deal-with-security-advisory

Coordinate confidential GitHub security advisory responses with private forks and synchronized publication.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/Mothership-Foundry/foundry-dashboard --skill deal-with-security-advisory-mothership-foundry
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: deal-with-security-advisory
Source: https://github.com/Mothership-Foundry/foundry-dashboard/tree/main/.agents/skills/deal-with-security-advisory
Command: npx skills add https://github.com/Mothership-Foundry/foundry-dashboard --skill deal-with-security-advisory-mothership-foundry

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Handle security vulnerabilities in a confidential, coordinated manner, ensuring that advisory details remain private until publication and that fixes are developed in isolation from the public repository.

Core Features & Use Cases

  • Private fork-based patch development: create a secure, isolated space to implement fixes without affecting the public codebase.
  • Human coordination on advisory threads: align reporter communication, track progress, and craft communications.
  • CVE requests and synchronized publication: manage CVE assignment and release timing to minimize risk windows.

Quick Start

Initiate a confidential advisory workflow by creating a private fork for the GitHub Security Advisory and begin patch development.

Frequently Asked Questions about deal-with-security-advisory

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I handle a GitHub security advisory response end-to-end?

To handle a GitHub security advisory response, you coordinate confidential patch development in private forks, manage human communication on advisory threads, and synchronize the final publication across release channels to ensure strict secrecy.

How does private fork development work for security patch isolation?

Private fork development for security patches creates an isolated environment from the public codebase, allowing you to implement fixes confidentially without exposing vulnerability details until the coordinated disclosure is ready.

What is the best way to coordinate CVE requests and synchronized publication for vulnerabilities?

The best way to coordinate CVE requests and synchronized publication is to enforce procedural steps and API usage, aligning release timing across channels to minimize risk windows during the vulnerability disclosure process.

Can I manage reporter communication directly on GitHub advisory threads?

Yes, you can manage reporter communication directly on GitHub advisory threads to align stakeholder coordination, track remediation progress, and craft release communications while maintaining strict confidentiality.

When do I need to use a confidential advisory workflow for GitHub vulnerabilities?

You need a confidential advisory workflow for GitHub vulnerabilities when developing fixes in isolation is required, ensuring advisory details remain private and patch development does not affect the public repository.

What are the limitations of using private forks for security advisory patch development?

A limitation of private fork security advisory workflows is the strict procedural requirement to maintain secrecy, requiring precise API usage and synchronized release timing to prevent accidental early disclosure across release channels.