responsible-disclosure

Automate vulnerability reporting and coordinated disclosure workflows with YAML frontmatter and Python tracking.

3|Updated Nov 18, 2025
One-click install
npx skills add https://github.com/pluginagentmarketplace/custom-plugin-ai-red-teaming --skill responsible-disclosure
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: responsible-disclosure
Source: https://github.com/pluginagentmarketplace/custom-plugin-ai-red-teaming/tree/main/skills/responsible-disclosure
Command: npx skills add https://github.com/pluginagentmarketplace/custom-plugin-ai-red-teaming --skill responsible-disclosure

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill streamlines and enforces responsible vulnerability disclosure workflows, ensuring private vulnerability reports are coordinated and tracked with vendors and timelines.

Core Features & Use Cases

  • Structured disclosures: Standardized frontmatter-driven schema for input, output, and policy references.
  • Lifecycle tracking: Python-based tracker to monitor discovery, acknowledgment, remediation, and disclosure status.
  • Templates & references: Reusable templates for vulnerability reports, timelines, and legal considerations.

Quick Start

To start, use the provided templates and the disclosure-tracker script to initiate a vulnerability report and monitor its progress across the defined timelines.

Frequently Asked Questions about responsible-disclosure

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I coordinate vulnerability disclosure timelines with a vendor?

Coordinate vulnerability disclosure timelines using a Python-based tracker that monitors discovery, acknowledgment, remediation, and disclosure status through a structured YAML schema. It automates lifecycle tracking for security researchers and security teams.

What is responsible vulnerability reporting and how does it work?

Responsible vulnerability reporting is the ethical process of privately disclosing security flaws to vendors. This Skill automates it by providing a standardized frontmatter-driven schema for inputs, outputs, and policy references to ensure coordinated discovery and reporting.

How do I create a structured vulnerability report for an AI system?

Create a structured vulnerability report using ready-made templates tailored for AI systems. The Skill provides a YAML frontmatter-driven schema that standardizes report inputs, outputs, and legal considerations for security teams.

Does this vulnerability disclosure tracker work without external dependencies?

Yes, the vulnerability disclosure tracker works without external dependencies. It relies on internal scripts, references, and assets to manage reporting workflows, meaning no prerequisite environment setup is required to initiate tracking.

What is the best way to track bug bounty remediation status across vendors?

Track bug bounty remediation status using a Python-based disclosure tracker. It enforces responsible disclosure workflows by applying a standardized schema to monitor vendor engagement and coordinate timelines from discovery to final disclosure.

When do I need a formal policy reference for security vulnerability disclosure?

You need a formal policy reference for security vulnerability disclosure when coordinating private reports with vendors. The Skill provides reusable templates and references that address legal considerations and enforce structured reporting workflows across AI systems.