Skip to content
Back to skills

Cyber Exercise Adjudication

ASecurity

Adjudicates authorized exercise outcomes against independently held ground truth, redacted evidence, and explicit status boundaries. Use when comparing observations, resolving discrepancies, or preparing evidence-led security-review handoffs.

  • 571 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
developmentsecurity

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill cyber-exercise-adjudication --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cyber Exercise Adjudication?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cyber Exercise Adjudication
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-cyber-exercise-adjudication-e24491b4/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-cyber-exercise-adjudication-e24491b4)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cyber-exercise-adjudication
guardrail: true
description: Adjudicates authorized exercise outcomes against independently held ground truth, redacted evidence, and explicit status boundaries. Use when comparing observations, resolving discrepancies, or preparing evidence-led security-review handoffs.
metadata:
  labels: [cybersecurity, adjudication, white-team]
  triggers:
    keywords: [exercise adjudication, independent ground truth, outcome adjudication, evidence discrepancy, exercise finding status]
---
# Cyber Exercise Adjudication

## **Priority: P0 (CRITICAL)**

Compare evidence to pre-held expectations without self-approved promotion or compliance claims.

## Structure

```text
cyber-exercise-adjudication/
├── SKILL.md
├── references/adjudication-record.md
└── evals/evals.json
```

## Workflow

1. Confirm adjudicator independence from operator and evidence collector.
2. Load approved objective, scope, expected observation, and ground-truth version.
3. Compare redacted evidence by time, source, and limitation; record discrepancies.
4. Assign `confirmed`, `suspected`, `blocked`, `not-tested`, or `false-positive` only with rationale.
5. Preserve unresolved conflicts and route them to an accountable owner.
6. Emit sanitized findings to `artifacts/security-review.md` when that artifact is in scope.

## Rules

- Independent ground truth is held before observation review; do not rewrite it to fit results.
- A blocked runtime or missing evidence remains blocked, not passed.
- Adjudication describes exercise evidence; it does not certify compliance or measure real-world efficacy.
- Production changes, credential use, and live target interaction remain separately gated.
Adjudication records carry `engagement_scope_ref`, `skill_version`, `source`, `observed_at`, `finding_status`, `evidence_refs`, `limitations`, and `accountable_owner`.

## Anti-Patterns

- **No operator grading**: Separate execution from adjudication.
- **No pass by silence**: Missing observation is not success.
- **No certainty inflation**: Keep suspected and not-tested statuses.
- **No raw leakage**: Redact before handoff.

## References

- [Adjudication record](references/adjudication-record.md)
- [Evidence fields](../cyber-evidence/references/evidence-record.md)

Files in this skill

  • SKILL.md2.2 KB
  • evals/evals.json2.6 KB
  • references/adjudication-record.md656 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…