security-triage

Triage GitHub security advisories with close/keep decisions and tag verification.

4|2|Updated Mar 26, 2026
One-click install
npx skills add https://github.com/bitan-del/gods-eye --skill security-triage-bitan-del
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/bitan-del/gods-eye/tree/main/.agents/skills/security-triage
Command: npx skills add https://github.com/bitan-del/gods-eye --skill security-triage-bitan-del

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage GitHub security advisories for Gods Eye with high-confidence close/keep decisions, exact tag and commit verification, trust-model checks, optional hardening notes, and a final reply ready to post and copy to clipboard.

Core Features & Use Cases

  • Structured, repeatable triage decisions aligned with SECURITY.md.
  • Verification of fixed tags, commits, and trust-model criteria, plus export-ready maintainer responses.
  • Use case: when reviewing GHSA advisories or security drafts for Gods Eye.

Quick Start

Run a maintainer-ready triage pass on a GHSA advisory described by the SKILL.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage GitHub security advisories for a maintainer-ready review?

Triaging GitHub security advisories involves verifying fixed tags and commits, applying trust-model checks, and generating a structured close/keep decision with a final reply ready to post.

What is a trust-model check in security advisory triage?

A trust-model check in security triage validates whether an advisory aligns with the project's SECURITY.md criteria, ensuring rigorous verification of canonical sources before making a close or keep decision.

Can I use this triage process for draft security reports and GHSA submissions?

Yes, the triage process applies to reviewing security advisories, drafts, or GHSA reports, producing a maintainer-ready summary with exact tag and commit verification.

How do I verify fixed tags and commits when reviewing security advisories?

Verifying fixed tags and commits requires checking the shipped-state against canonical sources, confirming exact references, and ensuring the advisory meets trust-model alignment per SECURITY.md.

What is the best way to generate an export-ready maintainer response for a GHSA report?

Generating an export-ready maintainer response involves running a structured triage pass that produces a final reply with close/keep decisions, optional hardening notes, and copy-to-clipboard formatting.

Are there limitations when automating close or keep decisions for code review advisories?

Limitations arise when canonical sources lack exact tag or commit references; the triage process requires preciseSECURITY.md trust-model alignment and shipped-state verification to produce high-confidence decisions.