security-triage

Triage OpenClaw security advisories and GHSA reports with evidence.

7|12|Updated Mar 10, 2026
One-click install
npx skills add https://github.com/borealBytes/my-farm-advisor --skill security-triage-borealbytes
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/borealBytes/my-farm-advisor/tree/main/.agents/skills/security-triage
Command: npx skills add https://github.com/borealBytes/my-farm-advisor --skill security-triage-borealbytes

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage OpenClaw security advisories, drafts, and GHSA reports to deliver clear maintainer decisions with evidence and traceable context.

Core Features & Use Cases

  • Enforces a repeatable triage workflow for each advisory, including trust-model checks, state assessment, and decision-making criteria.
  • Guides maintainers through required reads (SECURITY.md, GHSA body, and code review checks) and produces a concise, publish-ready resolution.
  • Supports drafting maintainer-ready comments and documentation of decisions, with traceable links to inputs and checks.

Quick Start

Start by selecting a GHSA advisory and follow the Required Reads to complete a maintainer-ready triage.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage GitHub security advisories for maintainer decisions?

To triage GitHub security advisories, follow a structured workflow enforcing trust-model checks, state assessment, and required reads like SECURITY.md to produce high-confidence maintainer decisions with traceable evidence.

What is the process for reviewing GHSA reports during vulnerability disclosure intake?

Reviewing GHSA reports during vulnerability disclosure intake involves enforcing required reads, performing code review checks, and assessing the advisory state. This formal review flow produces concise, publish-ready resolutions for maintainers.

Can I use this triage workflow for both draft and shipped OpenClaw security advisories?

Yes, this triage workflow applies across vulnerability disclosures, security advisories, and intake reviews for both shipped and open advisories. It guides maintainers through necessary checks to draft maintainer-ready comments and documentation.

How do I draft maintainer-ready comments and documentation for security advisory resolutions?

Draft maintainer-ready comments and documentation by completing the formal review flow, which includes required reads and trust-model checks. The process ensures decisions are documented with traceable links to inputs and verification checks.

What trust-model checks are required when triaging security advisories?

Trust-model checks during security advisory triage verify the reporter's credibility and advisory state before decision-making. Enforcing these checks alongside required reads like the GHSA body ensures high-confidence resolutions with traceable evidence.