From ddb2e0fb488c6907f0c51a0f3fd92b47276a3966 Mon Sep 17 00:00:00 2001 From: Sandiyo Christan <55909152+sandiyochristan@users.noreply.github.com> Date: Thu, 13 Aug 2026 01:25:40 +0530 Subject: [PATCH] Update strix/skills/custom/validation_methods.md Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com> --- strix/skills/custom/validation_methods.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/strix/skills/custom/validation_methods.md b/strix/skills/custom/validation_methods.md index 3dd2dc0d..673b47ac 100644 --- a/strix/skills/custom/validation_methods.md +++ b/strix/skills/custom/validation_methods.md @@ -48,7 +48,7 @@ Proof: Headless browser confirms onerror fired (e.g., network request to canary ``` Follow-up: create a new object and check if `obj.strix_canary_a1b2c3 === "polluted"`. -**Strength:** Deterministic. If the canary appears, the finding is confirmed. +**Strength:** Deterministic for confirming data flow. Exploitability is confirmed only when the canary demonstrates execution or another concrete security impact. **Weakness:** Only works for injection/reflection classes where you control input and observe output. ### 2. Heuristic / Differential Validation