findings-tracker

Manage security finding lifecycles with risk scores and SLA enforcement.

3|3|Updated Mar 8, 2026
One-click install
npx skills add https://github.com/jaskaranhundal/usap-skills --skill findings-tracker
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: findings-tracker
Source: https://github.com/jaskaranhundal/usap-skills/tree/main/governance/findings-tracker
Command: npx skills add https://github.com/jaskaranhundal/usap-skills --skill findings-tracker

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides an authoritative registry for all security findings, ensuring that no finding is lost and that each has a clear owner, risk score, and remediation deadline, ultimately enforcing SLA compliance.

Core Features & Use Cases

  • Centralized Registry: Manages the lifecycle of security findings from all sources (vulnerabilities, alerts, pentests, audits).
  • SLA Enforcement: Tracks remediation deadlines and triggers escalations for overdue findings.
  • Risk Scoring: Calculates composite risk scores based on CVSS, exploitability, business impact, and aging.
  • Use Case: Automatically ingest a critical vulnerability from a scan, assign it a high risk score, set a 24-hour remediation SLA, and notify the owner and their manager if it approaches the deadline.

Quick Start

Use the findings-tracker skill to update the status of finding 'finding-123' to 'in_progress'.

Frequently Asked Questions about findings-tracker

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I track security findings to closure across multiple sources?

Track security findings to closure by managing the full remediation lifecycle from a centralized registry, ensuring each vulnerability, IAM anomaly, or audit gap has a clear owner and deadline. This prevents lost findings and enforces SLA compliance across the enterprise.

How does SLA tracking work for vulnerability remediation?

SLA tracking enforces remediation deadlines by monitoring aging findings and triggering escalation notifications to owners and managers when vulnerabilities approach their deadline. This ensures critical exposures are remediated within strict timeframes.

Can I automatically close false positive security findings?

Automated false positive closure is supported directly within the findings lifecycle management process. The system can ingest findings from scans, pentests, and audits, allowing you to automatically close identified false positives to maintain an accurate risk registry.

How is risk assessment calculated for security findings?

Risk assessment calculates a composite risk score for security findings using CVSS metrics, exploitability data, business impact, and finding aging. This scoring model prioritizes remediation efforts based on the actual threat context of each vulnerability.

Does this support compliance gap tracking for enterprise audits?

Compliance gap tracking is fully supported alongside vulnerabilities, pentest findings, and secret exposures. The system provides an authoritative registry that assigns risk scores and remediation deadlines to audit findings to maintain enterprise SLA compliance.

What is the best way to manage IAM anomalies and secret exposures?

Manage IAM anomalies and secret exposures by ingesting them into a centralized security findings registry. The tracker assigns each anomaly a risk score and remediation SLA, automatically escalating overdue items to the respective owners for closure.