security-triage

Triage OpenClaw security advisories with shipped-tag and trust-model proof.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/rigeoben/fairy --skill security-triage-rigeoben
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/rigeoben/fairy/tree/main/.agents/skills/security-triage
Command: npx skills add https://github.com/rigeoben/fairy --skill security-triage-rigeoben

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage OpenClaw security advisories, drafts, and GHSA reports with shipped-tag and trust-model proof.

Core Features & Use Cases

  • Structured triage framework guiding maintainers to classify advisories as close/keep open/keep open but narrow.
  • Step-by-step checks including required reads, evidence gathering, and reference verification to ensure accurate state and communication.
  • Generates a maintainer-ready response with exact references and optional hardening notes while preventing escalation beyond documented scope.

Quick Start

Review a GHSA advisory and draft a maintainer-ready closure comment.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage GHSA security advisories with trust-model validation?▼

Triage GHSA security advisories by applying a structured framework that validates shipped-state tags, checks the trust model, and verifies references to determine advisory status, close reasons, and required hardening actions.

What is the best way to draft a maintainer-ready response for a security advisory?▼

Draft a maintainer-ready response by executing reproducible triage steps that generate citeable references, include optional hardening notes, and prevent scope escalation beyond documented advisory evidence.

How does the shipped-tag validation process work for OpenClaw advisories?▼

Shipped-tag validation works by enforcing step-by-step evidence gathering and reference verification checks, ensuring maintainers accurately classify advisories as close, keep open, or keep open but narrow.

Can I use security triage to classify draft advisories as close or keep open?▼

Yes, security triage classifies draft advisories as close, keep open, or keep open but narrow by guiding maintainers through a structured framework of required reads, evidence gathering, and reference verification.

When should I not use an automated advisory triage process?▼

Avoid automated advisory triage when lacking required reads, evidence, or reference verification data, as the process enforces trust-model checks and prevents scope escalation beyond documented advisory evidence.