knowledge/external-feedback-triage/SKILL.md
Triage external technical feedback before applying it. Use for code reviews, scanner findings, exploit PoC notes, blog advice, LLM suggestions, issue comments, and advisory recommendations. Verifies context fit, evidence, risk, and minimal changes instead of accepting or rejecting feedback performatively.
npx skillsauth add aeondave/malskill external-feedback-triageInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Treat every external suggestion as a hypothesis until it is checked against the current scope and evidence.
evidence-before-claims before accepting.Do not agree just because feedback sounds authoritative. Push back when:
For non-trivial feedback, return:
Evidence output shape: pair with evidence-before-claims.
Load on demand:
references/review-feedback.md — decision table for reviews, scanner output, advisories, PoCs, and model suggestions.Pair with:
evidence-before-claims — evidence quality and claim wording when verifying accepted feedback.verification-before-completion — freshness gate before claiming the applied fix is complete.development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.