security-triage

Triage OpenClaw security advisories with shipped-tag and trust-model proof.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/rigeoben/fairy --skill security-triage-rigeoben
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/rigeoben/fairy/tree/main/.agents/skills/security-triage
Command: npx skills add https://github.com/rigeoben/fairy --skill security-triage-rigeoben

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage OpenClaw security advisories, drafts, and GHSA reports with shipped-tag and trust-model proof.

Core Features & Use Cases

  • Structured triage framework guiding maintainers to classify advisories as close/keep open/keep open but narrow.
  • Step-by-step checks including required reads, evidence gathering, and reference verification to ensure accurate state and communication.
  • Generates a maintainer-ready response with exact references and optional hardening notes while preventing escalation beyond documented scope.

Quick Start

Review a GHSA advisory and draft a maintainer-ready closure comment.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage GHSA security advisories with trust-model validation?

Triage GHSA security advisories by applying a structured framework that validates shipped-state tags, checks the trust model, and verifies references to determine advisory status, close reasons, and required hardening actions.

What is the best way to draft a maintainer-ready response for a security advisory?

Draft a maintainer-ready response by executing reproducible triage steps that generate citeable references, include optional hardening notes, and prevent scope escalation beyond documented advisory evidence.

How does the shipped-tag validation process work for OpenClaw advisories?

Shipped-tag validation works by enforcing step-by-step evidence gathering and reference verification checks, ensuring maintainers accurately classify advisories as close, keep open, or keep open but narrow.

Can I use security triage to classify draft advisories as close or keep open?

Yes, security triage classifies draft advisories as close, keep open, or keep open but narrow by guiding maintainers through a structured framework of required reads, evidence gathering, and reference verification.

When should I not use an automated advisory triage process?

Avoid automated advisory triage when lacking required reads, evidence, or reference verification data, as the process enforces trust-model checks and prevents scope escalation beyond documented advisory evidence.