security-vulnerability-management

Prioritize and drive vulnerabilities from SAST/DAST scans to closure.

7|Updated Feb 14, 2026
One-click install
npx skills add https://github.com/KentoShimizu/sw-agent-skills --skill security-vulnerability-management-kentoshimizu
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-vulnerability-management
Source: https://github.com/KentoShimizu/sw-agent-skills/tree/main/skills/security-vulnerability-management
Command: npx skills add https://github.com/KentoShimizu/sw-agent-skills --skill security-vulnerability-management-kentoshimizu

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes assets (resource) components.

What problem does it solve?

Automates the evidence-based lifecycle for vulnerability handling, ensuring consistent intake, triage, remediation planning, and verification to drive issues to closure.

Core Features & Use Cases

  • Vulnerability intake normalization and severity classification for consistent triage.
  • Remediation planning with owner assignment, due dates, and escalation paths.
  • Fix verification, closure evidence, and SLA/backlog metrics to monitor program health.
  • Use Case: When scans from SAST/DAST, bug bounty reports, or manual reviews produce items, this skill ranks by impact, assigns owners, and sequences fixes while documenting traceability in the vulnerability-triage template.

Quick Start

Run the vulnerability lifecycle workflow to intake, triage, remediate, and verify fixes from scans and reports.

Frequently Asked Questions about security-vulnerability-management

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I manage vulnerability triage from SAST and DAST scans to closure?

Vulnerability triage is managed by normalizing scan intake, assigning severity and owners, planning remediation with due dates, and enforcing evidence-based fix verification to drive issues to closure.

What is the best way to prioritize bug bounty reports for remediation?

Prioritize bug bounty reports by ranking impact during intake normalization, classifying severity, and sequencing fixes using an established escalation path and standardized vulnerability-triage template.

How does vulnerability lifecycle management handle fix verification and SLA tracking?

Vulnerability lifecycle management handles fix verification by requiring closure evidence and monitoring program health through SLA and backlog metrics to ensure remediation completeness.

Can I use this workflow for manual security review findings as well as automated scans?

Yes, you can use this workflow for manual security review findings alongside SAST/DAST scans and bug bounty programs, ensuring consistent intake, severity classification, and traceable remediation.

What does evidence-based vulnerability remediation require for backlog items?

Evidence-based vulnerability remediation requires assigning owners, setting due dates, documenting traceability in the triage template, and capturing standardized closure evidence before clearing backlog items.