security-contacts

Create or update SECURITY_CONTACTS files with verified GitHub handles and role-based emails.

2|Updated Mar 4, 2026
One-click install
npx skills add https://github.com/castrojo/cncf-skills --skill security-contacts
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-contacts
Source: https://github.com/castrojo/cncf-skills/tree/main/skills/security-contacts
Command: npx skills add https://github.com/castrojo/cncf-skills --skill security-contacts

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill ensures that CNCF projects have a clear and up-to-date list of individuals responsible for handling security vulnerability reports, preventing disclosures from going unacknowledged.

Core Features & Use Cases

  • Create or Update SECURITY_CONTACTS: Automatically generates or modifies the SECURITY_CONTACTS file in the repository root.
  • Contact Verification: Verifies GitHub handles and ensures role-based email addresses are used.
  • Use Case: A project is graduating and needs to establish a formal security reporting channel. This Skill helps create the SECURITY_CONTACTS file, listing the designated security team members and their contact information.

Quick Start

Use the security-contacts skill to create or update the SECURITY_CONTACTS file.

Frequently Asked Questions about security-contacts

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create a SECURITY_CONTACTS file for vulnerability reporting?

To create a SECURITY_CONTACTS file for vulnerability reporting, use this skill to automatically generate the file in your repository root, listing designated individuals and their role-based email addresses. It ensures at least two verified GitHub handles are included.

What is the required number of security contacts for a CNCF project disclosure channel?

The required number of security contacts for a CNCF project disclosure channel is at least two. This skill verifies GitHub handles and ensures role-based email addresses are properly listed to prevent vulnerability disclosures from going unacknowledged.

How do I update security contacts to align with a SECURITY.md reporting channel?

To update security contacts to align with a SECURITY.md reporting channel, this skill modifies the existing SECURITY_CONTACTS file, verifying GitHub handles and ensuring role-based email addresses match the current security team members.

Do I need a SECURITY_CONTACTS file for a graduating CNCF project?

Yes, you need a SECURITY_CONTACTS file for a graduating CNCF project to establish a formal security reporting channel. This skill helps you create the file with designated team members and verified contact information.

What's the best way to ensure security contacts have verified GitHub handles?

The best way to ensure security contacts have verified GitHub handles is to use this skill, which checks handles and enforces role-based email addresses during the creation or update of the SECURITY_CONTACTS file.