MR
Mayur Rathi
@sickn33
⭐ 47.3k GitHub stars

evidence-hygiene

evidence-hygiene is an code AI skill with a core value of Evidence-capture and PoC-redaction discipline for bug-bounty submissions. It helps developers solve real-world problems in the code domain, boosting efficiency, automating repetitive tasks, and optimizing workflows.

Evidence-capture and PoC-redaction discipline for bug-bounty submissions

Last verified on: 2026-10-06

Quick Facts

Category code
Works With Claude
Source sickn33/antigravity-awesome-skills
Stars ⭐ 47.3k
Last Verified 2026-10-06
Risk Level Low
mkdir -p ./skills/evidence-hygiene && curl -sfL https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/skills/evidence-hygiene/SKILL.md -o ./skills/evidence-hygiene/SKILL.md

Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).

Skill Content

# EVIDENCE HYGIENE — PoC Capture & Redaction Discipline


> Use this skill BEFORE capturing any screenshot, exporting any HAR, or attaching any evidence to a bug-bounty submission. It catches the most common evidence-hygiene mistakes that cause cookies to leak, PII to be shared without consent, or screenshots to be unsuitable for triage.


The core principle: **Bug-bounty evidence is meant to convince a triager. Anything beyond that — live cookies, real-user PII, internal trace IDs that aren't useful — should not be in the evidence.**


---


1. Two Categories of Sensitive Data


Every PoC artifact (screenshot, HAR, raw HTTP request, terminal transcript) potentially contains data that needs different treatment.


| Category | Examples | Treatment |

|---|---|---|

| **Your-account secrets** | Session cookies, OAuth tokens, refresh tokens, API keys | Always redact. Even in private bug-bounty platform attachments. Your account, your session — protect it. |

| **Other users' PII** | Real names, emails, phone numbers, addresses, profile photos, account IDs | Redact unless explicitly demonstrating cross-account impact. Even then, mask faces and minimize the data you display. |

| **Triager-useful metadata** | Trace IDs (`x-datadog-trace-id`), request IDs, server timestamps, your test account UID/email, GraphQL operation names, response shapes | **Leave visible** — these help the triager correlate to logs and reproduce. |

| **Test-account passwords (limited use)** | Throwaway passwords on a test account (e.g., `Testing@5678`) | Acceptable in screenshots if you rotate immediately after submission so the value shown is dead. Don't leave real-use passwords in evidence. |


---


2. Cookie Redaction Protocol


2.1 What must be masked


The session cookie value is the highest-value secret in any PoC. Mask:


- The session cookie (`authn`, `session`, `sid`, `__Secure-id`, etc. — name varies per target)

- `csrf-token` if it's bound to your session

- `Authorization` headers (Bearer tokens, JWT)

- `Cookie` request header values for any session-bearing cookie

- `Set-Cookie` response header values for any session-bearing cookie


2.2 What's safe to leave visible


- Cloudflare cookies (`__cf_bm`, `_cfuvid`) — these are bot-management, not session-bearing

- Analytics cookies (`ajs_anonymous_id`, `_ga`)

- Trace correlation IDs (`x-datadog-trace-id`, `x-request-id`)

- Server / framework headers (`Server: cloudflare`, `X-Frame-Options`)

- Your test account email/UID (per Bugcrowdninja alias section in `bugcrowd-reporting`)


2.3 Redaction methods (ranked by practicality)


**Method A — Don't capture the cookies in the first place** (preferred when possible)

- For DevTools Console PoCs: use `credentials: 'include'` so the browser sends cookies automatically. Console output won't echo the cookie. Screenshot the Console output, never the Network tab Headers panel.

- For Burp Repeater PoCs: drag the bottom request/response panel divider DOWN to hide the request body before screenshotting. Capture only the Results table for Intruder runs.


**Method B — Black-bar in image editor** (when capture inevitably includes cookies)

- macOS: Open screenshot in Preview → Tools → Annotate → Rectangle → set fill color to black → drag rectangle over the cookie value → save

- Windows: Use Snip & Sketch's annotation tools or any image editor (Paint.NET, etc.)

- Burp itself: in Burp's Proxy → Match and Replace, you can pre-emptively redact cookie values to placeholder strings before screenshotting


**Method C — Find/replace in raw text** (for HAR files, terminal transcripts)

- See §4 for the jq commands


2.4 Pre-screenshot checklist


Before clicking Capture:


text
[ ] Network tab Headers panel is collapsed or out of frame
[ ] Burp's Request panel is hidden behind the divider drag
[ ] No "Copy as cURL" output is visible on screen
[ ] DevTools Application → Storage → Cookies tab is closed
[ ] Browser URL bar doesn't show a session token in query string (rare but possibl

🎯 Best For

  • Claude users
  • Software engineers
  • Development teams
  • Tech leads

💡 Use Cases

  • Code quality improvement
  • Best practice enforcement

📖 How to Use This Skill

  1. 1

    Install the Skill

    Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.

  2. 2

    Load into Your AI Assistant

    Open Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.

  3. 3

    Apply evidence-hygiene to Your Work

    Open your project in the AI assistant and ask it to apply the skill. Start with a small module to verify the output quality.

  4. 4

    Review and Refine

    Review AI suggestions before committing. Run tests, check for regressions, and iterate on the skill output.

❓ Frequently Asked Questions

Is evidence-hygiene compatible with Cursor and VS Code?

Yes — this skill works with any AI coding assistant including Cursor, VS Code with Copilot, and JetBrains IDEs.

Do I need specific dependencies for evidence-hygiene?

Check the install command and Works With section. Most code skills only require the AI assistant and your codebase.

How do I install evidence-hygiene?

Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/evidence-hygiene/SKILL.md, ready to use.

Can I customize this skill for my team?

Absolutely. Edit the SKILL.md file to add team-specific instructions, examples, or workflows.

⚠️ Common Mistakes to Avoid

Skipping validation

Always test AI-generated code changes, even for simple refactors.

Missing dependency updates

Check if the skill requires updated dependencies or new packages.

🔗 Related Skills