security-triage

Triages GitHub security advisories for OpenClaw with git tag and npm state verification.

Updated Jan 31, 2026
One-click install
npx skills add https://github.com/zyj18860969891-byte/openclaw-railway --skill security-triage-zyj18860969891-byte
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/zyj18860969891-byte/openclaw-railway/tree/main/.agents/skills/security-triage
Command: npx skills add https://github.com/zyj18860969891-byte/openclaw-railway --skill security-triage-zyj18860969891-byte

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage GitHub security advisories for OpenClaw, delivering high-confidence close/keep decisions, exact tag/commit verification, trust-model checks, and a ready-to-post final reply.

Core Features & Use Cases

  • Close/keep decision criteria with explicit rules for advisories
  • Exact verification steps using git tags, npm state, and code inspection
  • Trust-model checks and optional hardening notes
  • A maintainer-ready reply and a clipboard-ready summary for posting

Quick Start

Initiate triage for a new GHSA advisory to generate a ready-to-post maintainer reply and a copy-ready summary.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage GitHub security advisories for close or keep decisions?▼

Triage GitHub security advisories by applying explicit decision criteria, exact git tag and commit verification, npm state checks, and trust-model reviews to produce high-confidence close or keep outcomes with a maintainer-ready reply.

What verification steps are required for GHSA reports during security reviews?▼

GHSA report verification requires exact git tag checks, npm view state checks, and code inspection to validate the advisory's applicability before generating a final close or keep decision.

How do I generate a maintainer reply for a SECURITY.md advisory?▼

Generate a maintainer reply for SECURITY.md advisories by completing the structured triage workflow, which outputs a clipboard-ready summary and final response for direct posting.

Does security triage require trust-model checks before closing an advisory?▼

Yes, trust-model checks are required during security triage to validate the advisory source and context, ensuring high-confidence close or keep decisions before finalizing the maintainer reply.

Can I add hardening notes when triaging GitHub security advisories?▼

Yes, optional hardening notes can be added during the advisory triage process, supplementing the close or keep decision and maintainer-ready reply with additional security context.

What is the best way to automate GHSA triage for OpenClaw repositories?▼

Automate GHSA triage for OpenClaw by applying a structured review workflow that enforces exact tag and commit verification, npm state checks, and trust-model validation to deliver high-confidence decisions.