
Exploitability Validation
Validate that vulnerability findings are real, reachable, and exploitable
What You Can Do
This skill runs a deterministic multi-stage pipeline to validate that each vulnerability finding from your scanner is real, reachable in production code, and genuinely exploitable. You eliminate wasted effort on false positives, unreachable code paths, and findings with impossible prerequisites—ensuring your exploit development team only works on findings that matter.
Features
confirms the vulnerable code actually exists and matches the scanner output
proves code paths are reachable in production, not dead code or test-only logic
identifies and flags unrealistic or impossible exploit prerequisites
catches AI-generated false positives before they enter the exploitation pipeline
repeated validation runs produce identical results for consistency and auditability
enforces structured JSON output at each stage for downstream tooling integration
findings must pass Stages B and C before advancing to Stage D, preventing shortcuts
optional cross-model validation using Claude, GPT, and Gemini for high-confidence findings
Example Output
Example 1: Real Finding (Passes)
Stage A: Finding verified
- File: /src/auth.py line 156
- Code matches scanner output exactly
- Reachability: Proven via public API endpoint
- Preconditions: Standard HTTP request, no special privileges
Result: PASS → Proceed to exploit feasibility
Example 2: Hallucinated Finding (Rejected)
Stage A: Finding verification failed
- File: /src/database.py line 489
- Scanner claim: SQL injection in query builder
- Actual code: Parameterized query with bound variables
- Finding is hallucinated
Result: REJECT → Remove from exploitation backlog
Example 3: Unreachable Code (Dead Path)
Stage B: Reachability analysis
- Code exists in /lib/legacy.py line 223
- Path analysis: Only called from deprecated test_suite.py
- Production code does not invoke this path
Result: FAIL → Mark as non-exploitable in production
What's Included
- SKILL.md: Complete execution pipeline definition with configuration and gate logic
- Multi-stage validation framework: Stages A–D for finding verification, reachability analysis, and precondition assessment
- JSON schema definitions: Structured templates for stage outputs, attack trees, and hypothesis tracking
- Validation workflow: Step-by-step checklist for running end-to-end pipeline with error recovery
- Raptor schema validator: Built-in validation commands for stage files and working documents
Who It's For
- Security researchers — Validate scanner findings before investing time in exploit development
- Penetration testers — Confirm vulnerability findings are real and exploitable in client environments
- Red team leads — Prioritize findings with proven reachability and realistic attack paths
- Vulnerability disclosure coordinators — Filter out false positives before reporting to vendors
- Security engineers — Audit scanner quality and identify systematic hallucinations
Best For
- Validating output from automated vulnerability scanners (SAST, DAST, binary analysis)
- Pre-exploit feasibility assessment for time-boxed security assessments
- Filtering high-confidence findings from lower-confidence scanner detections
- Confirming code reachability and attack surface scope
- Building reproducible, auditable vulnerability triage pipelines







