Do not mark it confirmed. This violates the **no scanner-only finding** and **no invented certainty** guardrails. Set `finding_status: suspected` and stop promotion. Re-run validation with independent corroboration and an independent reviewer/adjudicator; the operator cannot approve their own result. Proceed only with redacted, provenance-bound evidence showing: - authorized scope and reproducible method; - observed output plus runtime/target confirmation; - timestamps, evidence references, a...
Installs into .claude/skills of the current project.
Are you the author of Cyber Evidence?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-cyber-evidence-b7cf0ddd)
Do not mark it confirmed. This violates the **no scanner-only finding** and **no invented certainty** guardrails.
Set `finding_status: suspected` and stop promotion. Re-run validation with independent corroboration and an independent reviewer/adjudicator; the operator cannot approve their own result.
Proceed only with redacted, provenance-bound evidence showing:
- authorized scope and reproducible method;
- observed output plus runtime/target confirmation;
- timestamps, evidence references, and limitations;
- independently held ground truth and comparison;
- accountable owner.
Preserve the suspected result and any `blocked` or `not-tested` outcomes; do not rewrite them as confirmed or clean.