security-triage

Automate triage decisions for GitHub security advisories with verification checks.

1|Updated Apr 28, 2026
One-click install
npx skills add https://github.com/seasonmac/Full-Scene-Agents --skill security-triage-seasonmac
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/seasonmac/Full-Scene-Agents/tree/main/openclaw/.agents/skills/security-triage
Command: npx skills add https://github.com/seasonmac/Full-Scene-Agents --skill security-triage-seasonmac

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage GitHub security advisories, drafts, and GHSA reports to produce high-confidence close or keep decisions, with exact tag and commit verification, trust-model checks, optional hardening notes, and a final reply ready to post and copy to clipboard.

Core Features & Use Cases

  • Evaluates advisories against shipped policy and code paths to ensure decisions align with security posture.
  • Applies to OpenClaw advisories, GHSA reports, and drafts, guiding maintainers to decide when to close, keep open, or keep open but narrow.
  • Generates a copy-ready response suitable for posting or clipboard transfer, including optional hardening notes when beneficial.

Quick Start

Review an advisory and run the triage workflow to generate a final, ready-to-post reply.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate triage decisions for GitHub security advisories?▼

Automate GitHub security advisory triage by evaluating advisories against shipped policy and code paths to produce high-confidence close or keep outcomes with a ready-to-post reply.

What is security triage for GHSA reports and how does it work?▼

Security triage for GHSA reports evaluates trust-model checks and exact tag and commit verification to guide maintainers in deciding whether to close, keep open, or narrow an advisory.

Can I use advisory triage workflows for OpenClaw reports and GitHub drafts?▼

Yes, advisory triage workflows apply to OpenClaw advisories, GHSA reports, and drafts, evaluating code paths to align decisions with your security posture.

How do I generate a ready-to-post reply after triaging a GitHub security advisory?▼

Generate a ready-to-post reply by running the triage workflow, which verifies exact tags and commits, applies trust-model checks, and includes optional hardening notes for clipboard transfer.

What is the best way to verify shipped code paths when triaging security advisories?▼

The best way to verify shipped code paths during security triage is applying deterministic, audit-friendly workflow checks that align advisory decisions with your actual security posture.

When should I keep a GitHub security advisory open instead of closing it?▼

Keep a GitHub security advisory open instead of closing it when trust-model checks or shipped policy evaluations indicate the reported vulnerability still affects active code paths.