vulnerability-writeup Skill
Write up vulnerabilities from disclosure documents, rough notes, supplied findings, PoCs, source code, or Codex Security scan output into polished, self-contained, source-backed reports. Use for one vulnerability or a disclosure campaign; a Codex Security scan is optional. Published by openai in plugins.
What is vulnerability-writeup Skill?
Write up vulnerabilities from disclosure documents, rough notes, supplied findings, PoCs, source code, or Codex Security scan output into polished, self-contained, source-backed reports. Use for one vulnerability or a disclosure campaign; a Codex Security scan is optional. Published by openai in plugins. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.
Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement.
Key capabilities
- Includes SKILL.md support
- Reusable instructions support
- Security review
- Writing
- Research
- Security review use cases
- Writing use cases
Technical details
- Install or run with Copy skill directory
When to use vulnerability-writeup Skill
- Use it for security review.
- Use it for writing.
- Use it for research.
Built with
Editorial notes
Source
- Creator: openai
- Repository: openai/plugins
- Skill file: plugins/codex-security/skills/vulnerability-writeup/SKILL.md
What it does
Write up vulnerabilities from disclosure documents, rough notes, supplied findings, PoCs, source code, or Codex Security scan output into polished, self-contained, source-backed reports. Use for one vulnerability or a disclosure campaign; a Codex Security scan is optional.
Skill instructions
Vulnerability Writeup Overview Produce a distributable report set from rough vulnerability notes, PoCs, and source code. Treat this as a technical disclosure campaign: every distinct vulnerability gets its own directory, its own report, its own PoC artifacts, and its own sub-agent draft. The desired output is not a cleaned-up note. It is a calm, expert narrative that proves the bug from source, explores how far the primitive can realistically be pushed, and ships with a PoC that another researcher can build and run. Do not require a Codex Security scan, scan ID, manifest, findings JSON, coverage receipt, or seal. Ordinary disclosure documents and supplied vulnerability material are first-class inputs. When scan artifacts are present, use their validated fields as additional evidence; otherwise inventory the supplied documents directly and proceed with the same research and quality bar. Core Rules - Use one sub-agent per vulnerability write-up. Do not assign multiple vulnerabilities to
Explore related resources
Frequently asked questions
What is vulnerability-writeup?
vulnerability-writeup is a open-source AI agent skill with Copy skill directory. Write up vulnerabilities from disclosure documents, rough notes, supplied findings, PoCs, source code, or Codex Security scan output into polished, self-contained, source-backed reports.
Who is vulnerability-writeup best for?
vulnerability-writeup is best for reusing agent instructions, scripts, and references, security review workflows, writing workflows, research workflows.
How do I install vulnerability-writeup?
Install or run vulnerability-writeup using Copy skill directory. Check vulnerability-writeup for the latest setup command.
Is vulnerability-writeup actively maintained?
vulnerability-writeup may need a closer maintenance check before production use.
Auto-fetched from GitHub.