LogoAwesome Skills
  • Search
  • Category
  • Tag
  • Blog
LogoAwesome Skills
LogoAwesome Skills

Discover Open-Source Agent Skills for AI Coding Assistants

Product

  • Search
  • Category
  • Tag
  • Blog

Resources

  • Claude Skill Docs
  • Antigravity Skills Docs

Tools

  • Claude Code
  • OpenCode
  • Cursor
  • Codex
  • Antigravity

Company

  • Privacy Policy
  • Terms of Service
  • Sitemap

©2026 Awesome Skills. All rights reserved.

Privacy PolicyTerms
Back to Skills

ghost-validate

This skill should be used when the user asks to "validate a finding", "check if a vulnerability is real", "triage a security finding", "confirm a vulnerability", "determine if a finding is a true positive or false positive", or provides a security finding for review. It validates security vulnerability findings by tracing data flows, verifying exploit conditions, analyzing security controls, and optionally testing attack vectors against a live application.

393stars26forksUpdated 6/22/2026
Security#security#triage#penetration-testing#vulnerability-assessment#security-validation#code-analysis

Security Assessment

Safe(100/100)
Security Score100/100

About ghost-validate

The ghost-validate skill is a specialized security validation tool that determines whether reported security vulnerabilities are true positives or false positives. When security scanners, penetration testers, or bug bounty researchers identify potential vulnerabilities, this skill performs comprehensive validation by analyzing source code, tracing data flows, verifying security controls, and optionally testing against live applications. It eliminates the manual triage burden and provides evidence-based determinations.

This skill supports validation of common vulnerability classes including BFLA (Broken Function Level Authorization), BOLA (Broken Object Level Authorization), XSS (Cross-Site Scripting), SQL Injection, SSRF (Server-Side Request Forgery), and others. It traces request flows from route registration through middleware to handlers, identifies indirect protections that automated scanners may miss, and confirms whether vulnerable code paths are actually reachable. When a live application instance is available, the skill can leverage the reaper proxy to perform active exploitation testing, capturing request-response pairs as concrete evidence.

Security teams, application security engineers, penetration testers, and development teams responsible for vulnerability management benefit from this skill. It streamlines the triage process by providing structured validation reports with clear determinations (True Positive, False Positive, or Inconclusive), confidence levels, supporting evidence from code analysis, and actionable recommendations. The skill can optionally persist validation results back to the original finding files, maintaining a complete audit trail of the security review process.

FAQ

What types of vulnerabilities can ghost-validate assess?

The skill validates common vulnerability classes including authorization issues (BFLA, BOLA), injection vulnerabilities (XSS, SQLi, SSRF), and other security findings. It analyzes the source code to verify specific claims made by security scanners or researchers.

Does ghost-validate require access to a running application?

No, live application access is optional. The skill can perform code-only validation by analyzing source files, tracing data flows, and checking for security controls. However, when a live instance is available, it can perform active testing using the proxy skill for higher-confidence determinations.

How do I provide a security finding for validation?

You can provide findings either as a file path or by pasting the finding details directly. The skill will extract the vulnerability class, affected endpoint, code location, and specific claims to validate. If information is missing, it will ask for clarification.

What format does the validation report use?

The skill outputs a structured report with a determination (True Positive, False Positive, or Inconclusive), confidence level, evidence summary from code analysis, live test results if performed, and specific recommendations for remediation or closure.

Can validation results be saved with the original finding?

Yes, if the finding was provided as a file path, the skill will ask if you want to append the validation details to the original file, creating a complete audit trail of the triage process.

All Files

2 files
SKILL.md4.2 KB
View
VULNERABILITY_PATTERNS.md0.9 KB
View

Install ghost-validate

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill

Repository

ghostsecurity/skills

Related Skills

ccf-idea-reviewer

2,958

ccf-integrity-auditor

2,958

finance-sentiment

3,382

ccf-humanization

2,958