security-review-owasp-vulnerability-disclosure

Identify vulnerability disclosure control gaps in code, configuration, and workflows.

Updated Mar 26, 2026
One-click install
npx skills add https://github.com/sjinks/ai-owasp-skillset --skill security-review-owasp-vulnerability-disclosure
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review-owasp-vulnerability-disclosure
Source: https://github.com/sjinks/ai-owasp-skillset/tree/main/.github/skills/security-review-owasp-vulnerability-disclosure
Command: npx skills add https://github.com/sjinks/ai-owasp-skillset --skill security-review-owasp-vulnerability-disclosure

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps reviewers find missing analysis, weak escalation paths, and operational blind spots in vulnerability disclosure handling before they become production risks.

Core Features & Use Cases

  • Coverage Review: Checks whether the relevant assets, trust boundaries, and abuse paths are explicitly identified and assessed.
  • Detection and Response Review: Evaluates logging, alerting, evidence preservation, escalation, and incident response quality for disclosure scenarios.
  • Operational Governance Review: Verifies that findings lead to enforceable policy, automation, tests, or rollout controls instead of one-off documentation.
  • Use Case: Use it when reviewing a security program, incident workflow, or codebase to confirm that vulnerable conditions will be discovered, triaged, and handled consistently.

Quick Start

Ask the skill to review the target repository or process for vulnerability disclosure gaps and provide confirmed findings, review gaps, and passed checks.

Frequently Asked Questions about security-review-owasp-vulnerability-disclosure

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review my codebase for vulnerability disclosure control gaps?

Vulnerability disclosure handling covers identifying assets and trust boundaries, evaluating logging and alerting, preserving evidence, and ensuring escalation paths and incident response procedures consistently triage and handle exploit reports.

How do I evaluate incident response procedures for exploit reporting?

You can review operational workflows for vulnerability disclosure by asking the skill to analyze the target repository or process, which then provides confirmed findings, review gaps, and passed checks based on evidence.

What is an OWASP-aligned vulnerability disclosure review?

An OWASP-aligned vulnerability disclosure review identifies missing analysis and operational blind spots in disclosure handling, applying OWASP recommendations for detection, response, and operational follow-through to prevent production risks before attackers exploit them.

Does this vulnerability disclosure review check operational governance and escalation paths?

Yes, this vulnerability disclosure review verifies operational governance by checking that findings lead to enforceable policy, automation, tests, or rollout controls, and thoroughly evaluates escalation paths for disclosure scenarios.

What are the limitations of automated security reviews for disclosure handling?

Automated security reviews for disclosure handling require evidence-based findings and separate confirmed weaknesses from review gaps, meaning they rely on explicit code, configuration, and workflow documentation rather than inferring missing operational context.