security-triage

Automate triage of security advisories and GHSA reports against trust models.

4|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/Agent-Pattern-Labs/sparse-kernel --skill security-triage-agent-pattern-labs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/Agent-Pattern-Labs/sparse-kernel/tree/main/.agents/skills/security-triage
Command: npx skills add https://github.com/Agent-Pattern-Labs/sparse-kernel --skill security-triage-agent-pattern-labs

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This Skill simplifies the process of reviewing and triaging security advisories, drafts, and GHSA reports, ensuring maintainers can make informed decisions quickly and accurately.

Core Features & Use Cases

  • Security Advisory Triage: Automates the review of security advisories, drafts, and GHSA reports.
  • Shipped-Tag and Trust-Model Proof: Validates advisories against shipped behavior and trust models.
  • Auditability: Provides detailed logs for tracking and auditing triage decisions.

Quick Start

Run the security-triage skill on the latest security advisory to determine its status.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage GHSA reports and security advisories automatically?

Security advisory triage validates reports against shipped behavior and trust models, automating the review of drafts and GHSA reports to help maintainers make informed decisions quickly and accurately.

What is the best way to validate security advisories against shipped software behavior?

Validating security advisories against shipped behavior requires confirming reported vulnerabilities match actual project releases, needing repository access and security practice knowledge to maintain accurate security posture.

Do I need access to my project repository to triage security advisories?

Yes, repository access is required to validate security advisories against shipped behavior, alongside knowledge of security practices to effectively automate the triage of GHSA reports and maintain security posture.

How does security triage improve auditability for software projects?

Security triage provides detailed logs for tracking and auditing triage decisions, ensuring the validation of security advisories and GHSA reports is fully documented to maintain auditability in software projects.

Can I use this security triage process for any software project?

This security triage process suits maintaining security posture in software projects, provided you have security practice knowledge and repository access to validate shipped behavior and automate GHSA report reviews.

What are the limitations of automating security advisory triage?

Automating security advisory triage requires security practice knowledge and repository access, meaning it cannot validate advisories without verifying shipped behavior and trust models of the specific software project.