triage-findings

Deduplicate and prioritize vulnerability findings using CVSS, EPSS, and KEV context.

5|3|Updated Apr 10, 2026
One-click install
npx skills add https://github.com/zebbern/termstack --skill triage-findings-zebbern
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: triage-findings
Source: https://github.com/zebbern/termstack/tree/main/.github/skills/triage-findings
Command: npx skills add https://github.com/zebbern/termstack --skill triage-findings-zebbern

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill consolidates scattered vulnerability findings into a unified, prioritized view, helping security teams drive faster remediation decisions.

Core Features & Use Cases

  • Deduplication: remove duplicates across sources to reveal distinct vulnerabilities.
  • Cross-tool correlation: align findings from Burp, Nuclei, and manual input to identify true positives.
  • Prioritization with context: compute priority using CVSS, EPSS, KEV, asset criticality, and business impact.
  • Triage reporting: generate a structured triage report that guides remediation planning.

Quick Start

Input vulnerability findings from scanners and output a prioritized triage report.

Frequently Asked Questions about triage-findings

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prioritize vulnerability findings using CVSS, EPSS, and KEV?▼

Prioritize vulnerability findings by computing priority through a defined matrix that combines CVSS scoring, EPSS integration, and KEV matching alongside asset criticality and business impact context.

What is the best way to deduplicate vulnerability findings from multiple scanners?▼

Deduplicate vulnerability findings from multiple sources by correlating scan results across tools and assets, removing duplicates to reveal distinct vulnerabilities for a consolidated, unified view.

Can I correlate scan results from tools like Burp and Nuclei for vulnerability triage?▼

Yes, you can correlate scan results from Burp, Nuclei, and manual input to identify true positives, aligning findings across tools and assets to produce a comprehensive triage report.

How do I generate a structured triage report for remediation planning?▼

Generate a structured triage report by consolidating scattered vulnerability findings into a unified, prioritized view that guides security teams in driving faster remediation decisions.

Does vulnerability triage require asset criticality and business impact context?▼

Yes, effective vulnerability triage computes priority using a defined matrix that incorporates asset criticality and business impact alongside CVSS, EPSS, and KEV context.

What limitations exist when correlating manual input with automated scanner findings?▼

The skill correlates manual input with automated scanner findings to identify true positives, but relies on the accuracy of the provided scan results and manual entries to produce a comprehensive triage report.