security-triage

Triage OpenClaw security advisories and GHSA reports with deterministic close/keep/open checks.

Updated Dec 6, 2016
One-click install
npx skills add https://github.com/majunbao/learn --skill security-triage-majunbao
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/majunbao/learn/tree/main/openclaw_tags/openclaw-2026.4.24/.agents/skills/security-triage
Command: npx skills add https://github.com/majunbao/learn --skill security-triage-majunbao

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides a structured, repeatable process for triaging OpenClaw security advisories, drafts, and GHSA reports, ensuring consistent decision-making and risk assessment.

Core Features & Use Cases

  • Deterministic review workflow: applies a predefined set of checks to decide between close, keep open, or keep open but narrow.
  • Trust-model alignment: cross-checks advisory status against SECURITY.md and shipped-state indicators.
  • Collaborative triage: enables uniform decision criteria across multiple advisories and releases.

Quick Start

Review an advisory following the mandated steps and use the shipped-state verification checks to evaluate its status.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage GitHub security advisories for multiple releases?

Triage GitHub security advisories by applying a deterministic review workflow that enforces predefined checks to close, keep open, or narrow each advisory across multiple releases. It aligns advisory status with SECURITY.md and shipped-state indicators for consistent risk assessment.

What is a deterministic security triage process?

A deterministic security triage process applies a predefined set of checks to advisories, drafts, and GHSA reports to enforce consistent decisions to close, keep open, or keep open but narrow.

How does a trust model work for security advisories?

A trust model for security advisories cross-checks advisory status against SECURITY.md and shipped-state verification indicators to validate risk and ensure accurate maintainer review decisions.

Do I need a SECURITY.md file to review GHSA reports?

Yes, reviewing GHSA reports requires access to SECURITY.md and shipped-state verification checks to evaluate advisory status and align decisions with the established trust model.

When should I keep a security advisory open but narrow?

Keep a security advisory open but narrow when predefined triage checks and shipped-state verification indicate the advisory is valid but its scope needs restriction based on the actual shipped state.