This skill should be used when the user asks to "validate a finding", "check if a vulnerability is real", "triage a security finding", "confirm a vulnerability", "determine if a finding is a true positive or false positive", or provides a security finding for review. It validates security vulnerability findings by tracing data flows, verifying exploit conditions, analyzing security controls, and optionally testing attack vectors against a live application.
The ghost-validate skill is a specialized security validation tool that determines whether reported security vulnerabilities are true positives or false positives. When security scanners, penetration testers, or bug bounty researchers identify potential vulnerabilities, this skill performs comprehensive validation by analyzing source code, tracing data flows, verifying security controls, and optionally testing against live applications. It eliminates the manual triage burden and provides evidence-based determinations.
This skill supports validation of common vulnerability classes including BFLA (Broken Function Level Authorization), BOLA (Broken Object Level Authorization), XSS (Cross-Site Scripting), SQL Injection, SSRF (Server-Side Request Forgery), and others. It traces request flows from route registration through middleware to handlers, identifies indirect protections that automated scanners may miss, and confirms whether vulnerable code paths are actually reachable. When a live application instance is available, the skill can leverage the reaper proxy to perform active exploitation testing, capturing request-response pairs as concrete evidence.
Security teams, application security engineers, penetration testers, and development teams responsible for vulnerability management benefit from this skill. It streamlines the triage process by providing structured validation reports with clear determinations (True Positive, False Positive, or Inconclusive), confidence levels, supporting evidence from code analysis, and actionable recommendations. The skill can optionally persist validation results back to the original finding files, maintaining a complete audit trail of the security review process.
The skill validates common vulnerability classes including authorization issues (BFLA, BOLA), injection vulnerabilities (XSS, SQLi, SSRF), and other security findings. It analyzes the source code to verify specific claims made by security scanners or researchers.
No, live application access is optional. The skill can perform code-only validation by analyzing source files, tracing data flows, and checking for security controls. However, when a live instance is available, it can perform active testing using the proxy skill for higher-confidence determinations.
You can provide findings either as a file path or by pasting the finding details directly. The skill will extract the vulnerability class, affected endpoint, code location, and specific claims to validate. If information is missing, it will ask for clarification.
The skill outputs a structured report with a determination (True Positive, False Positive, or Inconclusive), confidence level, evidence summary from code analysis, live test results if performed, and specific recommendations for remediation or closure.
Yes, if the finding was provided as a file path, the skill will ask if you want to append the validation details to the original file, creating a complete audit trail of the triage process.
Quick Setup:
.claude/skills/Repository
ghostsecurity/skills