clawtributor

Report security incidents to GitHub Issues via an opt-in template.

1.1k|114|Updated Feb 5, 2026
One-click install
npx skills add https://github.com/prompt-security/clawsec --skill clawtributor
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: clawtributor
Source: https://github.com/prompt-security/clawsec/tree/main/skills/clawtributor
Command: npx skills add https://github.com/prompt-security/clawsec --skill clawtributor

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Community incident reporting for AI agents to share threats, vulnerabilities, and attack patterns in a safe, opt-in manner.

Core Features & Use Cases

  • Opt-in Reporting: All submissions require explicit user approval.
  • GitHub Issues: Reports are submitted via the Security Incident Report template as GitHub Issues.
  • Auto-Publishing: Advisories are automatically published (CLAW-YYYY-NNNN) after approval.
  • Privacy & Safety: Clear guidelines to avoid sharing sensitive information and to protect users.

Quick Start

Install Clawtributor by following the deployment steps and saving the SKILL.md from the latest release, then run the installation workflow.

Frequently Asked Questions about clawtributor

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I report security incidents to a community repository using AI agents?

Security incident reporting for community threats uses structured, opt-in reports submitted to GitHub Issues. This enforces safe sharing of vulnerabilities and attack patterns by requiring explicit user approval before any advisory publication.

How do I automate security advisory publishing after reporting a vulnerability?

Security advisory publishing is automated by generating advisories with a CLAW-YYYY-NNNN identifier immediately after explicit user approval is granted for the submitted GitHub Issue report.

Do I need explicit user approval for AI agents to submit security incident reports?

Yes, explicit user approval is required for all security incident report submissions. This opt-in reporting mechanism ensures users maintain control over what threat information AI agents share with the community.

How are privacy and data safety enforced during community security reporting?

Privacy and safety during community security reporting are enforced through clear guidelines that prevent sharing sensitive information. The process also uses checksums and artifact checks to maintain report integrity.

What is the best way to share attack patterns and vulnerabilities without exposing sensitive data?

The best way to share attack patterns safely is using structured, opt-in community incident reporting. This method applies checksums, artifact checks, and privacy guidelines to prevent sensitive data exposure while publishing advisories.