deal-with-security-advisory Skill
Handle a GitHub Security Advisory response for Paperclip, including confidential fix development in a temporary private fork, human coordination on advisory-thread comments, CVE request, synchronized advisory publication, and immediate security release steps. Published by microsoft in amplifier-app-paperclip.
Decision snapshot
Is this a fit?
Security review, Writing, Includes SKILL.md, Reusable instructions
Compatibility not yet detected.
Permission behavior not yet detected.
Copy skill directory
2 months ago · MIT license
No specific cautions were detected. Review the source and requested permissions before installing.
What is deal-with-security-advisory Skill?
Handle a GitHub Security Advisory response for Paperclip, including confidential fix development in a temporary private fork, human coordination on advisory-thread comments, CVE request, synchronized advisory publication, and immediate security release steps. Published by microsoft in amplifier-app-paperclip. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.
Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement. See how SkillIndex evaluates profiles.
Key capabilities
- Includes SKILL.md support
- Reusable instructions support
- Security review
- Writing
- Security review use cases
- Writing use cases
Declared skill metadata
- Source file: .agents/skills/deal-with-security-advisory/SKILL.md
These fields retain source and confidence evidence from the indexed SKILL.md.
Compatibility and setup
- Install or run with Copy skill directory
When to use deal-with-security-advisory Skill
- Use it for security review.
- Use it for writing.
Built with
Editorial notes
Source
- Creator: microsoft
- Repository: microsoft/amplifier-app-paperclip
- Skill file: .agents/skills/deal-with-security-advisory/SKILL.md
What it does
Handle a GitHub Security Advisory response for Paperclip, including confidential fix development in a temporary private fork, human coordination on advisory-thread comments, CVE request, synchronized advisory publication, and immediate security release steps.
Skill instructions
Security Vulnerability Response Instructions ⚠️ CRITICAL: This is a security vulnerability. Everything about this process is confidential until the advisory is published. Do not mention the vulnerability details in any public commit message, PR title, branch name, or comment. Do not push anything to a public branch. Do not discuss specifics in any public channel. Assume anything on the public repo is visible to attackers who will exploit the window between disclosure and user upgrades. Context A security vulnerability has been reported via GitHub Security Advisory: Advisory: {{ghsaId}} (e.g. GHSA-x8hx-rhr2-9rf7) Reporter: {{reporterHandle}} Severity: {{severity}} Notes: {{notes}} Step 0: Fetch the Advisory Details Pull the full advisory so you understand the vulnerability before doing anything else: gh api repos/paperclipai/paperclip/security-advisories/{{ghsaId}} Read the description, severity, cvss, and vulnerabilities fields. Understand the attack vector before writing code. Step 1:
Verified compatibility and discovery
Frequently asked questions
What is deal-with-security-advisory?
deal-with-security-advisory is a open-source AI agent skill with Copy skill directory. Handle a GitHub Security Advisory response for Paperclip, including confidential fix development in a temporary private fork, human coordination on advisory-thread comments, CVE request.
Who is deal-with-security-advisory best for?
deal-with-security-advisory is best for reusing agent instructions, scripts, and references, security review workflows, writing workflows.
How do I install deal-with-security-advisory?
Install or run deal-with-security-advisory using Copy skill directory. Check deal-with-security-advisory for the latest setup command.
Is deal-with-security-advisory actively maintained?
deal-with-security-advisory may need a closer maintenance check before production use.
Project health auto-fetched from the source repository.
Maintain this resource?
Review this source-backed profile, send a correction with evidence, or link to it from your documentation. Claims verify your relationship to the project; profile facts still require source evidence and editorial review.