track-findings Skill
Track validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories. Use it for one finding or an explicitly selected batch of up to 25 findings tracked as Linear, Jira, or GitHub issues. Includes duplicate checks, exact previews, approval-gated writes, and readback. Do not use i Published by openai in plugins.
What is track-findings Skill?
Track validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories. Use it for one finding or an explicitly selected batch of up to 25 findings tracked as Linear, Jira, or GitHub issues. Includes duplicate checks, exact previews, approval-gated writes, and readback. Do not use i Published by openai in plugins. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.
Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement.
Key capabilities
- Includes SKILL.md support
- Reusable instructions support
- Security review
- Deployment
- Writing
- Security review use cases
- Deployment use cases
Technical details
- Install or run with Copy skill directory
When to use track-findings Skill
- Use it for security review.
- Use it for deployment.
- Use it for writing.
Built with
Editorial notes
Source
- Creator: openai
- Repository: openai/plugins
- Skill file: plugins/codex-security/skills/track-findings/SKILL.md
What it does
Track validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories. Use it for one finding or an explicitly selected batch of up to 25 findings tracked as Linear, Jira, or GitHub issues. Includes duplicate checks, exact previews, approval-gated writes, and readback. Do not use i
Skill instructions
Track Findings Objective Track findings from one sealed Codex Security scan as Linear issues, Jira issues, GitHub issues, or one draft GitHub security advisory. Do not change the scan bundle. Use one provider and one destination per run. Show the exact payload and get approval before writing. GitHub advisory mode creates one private draft in the verified public canonical source repository through authenticated gh api --hostname github.com. Read references/github-security-advisories.md in full before advisory work. Jira mode uses Atlassian Rovo to create, reuse, or update one Jira Cloud issue per selected finding. Use it for one finding or an explicitly selected batch of up to 25. Read references/jira.md in full before Jira work. Resources The tracking helper is at the plugin root: - scripts/validatetrackingsource.py This skill lives at <plugin-root/skills/track-findings/SKILL.md, so <plugin-root is two directories up. Do not look for the helper inside the skill directory. GitHub adviso
Explore related resources
Frequently asked questions
What is track-findings?
track-findings is a open-source AI agent skill with Copy skill directory. Track validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories.
Who is track-findings best for?
track-findings is best for reusing agent instructions, scripts, and references, security review workflows, deployment workflows, writing workflows.
How do I install track-findings?
Install or run track-findings using Copy skill directory. Check track-findings for the latest setup command.
Is track-findings actively maintained?
track-findings may need a closer maintenance check before production use.
Auto-fetched from GitHub.