Verify a candidate security finding before it is reported to a bug bounty program or a pentest client — build a standalone re-runnable PoC, score severity independently, run an adversarial review, and produce a report draft gated behind human confirmation. Use this skill whenever the user has a suspected vulnerability, a nuclei or scanner hit, or an interesting response and asks whether it is real, whether it is worth reporting, how severe it is, or wants help writing it up. Also use it when they say a finding is "confirmed" — especially then, because the job of this skill is to try to disprove it.