What problem does it solve?
This Skill helps you decide whether a GitHub security advisory for Enclawed should be closed, kept open, or narrowed, while reducing the risk of over-closing real issues or missing shipped vulnerabilities.
Core Features & Use Cases
- Trust-model review: Checks whether the reported behavior is truly outside the documented security boundary or only affects trusted local, host, or operator state.
- Shipped-state verification: Confirms whether the issue is present in released tags or npm versions, and whether a fix landed before the affected release.
- Maintainer-ready response drafting: Produces a firm, specific reply with exact code references, release facts, and optional functionality-preserving hardening notes.
- Use case: Use it when reviewing a GHSA, a draft advisory, or a security issue that may be a duplicate, invalid, out of scope, or fixed only on main.
Quick Start
Ask the Skill to review the advisory, verify the affected code paths and shipped releases, and draft a maintainer-ready close, keep-open, or keep-open-but-narrow response.