Vulnerability Triage

Prioritizes vulnerability findings from scanners, pentest reports, and bug bounty submissions by real-world exploitability rather than raw CVSS, assigning internal severity tiers with fix SLAs. Use when someone asks "which of these CVEs do we fix first", "triage this scanner report", "is this CVSS 9.8 actually critical for us", or is facing a wall of security findings and needs an actionable queue. Do NOT use for enumerating threats in a design that has not shipped - use threat-model-stride instead; for an active exploitation incident in production, use sev-triage; for reviewing the code itself, use secure-code-review.

SkillMedev 0772afd 7.5 KB Updated

File contents

SkillMedev/security-compliance-hardening/tree/main/skills/vulnerability-triage commit 0772afd68e

Frequently asked questions

npx skillmds@latest add skillmedev/vulnerability-triage