--- name: report-evidence-validation description: Independently validate an authorized security claim, remove unsupported escalation, redact evidence, and calibrate a minimal reproducible report. --- # Report evidence validation ## Accepted inputs - Current canonical scope and reporting rules - Candidate claim, prerequisites, numbered steps, and raw evidence references - Positive result, negative control, affected owned records, and cleanup status ## Procedure 1. Recheck current scope, exclusions, duplicate policy, and data-handling requirements. 2. Restate the smallest factual claim without severity or chain language. 3. Independently reproduce it with fresh controlled identifiers. 4. Run the supplied negative control and at least one plausible-confounder check. 5. Separate demonstrated capability, demonstrated impact, likely consequence, and untested chain edge. 6. Redact credentials, tokens, personal data, third-party records, and unnecessary infrastructure details. 7. Calibrate severity from demonstrated privileges, reach, interaction, scope, and business effect. ## Output artifacts - Numbered reproduction with expected and observed results - Paired redacted evidence and negative control - Scope statement, impact boundary, severity rationale, and cleanup note ## Stop conditions Stop if scope is stale, reproduction needs uncontrolled data or identity, evidence cannot be safely shared, or the claim depends on an untested edge. ## Completion gate Complete when another authorized reviewer can reproduce the smallest claim, controls reject cheaper explanations, secrets are removed, and only demonstrated impact is stated as fact.