triage-new-findings

Triage SubImage security findings by prioritizing rules with open issues and grouping them by theme.

Updated Apr 30, 2026
One-click install
npx skills add https://github.com/subimagesec/skills --skill triage-new-findings
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: triage-new-findings
Source: https://github.com/subimagesec/skills/tree/main/plugins/subimage-mcp/skills/triage-new-findings
Command: npx skills add https://github.com/subimagesec/skills --skill triage-new-findings

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill turns a noisy stream of SubImage security findings into an actionable triage digest, so teams can quickly see what is newly important, which rules are most urgent, and where to investigate first.

Core Features & Use Cases

  • Finding triage: Lists rules with open findings, filters out disabled or dismissed noise, and highlights the highest-priority items.
  • Theme grouping: Organizes issues by tag or framework so users can spot patterns across IAM, exposure, encryption, and compliance controls.
  • Operational digesting: Supports daily and weekly security briefs, ownership pings, and escalation decisions with representative resources and next-step guidance.
  • Use case: A security analyst asks for a morning summary of open SubImage findings and gets a concise, grouped report that points to the most urgent investigation targets.

Quick Start

Ask the Skill to triage the latest SubImage findings and summarize the most urgent issues by tag with recommended next steps.

Frequently Asked Questions about triage-new-findings

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage security findings to prioritize urgent issues?

To triage security findings, the Skill lists rules with open issues, filters out disabled or dismissed noise, and groups results by tag or framework to highlight highest-priority items for investigation.

Can I generate a daily security digest for open compliance findings?

Yes, you can generate daily or weekly security digests that summarize open SubImage findings, group issues by theme, and provide representative resources with recommended next steps for escalation decisions.

How do I group security findings by tag or framework for compliance investigations?

Group security findings by organizing issues according to their assigned tags or compliance frameworks, allowing you to spot patterns across IAM, exposure, encryption, and compliance controls.

Does triaging findings work with the SubImage MCP server for daily security reviews?

Yes, the triage process works across the SubImage MCP server, fetching findings, filtering disabled results, and summarizing representative resources without passing unsupported framework arguments to the rules listing tool.

What is the best way to filter dismissed security findings during an urgent review?

The best way to filter dismissed findings is to list active rules, fetch all findings, and automatically exclude disabled or dismissed results, leaving only open issues grouped by theme for your urgent review.

Are there limitations when passing framework arguments to list security rules?

Yes, a key limitation is that unsupported framework arguments must not be passed to the rules listing tool, as doing so will disrupt the finding triage and digest generation process.