security-triage

Automate triage decisions for GitHub security advisories with verification checks.

1|Updated Apr 28, 2026
One-click install
npx skills add https://github.com/seasonmac/Full-Scene-Agents --skill security-triage-seasonmac
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/seasonmac/Full-Scene-Agents/tree/main/openclaw/.agents/skills/security-triage
Command: npx skills add https://github.com/seasonmac/Full-Scene-Agents --skill security-triage-seasonmac

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage GitHub security advisories, drafts, and GHSA reports to produce high-confidence close or keep decisions, with exact tag and commit verification, trust-model checks, optional hardening notes, and a final reply ready to post and copy to clipboard.

Core Features & Use Cases

  • Evaluates advisories against shipped policy and code paths to ensure decisions align with security posture.
  • Applies to OpenClaw advisories, GHSA reports, and drafts, guiding maintainers to decide when to close, keep open, or keep open but narrow.
  • Generates a copy-ready response suitable for posting or clipboard transfer, including optional hardening notes when beneficial.

Quick Start

Review an advisory and run the triage workflow to generate a final, ready-to-post reply.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate triage decisions for GitHub security advisories?

Automate GitHub security advisory triage by evaluating advisories against shipped policy and code paths to produce high-confidence close or keep outcomes with a ready-to-post reply.

What is security triage for GHSA reports and how does it work?

Security triage for GHSA reports evaluates trust-model checks and exact tag and commit verification to guide maintainers in deciding whether to close, keep open, or narrow an advisory.

Can I use advisory triage workflows for OpenClaw reports and GitHub drafts?

Yes, advisory triage workflows apply to OpenClaw advisories, GHSA reports, and drafts, evaluating code paths to align decisions with your security posture.

How do I generate a ready-to-post reply after triaging a GitHub security advisory?

Generate a ready-to-post reply by running the triage workflow, which verifies exact tags and commits, applies trust-model checks, and includes optional hardening notes for clipboard transfer.

What is the best way to verify shipped code paths when triaging security advisories?

The best way to verify shipped code paths during security triage is applying deterministic, audit-friendly workflow checks that align advisory decisions with your actual security posture.

When should I keep a GitHub security advisory open instead of closing it?

Keep a GitHub security advisory open instead of closing it when trust-model checks or shipped policy evaluations indicate the reported vulnerability still affects active code paths.