What problem does it solve?
This skill eliminates inconsistent and high-risk manual review of Brikko Studio security advisories, GHSA reports, and draft security issues, ensuring all triage decisions align with the project's documented trust model, shipped release state, and security scope to avoid over-closing valid vulnerabilities or shipping unnecessary regressions.
Core Features & Use Cases
- Structured Decision Workflow: Follows a strict close bar and review method to evaluate advisories against scope, shipped behavior, and exploit path validity.
- Evidence-Backed Output: Generates maintainer-ready, precise comments for GitHub Security Advisories with exact code references, shipped tag facts, and optional hardening notes.
- Use Case: A Brikko maintainer reviewing a new GHSA for a potential local state access issue can use this skill to confirm the issue is out of scope per SECURITY.md, verify it does not affect the latest shipped release, and draft a compliant comment for the advisory thread.
Quick Start
Use the security-triage skill to review the open Brikko Studio GHSA and draft a maintainer-ready triage comment with supporting evidence.