Security Vuln Gauntlet

Apply the Gauntlet Loop to security vulnerability hunting — a hunter (builder) proposes candidate vulnerabilities and a blind validator (critic) inspects the real artifact and MUST build a working non-destructive PoC before anything is confirmed. The bar is exploitability + CWE mapping + real vulnerability-class precedent; false positives are killed by reachability → taint → PoC gates. Use ONLY on assets you own or are authorized in writing to test; every PoC must be non-destructive. Covers web, API, binary/memory, and cloud/IaC. Trigger keywords: "find vulnerabilities", "security code review", "pentest", "kill false positives", "IDOR", "BOLA", "SQL injection", "SSRF", "path traversal", "exploit PoC", "CWE", "OWASP Top 10", "triage this scan". Use together with the core gauntlet-loop skill.

trilwu 2b32de4 5 files · 28.2 KB Updated

File contents

trilwu/gauntlet-loop-skills/tree/main/skills/security-vuln-gauntlet commit 2b32de40c1

Frequently asked questions

npx skillmds@latest add trilwu/security-vuln-gauntlet