security-review

Parse and classify vulnerability reports with Bugcrowd VRT mapping and remediation steps.

Updated Mar 18, 2023
One-click install
npx skills add https://github.com/acmacalister/dotfiles --skill security-review-acmacalister
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review
Source: https://github.com/acmacalister/dotfiles/tree/main/dot_config/crush/skills/security-review
Command: npx skills add https://github.com/acmacalister/dotfiles --skill security-review-acmacalister

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage and validate incoming vulnerability reports to determine risk, scope, and remediation priorities, reducing time to reply and standardizing responses across teams.

Core Features & Use Cases

  • Structured triage: parse reporter details, affected assets, vulnerability type, and evidence to assign initial severity.
  • VRT mapping & ticketing: classify findings using Bugcrowd VRT and generate Linear tickets with remediation plans.
  • Communication & records: draft professional respondent emails and maintain auditable decision trails.

Quick Start

Submit a vulnerability report to receive structured triage, Bugcrowd VRT mapping, and remediation planning.

Frequently Asked Questions about security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage vulnerability reports from bug bounty platforms?

Triage vulnerability reports by parsing reporter details, affected assets, vulnerability type, and evidence to assign initial severity. The skill processes submissions from bug bounty platforms and internal discoveries to standardize risk assessment and remediation prioritization across teams.

How do I map vulnerability findings to Bugcrowd VRT categories?

Map vulnerability findings to Bugcrowd VRT categories by classifying incoming reports during the triage process. The skill automatically enforces VRT mapping to ensure consistent severity rating and standardized classification across web apps and infrastructure reports.

Can I generate Linear tickets for vulnerability remediation planning?

Generate Linear tickets for vulnerability remediation by processing triaged reports into structured task descriptions. The skill creates tickets with remediation plans after parsing and classifying findings, ensuring structured and auditable outputs for development teams.

What's the best way to draft responsible disclosure emails for security researchers?

Draft responsible disclosure emails by using the triage skill to generate professional respondent messages after assessing vulnerability severity. The skill produces structured communication that maintains auditable decision trails for incident response and bug bounty correspondence.

Does this vulnerability triage approach work for both web apps and infrastructure?

Vulnerability triage works for both web apps and infrastructure by parsing reports across diverse asset types. The skill handles findings from researchers, bug bounty platforms, and internal discoveries, assigning severity and remediation steps regardless of the affected system.

Why do I need structured incident response for incoming security reports?

Structured incident response reduces time to reply and standardizes vulnerability handling across teams. Without it, validating incoming reports to determine risk, scope, and remediation priorities becomes inconsistent, leading to delayed responses and untracked security decisions.