triage-findings

Deduplicate and prioritize vulnerability findings using CVSS, EPSS, and KEV context.

5|3|Updated Apr 10, 2026
One-click install
npx skills add https://github.com/zebbern/termstack --skill triage-findings-zebbern
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: triage-findings
Source: https://github.com/zebbern/termstack/tree/main/.github/skills/triage-findings
Command: npx skills add https://github.com/zebbern/termstack --skill triage-findings-zebbern

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill consolidates scattered vulnerability findings into a unified, prioritized view, helping security teams drive faster remediation decisions.

Core Features & Use Cases

  • Deduplication: remove duplicates across sources to reveal distinct vulnerabilities.
  • Cross-tool correlation: align findings from Burp, Nuclei, and manual input to identify true positives.
  • Prioritization with context: compute priority using CVSS, EPSS, KEV, asset criticality, and business impact.
  • Triage reporting: generate a structured triage report that guides remediation planning.

Quick Start

Input vulnerability findings from scanners and output a prioritized triage report.

Frequently Asked Questions about triage-findings

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prioritize vulnerability findings using CVSS, EPSS, and KEV?

Prioritize vulnerability findings by computing priority through a defined matrix that combines CVSS scoring, EPSS integration, and KEV matching alongside asset criticality and business impact context.

What is the best way to deduplicate vulnerability findings from multiple scanners?

Deduplicate vulnerability findings from multiple sources by correlating scan results across tools and assets, removing duplicates to reveal distinct vulnerabilities for a consolidated, unified view.

Can I correlate scan results from tools like Burp and Nuclei for vulnerability triage?

Yes, you can correlate scan results from Burp, Nuclei, and manual input to identify true positives, aligning findings across tools and assets to produce a comprehensive triage report.

How do I generate a structured triage report for remediation planning?

Generate a structured triage report by consolidating scattered vulnerability findings into a unified, prioritized view that guides security teams in driving faster remediation decisions.

Does vulnerability triage require asset criticality and business impact context?

Yes, effective vulnerability triage computes priority using a defined matrix that incorporates asset criticality and business impact alongside CVSS, EPSS, and KEV context.

What limitations exist when correlating manual input with automated scanner findings?

The skill correlates manual input with automated scanner findings to identify true positives, but relies on the accuracy of the provided scan results and manual entries to produce a comprehensive triage report.