security-triage

Triage GitHub security advisories and verify tags, commits, and trust models.

Updated Apr 24, 2026
One-click install
npx skills add https://github.com/frankhli843/gemmahermes --skill security-triage-frankhli843
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/frankhli843/gemmahermes/tree/main/.agents/skills/security-triage
Command: npx skills add https://github.com/frankhli843/gemmahermes --skill security-triage-frankhli843

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage GitHub security advisories for OpenClaw with high-confidence close/keep decisions, verifying tags and commits and generating maintainer-ready context for quick resolution.

Core Features & Use Cases

  • Rapid assessment of advisories and GHSA reports with clear close/keep recommendations.
  • Exact verification of tags and commits, with trust-model checks against SECURITY.md and related sources.
  • Generate a concise, copy-ready maintainer reply ready to post or share.
  • Use cases include security teams triaging advisories during a release cycle or maintainers validating fixes before publishing.

Quick Start

Run a full triage pass on the latest GHSA advisories to produce a maintainer-ready reply and verification notes.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage GitHub security advisories for OpenClaw?▼

Triage GitHub security advisories by verifying exact tags and commits, performing trust-model checks against SECURITY.md, and generating a maintainer-ready reply with concise verification notes.

What is the best way to verify GHSA reports before a release cycle?▼

Verify GHSA reports by running a full triage pass to assess advisories, check trust-models against SECURITY.md, and produce high-confidence close or keep recommendations with copy-ready maintainer replies.

Can I generate a maintainer-ready reply for a GHSA report?▼

Yes, you can generate a concise, copy-ready maintainer reply suitable for posting or sharing after verifying exact tag and commit information for the GitHub security advisory.

How does the trust-model check work for OpenClaw security advisories?▼

The trust-model check verifies advisory validity by comparing exact tag and commit information against the rules and sources defined in the project's SECURITY.md file to ensure high-confidence decisions.

Do I need exact commit information to keep or close an OpenClaw advisory?▼

Yes, exact tag and commit verification is required to produce high-confidence close or keep decisions for OpenClaw advisories, ensuring maintainer replies are backed by precise validation.

Can I use this for validating security fixes before publishing?▼

Yes, maintainers can use this triage process to validate security fixes before publishing by verifying commits and generating verification reports to ensure safe releases during a cycle.