security-triage

Triages GitHub security advisories for OpenClaw with git tag and npm state verification.

Updated Jan 31, 2026
One-click install
npx skills add https://github.com/zyj18860969891-byte/openclaw-railway --skill security-triage-zyj18860969891-byte
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-triage
Source: https://github.com/zyj18860969891-byte/openclaw-railway/tree/main/.agents/skills/security-triage
Command: npx skills add https://github.com/zyj18860969891-byte/openclaw-railway --skill security-triage-zyj18860969891-byte

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage GitHub security advisories for OpenClaw, delivering high-confidence close/keep decisions, exact tag/commit verification, trust-model checks, and a ready-to-post final reply.

Core Features & Use Cases

  • Close/keep decision criteria with explicit rules for advisories
  • Exact verification steps using git tags, npm state, and code inspection
  • Trust-model checks and optional hardening notes
  • A maintainer-ready reply and a clipboard-ready summary for posting

Quick Start

Initiate triage for a new GHSA advisory to generate a ready-to-post maintainer reply and a copy-ready summary.

Frequently Asked Questions about security-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage GitHub security advisories for close or keep decisions?

Triage GitHub security advisories by applying explicit decision criteria, exact git tag and commit verification, npm state checks, and trust-model reviews to produce high-confidence close or keep outcomes with a maintainer-ready reply.

What verification steps are required for GHSA reports during security reviews?

GHSA report verification requires exact git tag checks, npm view state checks, and code inspection to validate the advisory's applicability before generating a final close or keep decision.

How do I generate a maintainer reply for a SECURITY.md advisory?

Generate a maintainer reply for SECURITY.md advisories by completing the structured triage workflow, which outputs a clipboard-ready summary and final response for direct posting.

Does security triage require trust-model checks before closing an advisory?

Yes, trust-model checks are required during security triage to validate the advisory source and context, ensuring high-confidence close or keep decisions before finalizing the maintainer reply.

Can I add hardening notes when triaging GitHub security advisories?

Yes, optional hardening notes can be added during the advisory triage process, supplementing the close or keep decision and maintainer-ready reply with additional security context.

What is the best way to automate GHSA triage for OpenClaw repositories?

Automate GHSA triage for OpenClaw by applying a structured review workflow that enforces exact tag and commit verification, npm state checks, and trust-model validation to deliver high-confidence decisions.