Vuln Tracker

Cross-reference vuln-scanned.json with live GitHub state to surface action items.

Updated Jun 2, 2026
One-click install
npx skills add https://github.com/Atrium-Hermes/atrium-lighthouse --skill vuln-tracker-atrium-hermes
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Vuln Tracker
Source: https://github.com/Atrium-Hermes/atrium-lighthouse/tree/main/skills/vuln-tracker
Command: npx skills add https://github.com/Atrium-Hermes/atrium-lighthouse --skill vuln-tracker-atrium-hermes

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Daily audit of vuln-scanner outputs to surface merges, maintainer replies, and stalled disclosures, ensuring nothing slips through the cracks.

Core Features & Use Cases

  • Automated lifecycle tracking: Cross-references memory/vuln-scanned.json with live GitHub state to surface action items for open PRs, advisories, and queued drafts.
  • Proactive maintenance: Highlights merged-but-uncelebrated wins, maintainer questions, and queued disclosures needing attention.
  • Operational dashboards: Generates a memory dashboard and operator queue to guide follow-ups and triage.

Quick Start

Run vuln-tracker to audit memory/vuln-scanned.json against live GitHub state and surface action items for open disclosures.

Frequently Asked Questions about Vuln Tracker

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate vulnerability tracking across GitHub PRs?

Use an automated vuln tracker to cross-reference vuln-scanned.json memory files with live GitHub state, surfacing action items for open PRs, advisories, and queued drafts needing maintainer replies.

How does cross-referencing vuln-scanned.json with GitHub state work?

Cross-referencing vuln-scanned.json with live GitHub state audits open PRs, advisories, and queued drafts to surface action items, highlighting merged wins, maintainer questions, and aging disclosures needing follow-up.

Can I use this vulnerability tracker for queued draft disclosures?

Yes, the vulnerability tracker audits queued drafts alongside open PRs and advisories to surface needs for maintainer replies, aging disclosures, and queued items requiring immediate attention.

What is the best way to track stalled vulnerability disclosures on GitHub?

Track stalled disclosures by running an automated audit that cross-references vuln-scanned.json with GitHub state, producing a memory dashboard and operator queue to guide follow-up triage.

How do I handle missing data when tracking GitHub vulnerability advisories?

The vulnerability tracker enforces strict input validation and handles missing data gracefully, ensuring the audit across PRs and advisories completes without failing on incomplete memory records.