Vulnerability Triage

Triage inbound vulnerability reports - GitHub Advisories (GHSA/CVE), bug bounty submissions, HackerOne/Bugcrowd/Intigriti exports, or a researcher's issue - to decide whether a finding is real, by-design, or noise. Reads the report offline, cross-references the project's documented intent and threat model (SECURITY.md, README, code, closed issues), statically audits any PoC without executing it, and emits a structured markdown triage report with a P0-P3 / By-Design severity and a recommended action. Use whenever the user asks to triage, assess, or score a vulnerability report, advisory, CVE, GHSA, or bug bounty submission, or asks "is this a real finding or by-design?".

superagent-ai 843db8f 5 files · 23.5 KB Updated

File contents

superagent-ai/skills/tree/main/skills/vulnerability-triage commit 843db8f4bf

Frequently asked questions

npx skillmds add superagent-ai/vulnerability-triage