Favicon of deal-with-security-advisory

deal-with-security-advisory Skill

AI Agent SkillSecurityTypeScriptOpen source

Handle a GitHub Security Advisory response for Paperclip, including confidential fix development in a temporary private fork, human coordination on advisory-thread comments, CVE request, synchronized advisory publication, and immediate security release steps. Published by microsoft in amplifier-app-paperclip.

What is deal-with-security-advisory Skill?

Handle a GitHub Security Advisory response for Paperclip, including confidential fix development in a temporary private fork, human coordination on advisory-thread comments, CVE request, synchronized advisory publication, and immediate security release steps. Published by microsoft in amplifier-app-paperclip. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.

Trust signal
95/100
Maintenance signal
90/100

Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement.

Key capabilities

  • Includes SKILL.md support
  • Reusable instructions support
  • Security review
  • Writing
  • Security review use cases
  • Writing use cases

Technical details

Copy skill directory
  • Install or run with Copy skill directory

When to use deal-with-security-advisory Skill

  • Use it for security review.
  • Use it for writing.

Built with

TypeScriptCopy skill directory

Editorial notes

Source

  • Creator: microsoft
  • Repository: microsoft/amplifier-app-paperclip
  • Skill file: .agents/skills/deal-with-security-advisory/SKILL.md

What it does

Handle a GitHub Security Advisory response for Paperclip, including confidential fix development in a temporary private fork, human coordination on advisory-thread comments, CVE request, synchronized advisory publication, and immediate security release steps.

Skill instructions

Security Vulnerability Response Instructions ⚠️ CRITICAL: This is a security vulnerability. Everything about this process is confidential until the advisory is published. Do not mention the vulnerability details in any public commit message, PR title, branch name, or comment. Do not push anything to a public branch. Do not discuss specifics in any public channel. Assume anything on the public repo is visible to attackers who will exploit the window between disclosure and user upgrades. Context A security vulnerability has been reported via GitHub Security Advisory: Advisory: {{ghsaId}} (e.g. GHSA-x8hx-rhr2-9rf7) Reporter: {{reporterHandle}} Severity: {{severity}} Notes: {{notes}} Step 0: Fetch the Advisory Details Pull the full advisory so you understand the vulnerability before doing anything else: gh api repos/paperclipai/paperclip/security-advisories/{{ghsaId}} Read the description, severity, cvss, and vulnerabilities fields. Understand the attack vector before writing code. Step 1:

Explore related resources

Frequently asked questions

What is deal-with-security-advisory?

deal-with-security-advisory is a open-source AI agent skill with Copy skill directory. Handle a GitHub Security Advisory response for Paperclip, including confidential fix development in a temporary private fork, human coordination on advisory-thread comments, CVE request.

Who is deal-with-security-advisory best for?

deal-with-security-advisory is best for reusing agent instructions, scripts, and references, security review workflows, writing workflows.

How do I install deal-with-security-advisory?

Install or run deal-with-security-advisory using Copy skill directory. Check deal-with-security-advisory for the latest setup command.

Is deal-with-security-advisory actively maintained?

deal-with-security-advisory may need a closer maintenance check before production use.

Share:

Stars
0
Forks
1
Last commit
14 days ago
Repository age
2 months
License
MIT

Auto-fetched from GitHub.

Similar to deal-with-security-advisory