SkillsLib.ai

Exploitability Validation

Validate that vulnerability findings are real, reachable, and exploitable

4.4(50 reviews)
500+ downloads
Updated Sep 2026
Verified SafeSecurity VerifiedThis skill was analyzed by our AI security scanner for harmful content including data exfiltration, system manipulation, credential theft, and prompt injection. No threats were detected.

What You Can Do

This skill runs a deterministic multi-stage pipeline to validate that each vulnerability finding from your scanner is real, reachable in production code, and genuinely exploitable. You eliminate wasted effort on false positives, unreachable code paths, and findings with impossible prerequisites—ensuring your exploit development team only works on findings that matter.

Features

Real finding verification

confirms the vulnerable code actually exists and matches the scanner output

Reachability analysis

proves code paths are reachable in production, not dead code or test-only logic

Precondition validation

identifies and flags unrealistic or impossible exploit prerequisites

Hallucination detection

catches AI-generated false positives before they enter the exploitation pipeline

Deterministic output

repeated validation runs produce identical results for consistency and auditability

Schema validation

enforces structured JSON output at each stage for downstream tooling integration

Gate-based progression

findings must pass Stages B and C before advancing to Stage D, preventing shortcuts

Multi-model consensus

optional cross-model validation using Claude, GPT, and Gemini for high-confidence findings

Example Output

Example 1: Real Finding (Passes)

code
Stage A: Finding verified
- File: /src/auth.py line 156
- Code matches scanner output exactly
- Reachability: Proven via public API endpoint
- Preconditions: Standard HTTP request, no special privileges
Result: PASS → Proceed to exploit feasibility

Example 2: Hallucinated Finding (Rejected)

code
Stage A: Finding verification failed
- File: /src/database.py line 489
- Scanner claim: SQL injection in query builder
- Actual code: Parameterized query with bound variables
- Finding is hallucinated
Result: REJECT → Remove from exploitation backlog

Example 3: Unreachable Code (Dead Path)

code
Stage B: Reachability analysis
- Code exists in /lib/legacy.py line 223
- Path analysis: Only called from deprecated test_suite.py
- Production code does not invoke this path
Result: FAIL → Mark as non-exploitable in production

What's Included

  • SKILL.md: Complete execution pipeline definition with configuration and gate logic
  • Multi-stage validation framework: Stages A–D for finding verification, reachability analysis, and precondition assessment
  • JSON schema definitions: Structured templates for stage outputs, attack trees, and hypothesis tracking
  • Validation workflow: Step-by-step checklist for running end-to-end pipeline with error recovery
  • Raptor schema validator: Built-in validation commands for stage files and working documents

Who It's For

  • Security researchers — Validate scanner findings before investing time in exploit development
  • Penetration testers — Confirm vulnerability findings are real and exploitable in client environments
  • Red team leads — Prioritize findings with proven reachability and realistic attack paths
  • Vulnerability disclosure coordinators — Filter out false positives before reporting to vendors
  • Security engineers — Audit scanner quality and identify systematic hallucinations

Best For

  • Validating output from automated vulnerability scanners (SAST, DAST, binary analysis)
  • Pre-exploit feasibility assessment for time-boxed security assessments
  • Filtering high-confidence findings from lower-confidence scanner detections
  • Confirming code reachability and attack surface scope
  • Building reproducible, auditable vulnerability triage pipelines

You might also like

Pen Testing Assistant
$40
Pen Testing Assistant

Plan and execute penetration tests with Claude guidance on vulnerability identification, attack path mapping, and risk assessment. You'll accelerate recon automation strategy, CVSS scoring, and report writing—transforming raw scan data into executive-ready security findings with remediation timelines that stakeholders understand and act on.

Data Requirements
$35
Governance4.3(50)
Data Requirements

You convert business process descriptions into structured data specifications that technical teams can implement without follow-up questions. The skill generates detailed data dictionaries specifying what data exists, how it flows, what quality standards it must meet, retention timelines, and compliance requirements. This bridges the communication gap between business stakeholders and data engineers, architects, and compliance officers.

Lore & IP Consistency Validator
$35
Lore/IP3.7(31)
Lore & IP Consistency Validator

You can upload your complete lore documentation—quest texts, character bibles, environmental storytelling, dialogue scripts, timeline documents—and Claude will cross-reference them to flag contradictions, retcons, timeline inconsistencies, and canon gaps. The skill creates an auditable lore database that tracks which content is authoritative, identifies what's been retconned, and highlights missing connective narrative tissue across your IP.

Branching Narrative Architect
$25
Branching Narrative Architect

You can design, validate, and optimize complex branching narratives by mapping narrative topology, analyzing player agency across choice points, tracking narrative promises (narrative debt), and maintaining consistency across diverging story branches. This skill helps you forecast development scope, identify narrative contradictions before they become costly, and ensure player choices feel meaningful rather than illusory.

Coherent World System Builder
$40
Coherent World System Builder

You can systematically architect complex worlds where every system influences others, creating authentic cause-and-effect chains that drive narrative. This skill helps you map dependencies between geography and trade, politics and conflict, culture and faction dynamics, then identify logical inconsistencies before they break immersion. You'll produce consistency documents, lore frameworks, and faction relationship maps that support multi-author projects and branching storylines.

Lore Consistency Validator
$40
Lore/IP3.9(33)
Lore Consistency Validator

This skill transforms Claude into a lore auditor that catches contradictions across your entire narrative ecosystem—character ages, timeline placement, geography, personality consistency, and thematic integrity. You submit your lore documents, established canon, and new content together, and Claude flags logical inconsistencies, temporal conflicts, spatial incoherence, and potential player-facing plot holes before expensive production phases like voice acting or animation begin.

Dialogue Branching Parser & Optimizer
$30
Dialogue Branching Parser & Optimizer

You can upload complex dialogue documents and have Claude analyze their branching structure for logical inconsistencies, tonal drift, pacing issues, and player agency problems. Claude validates that character voices remain consistent across multiple writers' contributions, maps decision architecture to ensure choices matter narratively, and identifies dead-end conversations or unresolved dialogue threads. The result is a structured audit with actionable recommendations for optimization before dialogue implementation into branching engines like Yarn, ink, or Dialogue Flow.

Branching Narrative Planner
$35
Branching Narrative Planner

You can design multi-path narratives that feel coherent and meaningful by modeling how player choices create cascading consequences across story branches. This skill helps you track character state changes, dialogue dependencies, and narrative convergence points—ensuring that player agency feels genuine, not illusory. You'll identify and eliminate plot holes, false choices, and continuity errors before they reach players.

$25.00