security-triage

Automate GitHub security advisory triage with trust-model and commit verification.

Updated Mar 31, 2026
One-click install
npx skills add https://github.com/nuno7lopes/alisio --skill security-triage-nuno7lopes
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/nuno7lopes/alisio/tree/main/.agents/skills/security-triage
Command: npx skills add https://github.com/nuno7lopes/alisio --skill security-triage-nuno7lopes

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires git, npm, gh, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill streamlines the process of triaging GitHub security advisories for Alisio, providing maintainers with high-confidence decisions to close or keep open issues.

Core Features & Use Cases

  • Advisory Triage: Offers a structured approach to reviewing and deciding on GitHub security advisories.
  • High-Confidence Decisions: Assists in closing or keeping open issues with a high degree of confidence.
  • Code and Commit Verification: Verifies the exact tag and commit that address security issues.
  • Trust-Model Checks: Evaluates the trust model to determine the scope and severity of issues.
  • Optional Hardening Notes: Provides optional hardening notes for further action.
  • Final Reply Preparation: Generates a final reply ready to post, with the proposed response copied to the clipboard.
  • Use Case: Ideal for maintainers and security engineers who need to process a high volume of GitHub security advisories efficiently.

Quick Start

Run the 'security-triage' skill to triage a GitHub security advisory.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage GitHub security advisories automatically?

Triage GitHub security advisories automatically by running this Skill, which evaluates trust-model checks and verifies code to output high-confidence decisions on closing or keeping issues open.

What is advisory triage based on when verifying code and commits?

Advisory triage evaluates trust-model checks and verifies the exact tag and commit addressing security issues to generate high-confidence decisions for closing or keeping open GitHub advisories.

Do I need a local Git repository and GitHub API access to triage security advisories?

Yes, you need local Git repository access and GitHub API connectivity to run advisory triage, verify exact addressing commits, and generate final reply preparations for issue management.

Does the security triage process generate a final reply ready to post on GitHub issues?

Yes, security triage prepares a final reply ready to post on GitHub issues and copies the proposed response to the clipboard, alongside optional hardening notes for further action.

What's the best way to manage a high volume of GitHub security advisories efficiently?

The best way to manage high volumes of GitHub security advisories is automating triage via trust-model checks and code verification, yielding high-confidence close or keep-open decisions.