waivers

Automate formal waiver requests for blocking council findings with auditable governance.

Updated Apr 21, 2026
One-click install
npx skills add https://github.com/brucebanner010198-commits/DevSecOps-Agency --skill waivers
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: waivers
Source: https://github.com/brucebanner010198-commits/DevSecOps-Agency/tree/main/skills/waivers
Command: npx skills add https://github.com/brucebanner010198-commits/DevSecOps-Agency --skill waivers

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Formal waiver requests solve the problem of blocking red findings by providing a documented, auditable process that allows limited ship-time when remediation is not yet feasible.

Core Features & Use Cases

  • End-to-end waiver lifecycle: draft, review, approve/deny, expiry ADR, and historical/audit logs.
  • Integrates with _vision/waivers/, _decisions/, and _history to track open waivers and outcomes.
  • Enforces calendar expirations, independence checks, and governance rules to prevent permanent waivers.

Quick Start

Initiate a waiver by drafting a request using the templates in references, then present it to the user for approval.

Frequently Asked Questions about waivers

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I request a governance waiver for a blocking red finding?

To request a governance waiver for a blocking red finding, draft a formal request capturing the finding, owner, remediation plan, and ISO expiration date, then present it for independent approval to establish an auditable temporary exception.

What is an auditable waiver process for security red-team findings?

An auditable waiver process for security red-team findings provides a documented, time-boxed path to clear blocking issues when remediation is delayed. It enforces calendar expirations, independent approvals, and an ADR-driven paper trail across vision logs.

Does the waiver workflow require an explicit remediation plan and ISO expiration date?

Yes, the waiver workflow enforces prerequisites including a valid ISO expiration date and an explicit remediation plan. These governance rules prevent permanent waivers by ensuring temporary exceptions are time-boxed with clear corrective actions.

Can I use ADRs to document blocking-council waiver approvals and audit logs?

Yes, you can use ADRs to document blocking-council waiver approvals. The process integrates with _decisions and _history directories to maintain a complete ADR-driven paper trail tracking open waivers, outcomes, and historical audit logs.

What are the limitations of using time-boxed waivers for blocking security findings?

The limitation of time-boxed waivers is they cannot grant permanent exceptions; governance rules enforce calendar expirations, independent approval checks, and a complete ADR paper trail to ensure blocking security findings are eventually remediated.