deal-with-security-advisory

Coordinate GitHub security advisory remediation with private forks and CVE requests.

3|Updated Apr 11, 2026
One-click install
npx skills add https://github.com/googlarz/stapler --skill deal-with-security-advisory-googlarz
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: deal-with-security-advisory
Source: https://github.com/googlarz/stapler/tree/main/.agents/skills/deal-with-security-advisory
Command: npx skills add https://github.com/googlarz/stapler --skill deal-with-security-advisory-googlarz

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Confidentially manage and coordinate GitHub Security Advisory responses, including private fork development, cross-team communication, CVE requests, and timely publication, while preserving disclosure controls.

Core Features & Use Cases

  • Acknowledge advisory reports and triage details with the reporter.
  • Create and manage a temporary private fork for patch development, review, and testing.
  • Coordinate fixes across code, CI, and release pipelines, then publish advisory updates and CVE requests.
  • Reconcile advisory notes, patches, and sensitive timelines with audit-ready records.

Quick Start

Acknowledge the advisory, create a private fork for patch development, and begin the fix workflow immediately.

Frequently Asked Questions about deal-with-security-advisory

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I manage a GitHub security advisory response with confidential patching?

GitHub security advisory coordination involves acknowledging the report, creating a temporary private fork for patch development, and managing CVE requests while maintaining strict confidentiality and auditability until synchronized publication.

What's the best way to coordinate CVE requests and release timelines for a vulnerability patch?

Coordinating CVE requests and release timelines requires reconciling advisory notes across code, CI, and release pipelines while communicating with the reporter to ensure synchronized publication and audit-ready records.

How does private fork development work for incident response patch management?

Private fork development for incident response patch management creates a temporary confidential workspace to develop, review, and test security fixes before synchronizing the release across branches.

Can I handle multi-step approvals and cross-team communication during a GitHub vulnerability disclosure?

Multi-step approvals and cross-team communication during GitHub vulnerability disclosure are managed by triaging details with the reporter and governing the advisory workflow with strict disclosure controls and audit-ready records.

When do I need end-to-end security advisory coordination for a CVE?

End-to-end security advisory coordination is needed when handling security incidents reported via GitHub Security Advisory that require confidential patching workflows, precise advisory detail handling, and release coordination across branches.

What are the limitations of using GitHub Security Advisory workflows for incident response?

GitHub Security Advisory workflows require strict confidentiality and governance steps, meaning incident response coordination must carefully handle private fork management and multi-step approvals to avoid premature disclosure before synchronized publication.