Skip to content
Back to skills

Cyber Evidence

ASecurity

Captures redacted, provenance-aware cybersecurity observations with shared status fields, independent ground truth, and honest limitations. Use when recording exercise evidence, findings, validation results, or security-review handoffs.

  • 571 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
developmentrustsecurity

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill cyber-evidence --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cyber Evidence?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cyber Evidence
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-cyber-evidence-7695795e/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-cyber-evidence-7695795e)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cyber-evidence
guardrail: true
description: Captures redacted, provenance-aware cybersecurity observations with shared status fields, independent ground truth, and honest limitations. Use when recording exercise evidence, findings, validation results, or security-review handoffs.
metadata:
  labels: [cybersecurity, evidence, provenance]
  triggers:
    keywords: [security evidence, evidence record, redacted evidence, finding status, ground truth, evidence gap]
---
# Cyber Evidence

## **Priority: P0 (CRITICAL)**

Record what was observed, how it was sourced, and what remains unknown; never turn absence of proof into proof.

## Structure

```text
cyber-evidence/
├── SKILL.md
├── references/evidence-record.md
└── evals/evals.json
```

## Workflow

1. Bind record to `engagement_scope_ref`, `skill_version`, and `source`.
2. Capture `observed_at`, observer, method, and evidence references; redact secrets and sensitive payloads.
3. Set exactly one `finding_status`: `confirmed`, `suspected`, `blocked`, `not-tested`, or `false-positive`.
4. State limitations, missing runtime controls, synthetic-data boundaries, and accountable owner.
5. Preserve independently held ground truth; compare it only through an independent adjudicator.
6. Update the canonical `artifacts/security-review.md` when a workflow chain already owns that artifact.
Shared record fields: `engagement_scope_ref`, `skill_version`, `source`, `observed_at`, `finding_status`, `evidence_refs`, `limitations`, `accountable_owner`.

## Rules

- Hashes and timestamps support provenance; they do not prove trusted origin or efficacy.
- Keep raw evidence separate from sanitized reports; never persist credentials, real secrets, or unnecessary personal data.
- Preserve blocked and not-tested outcomes; do not downgrade them into clean results.
- Promotion requires independent review; an operator cannot approve their own result.
- Link [authorization](../cyber-authorization/SKILL.md) and [mapping](../cyber-framework-mapping/SKILL.md) only when evidenced.

## Anti-Patterns

- **No scanner-only finding**: Corroborate tool output or mark suspected.
- **No invented certainty**: Use limitations and status fields.
- **No unredacted persistence**: Minimize and sanitize before storage.
- **No rewritten history**: Append corrections with provenance.

## References

- [Evidence record fields](references/evidence-record.md)
- [Canonical security review conventions](../../common/common-security-audit/references/trust-review-policy.md)

Files in this skill

  • SKILL.md2.5 KB
  • evals/evals.json2.5 KB
  • references/evidence-record.md933 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…