Triaging Security Reports

Use when a vulnerability or security report arrives for triage, when assessing a CVE/RCE/OGNL/injection claim against the code, or when drafting a reply to a security researcher — to research the claim from source without trusting the reporter and without fabricating your own facts.

tomevault-io Updated

File contents

tomevault-io/skills-registry/tree/main/apache--struts--struts commit 8d50788da9

Frequently asked questions

npx skillmds@latest add tomevault-io/triaging-security-reports