security-triage

Triage OpenClaw security advisories and GHSA reports for release readiness.

5|Updated Mar 17, 2026
One-click install
npx skills add https://github.com/p-sree-sai-pavan/P.A.R.K.E.R --skill security-triage-p-sree-sai-pavan
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/p-sree-sai-pavan/P.A.R.K.E.R/tree/main/gateway/.agents/skills/security-triage
Command: npx skills add https://github.com/p-sree-sai-pavan/P.A.R.K.E.R --skill security-triage-p-sree-sai-pavan

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage OpenClaw security advisories, drafts, and GHSA reports with shipped-tag and trust-model proof.

Core Features & Use Cases

  • Systematizes advisory reviews for scope, trust-model alignment, and release readiness.
  • Validates evidence by following required reads and prescribed checks to ensure accurate triage decisions.
  • Reduces time-to-response by standardizing maintainer workflows and decision criteria.

Quick Start

Authenticate and load an advisory into the triage workflow, then verify the shipped-tag and trust-model alignment.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage OpenClaw security advisories for release readiness?

Triage OpenClaw security advisories by validating the shipped-tag state, reviewing SECURITY.md, fetching the GHSA body via API, and assessing trust-model alignment to draft actionable responses.

What is trust-model alignment when reviewing GHSA reports?

Trust-model alignment validates GHSA reports against project security requirements by verifying shipped-tag state and SECURITY.md to ensure accurate advisory triage and response.

How do I validate a GHSA report body via API for advisory triage?

Validate a GHSA report body by fetching advisory details via API, comparing content against SECURITY.md requirements, and verifying shipped tag state to ensure accurate triage outcomes.

Does the triage workflow enforce specific validation steps for OpenClaw advisories?

The triage workflow enforces validation steps including reviewing SECURITY.md, fetching the GHSA body via API, and verifying shipped tag state to standardize maintainer decisions and reduce response time.

Can I use this triage process for OpenClaw advisory drafts?

You can triage OpenClaw advisory drafts by loading them into the workflow, verifying shipped-tag state and trust-model alignment, and generating maintainer-ready responses based on prescribed validation checks.

What limitations exist when assessing advisories for trust-model alignment?

Assessing trust-model alignment requires strict validation of shipped-tag state and SECURITY.md; without these prescribed checks, the maintainer response may lack sufficient release readiness proof.