security-vulnerability-management

Prioritize and drive vulnerabilities from SAST/DAST scans to closure.

7|Updated Feb 14, 2026
One-click install
npx skills add https://github.com/KentoShimizu/sw-agent-skills --skill security-vulnerability-management-kentoshimizu
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: security-vulnerability-management
Source: https://github.com/KentoShimizu/sw-agent-skills/tree/main/skills/security-vulnerability-management
Command: npx skills add https://github.com/KentoShimizu/sw-agent-skills --skill security-vulnerability-management-kentoshimizu

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes assets (resource) components.

What problem does it solve?

Automates the evidence-based lifecycle for vulnerability handling, ensuring consistent intake, triage, remediation planning, and verification to drive issues to closure.

Core Features & Use Cases

  • Vulnerability intake normalization and severity classification for consistent triage.
  • Remediation planning with owner assignment, due dates, and escalation paths.
  • Fix verification, closure evidence, and SLA/backlog metrics to monitor program health.
  • Use Case: When scans from SAST/DAST, bug bounty reports, or manual reviews produce items, this skill ranks by impact, assigns owners, and sequences fixes while documenting traceability in the vulnerability-triage template.

Quick Start

Run the vulnerability lifecycle workflow to intake, triage, remediate, and verify fixes from scans and reports.

Frequently Asked Questions about security-vulnerability-management

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I manage vulnerability triage from SAST and DAST scans to closure?▼

Vulnerability triage is managed by normalizing scan intake, assigning severity and owners, planning remediation with due dates, and enforcing evidence-based fix verification to drive issues to closure.

What is the best way to prioritize bug bounty reports for remediation?▼

Prioritize bug bounty reports by ranking impact during intake normalization, classifying severity, and sequencing fixes using an established escalation path and standardized vulnerability-triage template.

How does vulnerability lifecycle management handle fix verification and SLA tracking?▼

Vulnerability lifecycle management handles fix verification by requiring closure evidence and monitoring program health through SLA and backlog metrics to ensure remediation completeness.

Can I use this workflow for manual security review findings as well as automated scans?▼

Yes, you can use this workflow for manual security review findings alongside SAST/DAST scans and bug bounty programs, ensuring consistent intake, severity classification, and traceable remediation.

What does evidence-based vulnerability remediation require for backlog items?▼

Evidence-based vulnerability remediation requires assigning owners, setting due dates, documenting traceability in the triage template, and capturing standardized closure evidence before clearing backlog items.