triage-vulnerabilities

Aggregate and deduplicate security vulnerabilities from Dependabot, GCP Artifact Registry, Docker Scout, and Linear.

Updated Apr 28, 2026
One-click install
npx skills add https://github.com/89jobrien/warpx --skill triage-vulnerabilities
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: triage-vulnerabilities
Source: https://github.com/89jobrien/warpx/tree/main/resources/channel-gated-skills/dogfood/triage-vulnerabilities
Command: npx skills add https://github.com/89jobrien/warpx --skill triage-vulnerabilities

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Triage and remediate security vulnerabilities across Warp infrastructure, enabling teams to quickly identify, prioritize, and remediate issues.

Core Features & Use Cases

  • Aggregate and normalize vulnerability data from Dependabot alerts (GitHub), GCP Artifact Registry scans, Docker Scout, and Linear security issues.
  • Deduplicate and track vulnerabilities across production and staging projects, generating a prioritized remediation plan and TODOs.
  • Guide PR creation with CVE IDs, advisories, and links to upstream fixes to close issues efficiently.

Quick Start

Prompt the triage-vulnerabilities skill to start analyzing open vulnerabilities across Warp sources and generate a remediation plan.

Frequently Asked Questions about triage-vulnerabilities

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage security vulnerabilities across multiple sources like Dependabot and GCP Artifact Registry?

To triage security vulnerabilities across multiple sources, this Skill aggregates and normalizes findings from Dependabot, GCP Artifact Registry, Docker Scout, and Linear. It identifies and deduplicates issues across production and staging to generate a single prioritized remediation plan.

What's the best way to deduplicate vulnerability findings across production and staging environments?

The best way to deduplicate vulnerability findings is to use this Skill to aggregate alerts from Docker Scout and Dependabot. It tracks vulnerabilities across production and staging environments, normalizes the data, and outputs a consolidated list of prioritized TODOs.

Can I generate a prioritized remediation plan for CVEs found in Docker Scout and Linear security issues?

Yes, you can generate a prioritized remediation plan for CVEs found in Docker Scout and Linear. The Skill analyzes these security issues, prioritizes them, and records actionable TODOs to guide your remediation workflow.

How do I track and close GitHub Dependabot alerts with PRs that include CVE IDs and advisory links?

To track and close Dependabot alerts, this Skill guides PR creation by attaching specific CVE IDs, advisories, and links to upstream fixes. This ensures vulnerabilities are closed efficiently with proper tracking metadata.

Does this vulnerability triage process require separate configuration for Docker Scout and GCP Artifact Registry scanning?

The vulnerability triage process aggregates findings from both Docker Scout and GCP Artifact Registry scanning without requiring separate manual configuration per source. It normalizes the alerts automatically to produce a unified remediation plan.