security-triage

Triage GHSA security advisories using shipped-tag and trust-model proof.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/qkal/superbyte --skill security-triage-qkal
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/qkal/superbyte/tree/main/.agents/skills/security-triage
Command: npx skills add https://github.com/qkal/superbyte --skill security-triage-qkal

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage SuperByte security advisories, drafts, and GHSA reports with shipped-tag and trust-model proof to help maintainers act confidently.

Core Features & Use Cases

  • Close Bar: Enforces precise criteria for closing advisories, avoiding premature closures.
  • Required Reads: Defines steps to verify relevance by reading SECURITY.md, the GHSA body, and inspecting shipped state.
  • Review Method: Guides one-advisory-at-a-time discussion, with a structured workflow and maintainer-ready comments.

Quick Start

Review a new GHSA advisory and decide its disposition using the defined triage workflow.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage GitHub security advisories to decide whether to close or keep them open?

To triage GitHub security advisories, you verify relevance by reading SECURITY.md, inspecting the GHSA body, and checking the shipped state via tags and npm versions to enforce a structured close or keep-open workflow.

What is the required process for reviewing GHSA drafts before closing a security advisory?

The required process for reviewing GHSA drafts involves reading SECURITY.md, checking the GHSA details, and inspecting the current shipped state to meet precise closure criteria and avoid premature advisory closures.

Can I review multiple GHSA reports at once using this structured triage workflow?

No, you should review multiple GHSA reports one advisory at a time. This structured triage workflow guides single-advisory discussions to generate maintainer-ready comments and ensure rigorous hardening considerations.

Does the triage workflow check npm versions and git tags to verify the shipped state of an advisory?

Yes, the triage workflow checks npm versions and shipped tags to verify the current shipped state. This provides trust-model proof required to validate advisory relevance before maintainers act.

What is the close bar criteria for resolving security advisories in maintainer workflows?

The close bar criteria for resolving security advisories requires verifying the GHSA body, SECURITY.md, and current shipped state to prevent premature closures and ensure maintainers act confidently with trust-model proof.