deal-with-security-advisory

Coordinate private fixes, CVE requests, and publication for GitHub security advisories.

Updated Mar 30, 2026
One-click install
npx skills add https://github.com/thetangstr/agentdash --skill deal-with-security-advisory-thetangstr
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: deal-with-security-advisory
Source: https://github.com/thetangstr/agentdash/tree/main/.agents/skills/deal-with-security-advisory
Command: npx skills add https://github.com/thetangstr/agentdash --skill deal-with-security-advisory-thetangstr

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) and assets (resource) components.

What problem does it solve?

This Skill streamlines the process of managing and responding to GitHub Security Advisories, ensuring rapid, confidential, and coordinated vulnerability handling.

Core Features & Use Cases

  • Vulnerability response coordination: Guides teams through advisory acknowledgment, private fix development, and publication.
  • Confidential workflow management: Ensures all development and communication remain private until public disclosure.
  • Use Case: A security team receives a vulnerability report and uses this Skill to coordinate an internal fix, develop patch, and publish the advisory securely.

Quick Start

Use the deal-with-security-advisory skill to guide your team through handling a GitHub Security Advisory, from acknowledgment to public disclosure.

Frequently Asked Questions about deal-with-security-advisory

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I coordinate a security response for a GitHub security advisory?

To coordinate a security response, you guide your team through advisory acknowledgment, private fork development, and coordinated publication. This ensures confidential communication and timely vulnerability remediation from initial report to public disclosure.

What is the process for handling a confidential vulnerability report on GitHub?

Handling a confidential vulnerability report involves managing private fix development and internal notifications while keeping all communication secure. The process ensures proper internal and external coordination until the advisory is ready for publication.

How do I manage private fork development when fixing a security vulnerability?

Managing private fork development requires coordinating patch creation within a confidential workflow. You develop the fix securely in a private fork, ensuring all development remains hidden until the coordinated public disclosure of the advisory.

Can I request a CVE through the GitHub security advisory workflow?

Yes, you can request a CVE through the GitHub security advisory workflow. The process manages CVE requests alongside confidential communication and private fix development to ensure proper vulnerability documentation and coordinated publication.

What is the best way to ensure timely vulnerability remediation for GitHub repositories?

Timely vulnerability remediation relies on a coordinated response that manages internal and external notifications during each phase. By securing private fork development and publication steps, teams ensure rapid and confidential advisory handling.

When do I need to use a coordinated publication process for security advisories?

A coordinated publication process is needed when resolving GitHub security advisories that require confidential communication and private fixes. It ensures all internal and external notifications are properly managed before the vulnerability details go public.