled criteria before committing resources to deeper analysis. Each brocard is a falsifiable test: if a report fails any brocard, document the reason and dismiss or request clarification. If a report survives all 7, escalate it.

The 7 brocards are adapted from William Woodruff's "Brocards for vulnerability triage" (2026).

When to Use

  • Filtering findings from agentic vulnerability discovery pipelines before human review -- the primary use case; most automated runs produce findings that fail one or more brocards and can be dismissed without auditor time
  • Triaging findings during a ToB audit to decide which warrant escalation to PoC development
  • Evaluating third-party CVEs or advisories against a codebase under active audit to decide if they affect engagement scope
  • Reviewing bug bounty submissions or external vulnerability reports for ToB open-source projects
  • Providing structured, defensible justification when recommending a client dismiss or deprioritize a reported CVE

When NOT to Use

  • Hunting for new bugs during an audit -- use other skills
  • Proving exploitability of a confirmed finding -- use a dedicated PoC/exploitability skill
  • Triaging fuzzer crashes in C/C++ -- use a dedicated crash triage skill

Pipeline Position

This skill is the quality gate between automated discovery and human review. Findings that survive triage proceed to PoC development and formal writeup.

mermaid
flowchart TD
    A([agentic vulnerability discovery]) -->|raw findings| B[vulnerability-triage-brocards]
    B -->|DISMISS| C([Document brocard # and reasoning])
    B -->|NEEDS-MORE-INFO| D([Request specific evidence])
    B -->|ACCEPT| E[PoC / exploitability proof]
    E --> F[vulnerability report writeup]

Triage Workflow

For each incoming vulnerability report, evaluate it against all 7 brocards sequentially. By default, stop at the first DISMISS verdict and report it. If the user requests a full evaluation, continue through all 7 brocards regardless of intermediate failures. For each brocard, record one of three verdicts:

  • PASS -- the report survives this test
  • DISMISS -- the report fails this test; document the reason
  • NEEDS-MORE-INFO -- insufficient evidence to evaluate; specify what is missing
Brocard 1: No Vulnerability Without a Threat Model

Dismiss any report that lacks a coherent threat model. The report must articulate: (a) who the attacker is, (b) what capability the attacker has, (c) how the attacker exploits the behavior, and (d) what harm results.

Reports that describe a code behavior without connecting it to attacker- reachable harm fail this brocard.

Quick test: Can the report answer "an attacker with [capability] can [action] to achieve [impact]"? If not, dismiss or request clarification.

Brocard 2: No Exploit from the Heavens

Dismiss any report where the attacker capabilities required to trigger the vulnerability equal or exceed the impact of the vulnerability itself. If the attacker must already possess the power the exploit would grant, the vulnerability is redundant.

Quick test: Does triggering the exploit require capabilities that already subsume its impact? If yes, dismiss.

Brocard 3: No Vulnerability Outside of Usage

Dismiss any report describing behavior that is theoretically possible but does not occur in actual software usage. Check whether the vulnerable code path is reachable in practice.

Quick test: Is the vulnerable code path exercised by any real caller? If not, dismiss. If the report targets a library, ask if we should check downstream usage.

Brocard 4: No Vulnerability from Standard Behavior

Dismiss any report where the behavior results from correct implementation of a specification. The vulnerability, if any, exists in the standard -- not the implementation.

Nuance: If an implementation voluntarily adopts a stricter posture than the standard requires, and that strictness fails, the implementation is vulnerable even though the standard permits the behavior.

Quick test: Does the specification require or permit this behavior? If yes, the report targets the standard, not the code.

Show full SKILL.md (416 more words)Show less
Brocard 5: No Vulnerability from Documented Behavior

Dismiss any report describing behavior that is explicitly documented, especially when the documentation includes security implications or usage caveats.

Nuance: Downstream usage that violates documented guidelines may constitute a valid vulnerability in the downstream project, not the documented component.

Quick test: Does the project's documentation describe this behavior and warn against misuse? If yes, dismiss the report against the project itself.

Brocard 6: No Cure Worse Than the Disease

Dismiss any report whose remediation would cause more harm than the vulnerability itself. Evaluate: (a) severity of the vulnerability in practice, (b) cost and disruption of the proposed fix, (c) blast radius of the remediation (dependency graph, ecosystem impact).

Quick test: Would fixing this cause more disruption than the vulnerability itself? If yes, dismiss or downgrade severity.

Brocard 7: The Report Is Neither Necessary nor Sufficient

A CVE identifier or formal report does not prove a vulnerability exists. Conversely, absence of a report does not prove safety. Evaluate the technical merits independently of report metadata.

Quick test: Strip the CVE number and CVSS score. Does the technical description alone justify action? Judge on evidence, not authority.

Output Format

After evaluating all 7 brocards, produce a structured triage summary:

## Triage Summary: [Report ID or Title]

| # | Brocard | Verdict | Rationale |
|---|---------|---------|-----------|
| 1 | Threat Model | PASS/DISMISS/NEEDS-MORE-INFO | ... |
| 2 | Exploit from the Heavens | PASS/DISMISS/NEEDS-MORE-INFO | ... |
| 3 | Outside of Usage | PASS/DISMISS/NEEDS-MORE-INFO | ... |
| 4 | Standard Behavior | PASS/DISMISS/NEEDS-MORE-INFO | ... |
| 5 | Documented Behavior | PASS/DISMISS/NEEDS-MORE-INFO | ... |
| 6 | Cure Worse Than Disease | PASS/DISMISS/NEEDS-MORE-INFO | ... |
| 7 | Report Sufficiency | PASS/DISMISS/NEEDS-MORE-INFO | ... |

**Overall Verdict:** ACCEPT / DISMISS / NEEDS-MORE-INFO
**Reasoning:** [1-3 sentence justification]
**Next Step:** [escalate to PoC development / request info / close]

Rationalizations to Reject

Guard against these reasoning failures in both directions:

Wrongly Dismissing Valid Findings
  • "It's only reachable in debug mode" -- verify debug mode is truly never enabled in production; many clients ship with debug flags on
  • "The attacker would need local access" -- local access is a realistic threat model for many deployments, especially containerized services
  • "Nobody uses that API" -- confirm with actual usage data, not assumptions; check client's integration tests and deployment configs
  • "The spec allows it" -- check whether the implementation claims stricter behavior than the spec requires
Wrongly Accepting Invalid Findings
  • "It has a CVE, so it must be real" -- Brocard 7 exists for this reason
  • "The CVSS score is high" -- CVSS is a formula, not a verdict
  • "Better safe than sorry" -- Brocard 6 requires evaluating fix cost
  • "We can't prove it's NOT exploitable" -- the burden of proof is on the reporter to demonstrate a threat model (Brocard 1)
  • "Other projects patched it" -- other projects may have different usage patterns (Brocard 3)
  • "We should include it to pad the report" -- ToB reports reflect technical reality, not finding count targets; a dismissed report with documented reasoning is more valuable than a false positive in a final deliverable

Detailed References

For expanded explanations, examples, and edge cases for each brocard, consult references/brocards-detail.md.

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards of trailofbits/skills.

  • SKILL.md
  • references/brocards-detail.md

Open the folder on GitHubat commit 82fe822

Compare with similar skills

Vulnerability Triage Brocards next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vulnerability Triage Brocards compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vulnerability Triage Brocards this skilltrailofbits/skills7.4k—~2.2kAutomated safety check: PassCC-BY-SA-4.0
Security Analysismicrosoft/haste107—~1kAutomated safety check: PassMIT
Find Cybersecurity Firmjeremylongshore/tons-of-skills-marketplace2.8k—~3.7kAutomated safety check: NotesMIT
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Deepsec Vulnerability Scannervercel-labs/deepsec8.1k—~1.2kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone

Similar skills

  • Security Analysis

    microsoft/haste

    Official

    Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste.

    107 GitHub stars~1k tokensUpdated today
    SecurityAuto-check passed
  • Find Cybersecurity Firm

    jeremylongshore/tons-of-skills-marketplace

    A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed…

    2.8k GitHub stars~3.7k tokensUpdated today
    SecurityAuto-check: notes
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Official

    Runs deepsec's AI-powered security scan over a repository's uncommitted changes, its diff to main, or the whole codebase, using a regex pass followed by agent investigation.

    8.1k GitHub stars~1.2k tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 10 days ago
    SecurityAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated yesterday
    Auto-check: notes
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check: notes

Categories

Questions about Vulnerability Triage Brocards

What does Vulnerability Triage Brocards do?

Screens vulnerability reports, CVEs and automated findings against seven rules of thumb to accept, dismiss or ask for more information before any deep analysis. This skill puts incoming vulnerability reports through seven falsifiable tests, called brocards, adapted from William Woodruff's Brocards for vulnerability triage. Each report is checked in order and gets one of three verdicts per test: PASS, DISMISS with the reason written down, or NEEDS-MORE-INFO with what is missing.

When should I use Vulnerability Triage Brocards?

Vulnerability Triage Brocards fits situations like: filtering raw findings from an agentic vulnerability discovery pipeline; deciding whether a bug bounty submission deserves investigation; assessing whether a third-party CVE affects the code under audit; writing a documented justification for dismissing or deprioritizing a CVE.

How do I install Vulnerability Triage Brocards in Claude Code?

Run `npx skills add trailofbits/skills --skill vulnerability-triage-brocards -a claude-code`. Or copy the skill folder (plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards in trailofbits/skills) into .claude/skills/vulnerability-triage-brocards in your project. Claude Code loads it when a task matches its description.

How do I install Vulnerability Triage Brocards in Codex?

Run `npx skills add trailofbits/skills --skill vulnerability-triage-brocards -a codex`. Or copy the skill folder (plugins/vulnerability-triage-brocards/skills/vulnerability-triage-brocards in trailofbits/skills) into .agents/skills/vulnerability-triage-brocards in your project. Codex loads it when a task matches its description.

Can I use Vulnerability Triage Brocards in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill vulnerability-triage-brocards -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vulnerability-triage-brocards, .gemini/skills/vulnerability-triage-brocards, .github/skills/vulnerability-triage-brocards and .opencode/skills/vulnerability-triage-brocards in your project.

What does Vulnerability Triage Brocards need to run?

SKILL.md names no scripts, command-line tools or credentials: Vulnerability Triage Brocards is instructions for the agent only.

Does Vulnerability Triage Brocards access the network?

SKILL.md names 1 domain. As links in the text: vulnbrocards.com. This is read from the text; nothing was executed.

Is Vulnerability Triage Brocards safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vulnerability Triage Brocards use?

Vulnerability Triage Brocards is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vulnerability Triage Brocards use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.

What are the alternatives to Vulnerability Triage Brocards?

Skills that share tags, products or a category with Vulnerability Triage Brocards: Security Analysis (microsoft/haste, 107 stars), Find Cybersecurity Firm (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Security Auditor (eigent-ai/eigent, 15k stars) and Deepsec Vulnerability Scanner (vercel-labs/deepsec, 8.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vulnerability Triage Brocards?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,440 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.