Vulnerability Triage Brocards

This skill should be used when the user asks to "triage a vulnerability report", "assess a CVE", "evaluate a bug bounty submission", "decide if a finding is valid", "review a security finding", "dismiss a vulnerability", "should we fix this CVE", "prioritize a vulnerability report", or needs to determine whether an incoming vulnerability report warrants investigation. Applies 7 brocards (rules of thumb) to systematically accept, dismiss, or request more information on vulnerability reports, or needs to filter raw findings from agentic vulnerability discovery pipelines before human review.

seikaikyo Updated

File contents

seikaikyo/dash-skills/tree/main/external/trailofbits-security/vulnerability-triage-brocards/skills/vulnerability-triage-brocards commit 2e73d1f335

Frequently asked questions

npx skillmds@latest add seikaikyo/vulnerability-triage-brocards