deal-with-security-advisory Skill
Handle a GitHub Security Advisory response for Paperclip, including confidential fix development in a temporary private fork, human coordination on advisory-thread comments, CVE request, synchronized advisory publication, and immediate security release steps. Published by microsoft in amplifier-app-paperclip.
What is deal-with-security-advisory Skill?
Handle a GitHub Security Advisory response for Paperclip, including confidential fix development in a temporary private fork, human coordination on advisory-thread comments, CVE request, synchronized advisory publication, and immediate security release steps. Published by microsoft in amplifier-app-paperclip. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.
Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement.
Key capabilities
- Includes SKILL.md support
- Reusable instructions support
- Security review
- Writing
- Security review use cases
- Writing use cases
Technical details
- Install or run with Copy skill directory
When to use deal-with-security-advisory Skill
- Use it for security review.
- Use it for writing.
Built with
Editorial notes
Source
- Creator: microsoft
- Repository: microsoft/amplifier-app-paperclip
- Skill file: .agents/skills/deal-with-security-advisory/SKILL.md
What it does
Handle a GitHub Security Advisory response for Paperclip, including confidential fix development in a temporary private fork, human coordination on advisory-thread comments, CVE request, synchronized advisory publication, and immediate security release steps.
Skill instructions
Security Vulnerability Response Instructions ⚠️ CRITICAL: This is a security vulnerability. Everything about this process is confidential until the advisory is published. Do not mention the vulnerability details in any public commit message, PR title, branch name, or comment. Do not push anything to a public branch. Do not discuss specifics in any public channel. Assume anything on the public repo is visible to attackers who will exploit the window between disclosure and user upgrades. Context A security vulnerability has been reported via GitHub Security Advisory: Advisory: {{ghsaId}} (e.g. GHSA-x8hx-rhr2-9rf7) Reporter: {{reporterHandle}} Severity: {{severity}} Notes: {{notes}} Step 0: Fetch the Advisory Details Pull the full advisory so you understand the vulnerability before doing anything else: gh api repos/paperclipai/paperclip/security-advisories/{{ghsaId}} Read the description, severity, cvss, and vulnerabilities fields. Understand the attack vector before writing code. Step 1:
Explore related resources
Frequently asked questions
What is deal-with-security-advisory?
deal-with-security-advisory is a open-source AI agent skill with Copy skill directory. Handle a GitHub Security Advisory response for Paperclip, including confidential fix development in a temporary private fork, human coordination on advisory-thread comments, CVE request.
Who is deal-with-security-advisory best for?
deal-with-security-advisory is best for reusing agent instructions, scripts, and references, security review workflows, writing workflows.
How do I install deal-with-security-advisory?
Install or run deal-with-security-advisory using Copy skill directory. Check deal-with-security-advisory for the latest setup command.
Is deal-with-security-advisory actively maintained?
deal-with-security-advisory may need a closer maintenance check before production use.
Auto-fetched from GitHub.