What it does
- HackerOne: fetches reports and internal comments; for automation-started triage, can post an internal Triage Summary (scope)
- GitHub Security Advisories: reviews advisories selected from the Triage inbox
- Exploitability verification: tests reported issues to confirm they are real and assess impact
- Security verification: XSS context analysis, server-side checks, and out-of-band testing
- Sandbox execution: nuclei, curl, and custom scripts for reproduction
- Web research: related CVEs and exploitation references
- Issue tracking: correlates results with existing issues

