security-triage

Triage GitHub security advisories and verify tags, commits, and trust models.

Updated Apr 24, 2026
One-click install
npx skills add https://github.com/frankhli843/gemmahermes --skill security-triage-frankhli843
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/frankhli843/gemmahermes/tree/main/.agents/skills/security-triage
Command: npx skills add https://github.com/frankhli843/gemmahermes --skill security-triage-frankhli843

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage GitHub security advisories for OpenClaw with high-confidence close/keep decisions, verifying tags and commits and generating maintainer-ready context for quick resolution.

Core Features & Use Cases

  • Rapid assessment of advisories and GHSA reports with clear close/keep recommendations.
  • Exact verification of tags and commits, with trust-model checks against SECURITY.md and related sources.
  • Generate a concise, copy-ready maintainer reply ready to post or share.
  • Use cases include security teams triaging advisories during a release cycle or maintainers validating fixes before publishing.

Quick Start

Run a full triage pass on the latest GHSA advisories to produce a maintainer-ready reply and verification notes.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage GitHub security advisories for OpenClaw?

Triage GitHub security advisories by verifying exact tags and commits, performing trust-model checks against SECURITY.md, and generating a maintainer-ready reply with concise verification notes.

What is the best way to verify GHSA reports before a release cycle?

Verify GHSA reports by running a full triage pass to assess advisories, check trust-models against SECURITY.md, and produce high-confidence close or keep recommendations with copy-ready maintainer replies.

Can I generate a maintainer-ready reply for a GHSA report?

Yes, you can generate a concise, copy-ready maintainer reply suitable for posting or sharing after verifying exact tag and commit information for the GitHub security advisory.

How does the trust-model check work for OpenClaw security advisories?

The trust-model check verifies advisory validity by comparing exact tag and commit information against the rules and sources defined in the project's SECURITY.md file to ensure high-confidence decisions.

Do I need exact commit information to keep or close an OpenClaw advisory?

Yes, exact tag and commit verification is required to produce high-confidence close or keep decisions for OpenClaw advisories, ensuring maintainer replies are backed by precise validation.

Can I use this for validating security fixes before publishing?

Yes, maintainers can use this triage process to validate security fixes before publishing by verifying commits and generating verification reports to ensure safe releases during a cycle.