False-positive check: verify suspected security bugs
Systematically verify a suspected bug to a TRUE/FALSE POSITIVE verdict with documented evidence — never for hunting new bugs
- What
- Systematically verify a suspected bug to a TRUE/FALSE POSITIVE verdict with documented evidence — never for hunting new bugs
- Cost
- Free
- Needs
- none — the skill is a verification workflow, guidance only. Authorized use only: your own code or authorized security assessments; this skill is for verifying suspected bugs, not hunting for new ones.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — ⚠️ **Security warning / Avertissement de sécurité — AUTHORIZED USE ONLY / USAGE AUTORISÉ UNIQUEMENT**: Trail of Bits' verification workflow for suspected security bugs: restate the claim precisely first (step 0 — half of false positives collapse here), reject LLM rationalizations ("pattern recognition is not analysis", no partial analysis), route to standard or deep verification with built-in escalation checkpoints, batch triage with exploit-chain checks across findings, six mandatory gate reviews, bug-class-specific verification requirements (memory corruption, race conditions, integer issues, crypto, injection, info disclosure, DoS, deserialization), a 13-item false-positive-patterns checklist, and a final TRUE/FALSE POSITIVE summary with evidence templates. Kept by editorial choice as a borderline case: verification work can sharpen exploit development, so use it only on your own code or within authorized security assessments. Honest caveats: strictly for verifying suspected bugs — the skill explicitly refuses bug hunting and general code review; CC-BY-SA-4.0 licensed (share-alike). Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: none — the skill is a verification workflow, guidance only. Authorized use only: your own code or authorized security assessments; this skill is for verifying suspected bugs, not hunting for new ones. Install "False-positive check: verify suspected security bugs" for me. It teaches Trail of Bits' workflow for systematically verifying a suspected security bug to a TRUE/FALSE POSITIVE verdict: step-0 claim restatement, rationalization rejection, standard vs deep verification routing, gate reviews, bug-class-specific requirements, false-positive patterns checklist and evidence templates — CC-BY-SA-4.0 licensed. Repository: https://github.com/trailofbits/skills/blob/main/plugins/fp-check/skills/fp-check/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "fp-check". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. bring a concrete suspected bug to verify — this skill does not hunt for bugs). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.