security-triage

Triage OpenClaw security advisories and GHSA reports with evidence.

7|12|Updated Mar 10, 2026
One-click install
npx skills add https://github.com/borealBytes/my-farm-advisor --skill security-triage-borealbytes
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/borealBytes/my-farm-advisor/tree/main/.agents/skills/security-triage
Command: npx skills add https://github.com/borealBytes/my-farm-advisor --skill security-triage-borealbytes

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage OpenClaw security advisories, drafts, and GHSA reports to deliver clear maintainer decisions with evidence and traceable context.

Core Features & Use Cases

  • Enforces a repeatable triage workflow for each advisory, including trust-model checks, state assessment, and decision-making criteria.
  • Guides maintainers through required reads (SECURITY.md, GHSA body, and code review checks) and produces a concise, publish-ready resolution.
  • Supports drafting maintainer-ready comments and documentation of decisions, with traceable links to inputs and checks.

Quick Start

Start by selecting a GHSA advisory and follow the Required Reads to complete a maintainer-ready triage.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage GitHub security advisories for maintainer decisions?▼

To triage GitHub security advisories, follow a structured workflow enforcing trust-model checks, state assessment, and required reads like SECURITY.md to produce high-confidence maintainer decisions with traceable evidence.

What is the process for reviewing GHSA reports during vulnerability disclosure intake?▼

Reviewing GHSA reports during vulnerability disclosure intake involves enforcing required reads, performing code review checks, and assessing the advisory state. This formal review flow produces concise, publish-ready resolutions for maintainers.

Can I use this triage workflow for both draft and shipped OpenClaw security advisories?▼

Yes, this triage workflow applies across vulnerability disclosures, security advisories, and intake reviews for both shipped and open advisories. It guides maintainers through necessary checks to draft maintainer-ready comments and documentation.

How do I draft maintainer-ready comments and documentation for security advisory resolutions?▼

Draft maintainer-ready comments and documentation by completing the formal review flow, which includes required reads and trust-model checks. The process ensures decisions are documented with traceable links to inputs and verification checks.

What trust-model checks are required when triaging security advisories?▼

Trust-model checks during security advisory triage verify the reporter's credibility and advisory state before decision-making. Enforcing these checks alongside required reads like the GHSA body ensures high-confidence resolutions with traceable evidence.