security-triage

Triage OpenClaw security advisories and GHSA reports with shipped-tag proof.

1|Updated Mar 6, 2026
One-click install
npx skills add https://github.com/zhcndoc/openclaw --skill security-triage-zhcndoc
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/zhcndoc/openclaw/tree/main/.agents/skills/security-triage
Command: npx skills add https://github.com/zhcndoc/openclaw --skill security-triage-zhcndoc

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage OpenClaw security advisories, drafts, and GHSA reports with shipped-tag and trust-model proof.

Core Features & Use Cases

  • Provide maintainer-ready triage decisions for advisories, GHSA reports, and drafts.
  • Follow explicit Review Method steps and Required Reads to ensure consistent outcomes.
  • Maintain alignment with SECURITY.md and canonical state verification before closing or keeping issues open.

Quick Start

Run the security-triage workflow on a new advisory to determine the proper maintainer action.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage GitHub security advisories for maintainer workflows?

To triage GitHub security advisories, apply the security-triage workflow to verify canonical states, draft maintainer-ready decisions, and align outcomes with SECURITY.md guidelines and trust-model proofs.

What is a trust-model proof in security advisory review?

A trust-model proof in security advisory review validates the advisory's shipped-tag and canonical state through structured verification steps, ensuring evidence-based conclusions before updating maintainer statuses or closing issues.

How do I draft maintainer-ready decisions for GHSA reports?

Draft maintainer-ready decisions for GHSA reports by following the explicit Review Method steps and Required Reads, which enforce a structured decision process to generate consistent hardening recommendations and status updates.

Does this triage process align with SECURITY.md guidelines for advisory status updates?

Yes, the triage process maintains strict alignment with SECURITY.md guidelines by verifying canonical repository states and applying evidence-based conclusions before closing or keeping security advisories open.

What are the limitations of automated security advisory triage?

Automated security advisory triage requires explicit Required Reads and canonical state verification before closing issues, meaning it cannot bypass the structured decision process or skip evidence-based hardening recommendations without proof.