security-triage

Triage GitHub security advisories with tag and commit verification.

2|Updated Mar 15, 2026
One-click install
npx skills add https://github.com/AG064/argentum --skill security-triage-ag064
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/AG064/argentum/tree/main/.agents/skills/security-triage
Command: npx skills add https://github.com/AG064/argentum --skill security-triage-ag064

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage GitHub security advisories for Argentum with high-confidence close/keep decisions, exact tag and commit verification, trust-model checks, optional hardening notes, and a final reply ready to post and copy to clipboard.

Core Features & Use Cases

  • Trust-model guided review of advisories to determine whether to close, keep open, or narrow.
  • Exact verification steps: tag creation date, npm version, affected commits, and tag containment checks.
  • Produce maintainer-ready, postable responses including precise code references and a clipboard-ready message.

Quick Start

Run the triage workflow on a new GitHub advisory to generate a maintainer-ready close/keep decision.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I verify GitHub security advisories for affected commits and tags?

Verify GitHub security advisories by checking tag creation dates, npm versions, affected commits, and tag containment to establish exact state verification for reproducible triage workflows.

What is the best way to triage GHSA reports with a trust model?

Triage GHSA reports using trust-model guided review to evaluate advisory tags and commits, yielding high-confidence decisions to close, keep open, or narrow the reported vulnerability scope.

How do I generate maintainer-ready responses for GitHub security advisories?

Generate maintainer-ready responses by running the triage workflow to produce postable content with precise code references and a copy-to-clipboard message for closing or keeping advisories.

Can I automate GitHub security advisory decisions with exact state verification?

Automate advisory decisions through a reproducible workflow applying trust-model checks and exact verification of tags and commits to confidently close or keep GitHub security advisories.

Does the triage workflow support hardening notes for security advisories?

The triage workflow supports optional hardening notes alongside trust-model checks and exact state verification, providing comprehensive advisory assessment and maintainer-ready posting content.

When do I need exact tag containment checks for GitHub security advisories?

Exact tag containment checks are needed when verifying affected commits and npm versions in GHSA reports to ensure reproducible, high-confidence close or keep decisions for security advisories.