vuln-triage-quality-gate

Validate WordPress vulnerability triage reports for evidence, scope, and CVSS consistency.

Updated Mar 19, 2026
One-click install
npx skills add https://github.com/sjinks/ai-wp-vulnerability-triage --skill vuln-triage-quality-gate
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vuln-triage-quality-gate
Source: https://github.com/sjinks/ai-wp-vulnerability-triage/tree/main/.agents/skills/vuln-triage-quality-gate
Command: npx skills add https://github.com/sjinks/ai-wp-vulnerability-triage --skill vuln-triage-quality-gate

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Final triage reports often suffer from inconsistent evidence, unclear scope, and misaligned mitigations. This skill provides a structured quality gate to ensure reports are evidence-backed, scope-appropriate, and ready for stakeholder review.

Core Features & Use Cases

  • Evidence-backed claims: Every key claim references a file and line.
  • Explicit scope and boundary: Documents unauthenticated vs authenticated reach, roles, and target components.
  • Companion rubric coherence: Aligns with reachability, CVSS, threat model, and acceptance rubric to produce a formal report.

Quick Start

Run the quality gate on the latest WP triage report to verify evidence, scope, and mitigation coherence before publication.

Frequently Asked Questions about vuln-triage-quality-gate

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate evidence alignment in WordPress vulnerability triage reports?

Validating evidence alignment in WordPress vulnerability triage requires a quality gate that verifies every key claim references a specific file and line. This structured check ensures reports are evidence-backed, scope-appropriate, and ready for formal stakeholder review.

What is a quality gate for WordPress plugin and theme security advisories?

A quality gate for WordPress security advisories is an automated final validation step that checks evidence alignment, scope clarity, CVSS consistency, and mitigation recommendations. It enforces must-pass criteria and companion rubrics to ensure formal triage reports meet publication standards.

How do I ensure CVSS consistency and explicit entry paths in my vulnerability report?

You can ensure CVSS consistency and explicit entry paths by applying a structured quality gate to your end-to-end triage workflow. This validation step enforces companion rubric coherence by checking that reports explicitly document unauthenticated versus authenticated reach, roles, and target components.

Can I use an automated triage quality gate for WordPress plugins without external dependencies?

Yes, you can use an automated triage quality gate for WordPress plugins without external dependencies. The validation process operates independently to verify file-and-line evidence, scope boundaries, and structured remediation guidance across advisories before they reach stakeholder review.

What is the best way to check scope clarity for unauthenticated vs authenticated reach in WP triage reports?

The best way to check scope clarity for authentication reach in WP triage reports is applying a final quality gate. This step explicitly validates the documentation of unauthenticated versus authenticated boundaries, affected roles, and target components to ensure formal report coherence.

Why does my WordPress vulnerability triage report fail stakeholder review?

Your WordPress vulnerability triage report may fail stakeholder review due to inconsistent evidence, unclear scope, or misaligned mitigations. A final quality gate identifies these issues by validating evidence alignment, CVSS consistency, and structured remediation guidance before publication.