security-triage

Triage GitHub security advisories and generate ready-to-post replies.

1.0k|59|Updated Mar 20, 2026
One-click install
npx skills add https://github.com/SafeAI-Lab-X/ClawKeeper --skill security-triage-safeai-lab-x
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/SafeAI-Lab-X/ClawKeeper/tree/main/legacy/clawkeeper-watcher/.agents/skills/security-triage
Command: npx skills add https://github.com/SafeAI-Lab-X/ClawKeeper --skill security-triage-safeai-lab-x

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage GitHub security advisories for OpenClaw with high-confidence close/keep decisions, exact tag and commit verification, trust-model checks, optional hardening notes, and a final reply ready to post and copy to clipboard.

Core Features & Use Cases

  • High-confidence triage decisions (close/keep) based on advisory content and shipped state.
  • Exact verification of affected tags and commits to ensure correct remediation mapping.
  • Trust-model checks and optional hardening notes to guide maintainers.

Quick Start

Review a new GitHub Security Advisory within this skill to generate a ready-to-post triage response.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage GitHub security advisories to decide whether to close or keep them?

Triage GitHub security advisories by verifying affected tags and commits, applying trust-model checks, and evaluating advisory content against the shipped state to produce high-confidence close or keep decisions.

Can I automatically generate a ready-to-post reply for a GitHub security advisory?

Yes, you can generate a formatted reply suitable for clipboard posting after triaging a GitHub security advisory, which includes the close/keep decision, verification results, and optional hardening notes.

What is a trust-model check when verifying GitHub security advisory reports?

A trust-model check verifies the integrity and origin of affected tags and commits in GitHub security advisories, ensuring that correct remediation mapping is applied before making a close or keep decision.

Does this advisory triage process work with GHSA reports and draft security advisories?

Yes, this advisory triage process works with GHSA reports, draft advisories requiring verification, and OpenClaw-related advisories to generate high-confidence decisions and ready-to-post replies.

How do I verify affected tags and commits during a GitHub security advisory triage?

Verify affected tags and commits by mapping the advisory content to the actual shipped state of the repository, ensuring exact remediation mapping and validating the results through trust-model checks.

What is the best way to add hardening notes to a GitHub security advisory triage response?

The best way to add hardening notes is to include them as optional guidance for maintainers within the final formatted triage reply, generated after completing the close or keep decision and commit verification.