security-triage

Triage OpenClaw security advisories and GHSA reports with structured checks.

18|1|Updated Jun 12, 2026
One-click install
npx skills add https://github.com/vignesh2027/Vilvona-AI --skill security-triage-vignesh2027
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/vignesh2027/Vilvona-AI/tree/main/.agents/skills/security-triage
Command: npx skills add https://github.com/vignesh2027/Vilvona-AI --skill security-triage-vignesh2027

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a structured approach to reviewing and triaging security advisories, drafts, and GHSA reports, ensuring high-confidence maintainers' decisions without closing real issues or shipping unnecessary regressions.

Core Features & Use Cases

  • Advisory Triage: Analyze OpenClaw security advisories, drafts, and GHSA reports.
  • Proof Verification: Assess shipped-tag and trust-model evidence.
  • Review Method: Utilize a defined set of checks to decide on closing or keeping open advisories.
  • Response Format: Prepare clear, maintainable comments for maintainers.
  • Public Wording Hygiene: Maintain professional and accurate communication.
  • Discussion Mode: Facilitate effective communication with other maintainers.
  • Clipboard Step: Streamline response copying process.
  • Useful Commands: Provide a list of commands for accessing information.

Quick Start

Review the security advisory at 'https://github.com/openclaw/openclaw/security-advisories/<GHSA>' and provide a decision based on the guidelines.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage security advisories to avoid closing real issues or shipping regressions?

Security advisory triage requires assessing shipped behavior, exploit paths, and trust models to make high-confidence decisions. A structured review method evaluates proof evidence and trust-model data to prevent closing valid issues or introducing unnecessary regressions.

What is the process for reviewing GHSA reports and security drafts?

Reviewing GHSA reports involves analyzing advisory drafts using defined checks to assess shipped-tag and trust-model evidence. This structured approach ensures accurate issue tracking and prepares clear, maintainable comments for maintainers.

How do I verify proof of exploitation when triaging security reports?

Proof verification during security triage involves assessing shipped-tag evidence and evaluating the trust model within the advisory. This validates the exploit path and shipped behavior to determine if the report represents a genuine vulnerability.

Can I automate security advisory triage for GitHub security advisories?

Automating security advisory triage involves using scripts to apply a defined set of review checks to GHSA reports. This streamlines the assessment of exploit paths and trust models to produce consistent maintainer decisions and comments.

What's the best way to communicate triage decisions to other maintainers?

Communicating triage decisions requires preparing clear, maintainable comments and maintaining professional public wording hygiene. A discussion mode facilitates effective communication with other maintainers for collaborative issue tracking.