security-embargo

Create security embargo policies and draft pre-disclosure notices for CNCF projects.

2|Updated Mar 4, 2026
One-click install
npx skills add https://github.com/castrojo/cncf-skills --skill security-embargo
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-embargo
Source: https://github.com/castrojo/cncf-skills/tree/main/skills/security-embargo
Command: npx skills add https://github.com/castrojo/cncf-skills --skill security-embargo

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps CNCF project maintainers establish and manage a formal security embargo policy, ensuring coordinated vulnerability disclosure and protecting downstream distributors.

Core Features & Use Cases

  • Embargo Policy Creation: Guides the creation of a comprehensive embargo policy document.
  • Embargo Notice Drafting: Provides templates for drafting pre-disclosure notices to distributors.
  • Use Case: A project is preparing to release a security patch for a widely used component. This Skill assists in setting up the communication channels, drafting the embargo notice, and ensuring distributors are informed and prepared before the public disclosure.

Quick Start

Use the security-embargo skill to create and maintain the security embargo policy for your project.

Frequently Asked Questions about security-embargo

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create a security embargo policy for coordinated vulnerability disclosure?

To create a security embargo policy, use this Skill to generate a comprehensive document that establishes pre-disclosure coordination agreements and protects downstream distributors before public vulnerability disclosure.

What is a security embargo policy and when do I need one for my project?

A security embargo policy is a formal agreement governing coordinated vulnerability disclosure. You need one when preparing to release a security patch for a widely used component to ensure downstream distributors are informed and prepared.

Can I use this to draft pre-disclosure notices for downstream distributors?

Yes, this Skill provides templates for drafting pre-disclosure embargo notices to distributors, ensuring they receive advance notification and can prepare their systems before public vulnerability disclosure.

What is the best way to manage vulnerability disclosure coordination for CNCF projects?

The best way to manage CNCF vulnerability disclosure coordination is by establishing a formal embargo policy and using draft notice templates to secure communication channels with downstream distributors prior to public disclosure.

Do I need this Skill if my project does not have downstream distributors?

If your project lacks downstream distributors, the formal pre-disclosure coordination and embargo notification templates provided by this Skill are less critical, as coordinated vulnerability disclosure primarily protects distributing partners.