security-triage

Triage GitHub security advisories with verification steps and close or keep decisions.

30|1|Updated Apr 15, 2026
One-click install
npx skills add https://github.com/qianleigood/crawclaw --skill security-triage-qianleigood
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/qianleigood/crawclaw/tree/main/skills-optional/security-triage
Command: npx skills add https://github.com/qianleigood/crawclaw --skill security-triage-qianleigood

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill helps security teams triage GitHub security advisories (GHSA) for CrawClaw, delivering clear close/keep decisions, exact tag/commit verification, and templates ready to post.

Core Features & Use Cases

  • Structured triage workflow for each advisory, including trust-model checks and evidence-driven decisions.
  • Exact verification steps for shipped state (tags, releases, and affected components) and reproducible audit trails.
  • Maintainer-ready responses, optional hardening notes, and concise post-ready summaries.

Quick Start

Review each advisory using the defined checks and issue a final triage decision.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage GitHub security advisories to determine if they should be closed or kept open?

To triage GitHub security advisories, you apply structured verification steps to evaluate the trust-model and shipped state, yielding a close, keep open, or narrow decision with reproducible audit trails.

What is the best way to verify if a GHSA report actually affects my shipped release tags?

The best way to verify if a GHSA report affects your shipped releases is to perform exact tag and commit verification against affected components, producing evidence-driven decisions and optional hardening notes.

How does advisory triage handle trust-model assessment for security vulnerabilities?

Advisory triage handles trust-model assessment by applying rigorous verification checks to advisories or drafts, ensuring precise handling and reproducible audits before issuing a final maintainer-ready response.

Can I use automated security triage for drafts and GHSA reports across development workflows?

Yes, you can use automated security triage for drafts and GHSA reports across development workflows to apply trust-model checks and generate concise post-ready summaries for maintainer action.

What steps are needed to generate maintainer-ready responses for GitHub security advisories?

Generating maintainer-ready responses requires reviewing each advisory using defined checks for shipped state and trust-model, which produces exact verification evidence and optional hardening notes for posting.