Omv Disclose

Helps prepare responsible disclosure communications and timelines from an Evidence.v1 finding. Use when the user asks to contact a vendor, create initial/follow-up/deadline disclosure email templates, plan a 90-day timeline, record disclosure fields, or invokes `/omv-disclose`.

bx33661 0205ac6 6 files · 13.2 KB Updated

File contents

omv-disclose

Prepare local responsible disclosure material after a finding is report-ready.

Invocation

/omv-disclose <id>
/omv-disclose timeline <id> [--days N]

Workflow

  1. Read .omv/findings/<id>.yaml using contracts/evidence.v1.yaml as the local schema reference.
  2. Identify vendor type: individual maintainer, company, foundation, or unknown.
  3. Generate three templates: initial contact, follow-up, and disclosure deadline reminder.
  4. Use omv disclose timeline <id> for 90-day milestones or --days N for a custom window.
  5. Ask before writing Evidence.v1 disclosure fields.

Template Requirements

Include package name, affected versions, impact summary, reproduction summary, suggested coordination deadline, and contact metadata. Avoid exploit payload expansion beyond what the existing Evidence.v1 reproducer already states.

Local State

Submission bookkeeping belongs in .omv/submissions/<id>.yaml through omv submissions and follows contracts/submission.v1.yaml. Research notes belong in .omv/notes/<id>.md. Treat both as private local state until sanitized.

bx33661/oh-my-vul/tree/main/skills/omv-disclose commit 0205ac620c

Frequently asked questions

npx skillmds@latest add bx33661/omv-disclose