Skip to content
Development
Skill

/triage-vulnerability-report

Triage a vulnerability report, scanner result, advisory, CVE, PoC, bug bounty, ticket, or researcher note. Use when affected versions, credibility, prerequisites, evidence, applicability, validation, and exposure must be established.

From plugin
socket
7200 skills5 MCP
Install
$ npx -y skills add gaelic-ghost/socket --skill triage-vulnerability-report --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/triage-vulnerability-report

Context preview

The summary Claude sees to decide when to auto-load this skill.

Triage a vulnerability report, scanner result, advisory, CVE, PoC, bug bounty, ticket, or researcher note. Use when affected versions, credibility, prerequisites, evidence, applicability, validation, and exposure must be established.

SKILL.md

triage-vulnerability-report.SKILL.md
name: triage-vulnerability-report
description: Triage a vulnerability report, scanner result, advisory, CVE, PoC, bug bounty, ticket, or researcher note. Use when affected versions, credibility, prerequisites, evidence, applicability, validation, and exposure must be established.

Triage Vulnerability Report

Overview

Convert incoming claims into a testable hypothesis tied to an exact product, version, configuration, and asset. Do not reproduce active impact until authorization and the smallest safe validation plan are explicit.

Read [references/vulnerability-intake.md](references/vulnerability-intake.md) for the normalized record.

Workflow

1. Preserve the original report and source. 2. Normalize identity.

  • Record product/component, versions, commit/build/image, dependency identity, advisory/CVE/CWE, endpoints/code paths, deployment/configuration, and affected assets.

3. Extract the claim.

  • State attacker position, prerequisites, input, security boundary crossed, result, impact, and supplied reproduction.

4. Grade evidence.

  • Separate scanner matching, vulnerable-code presence, reachability, successful reproduction, external advisory, and speculation.
  • Record logs, requests/responses, traces, screenshots, code, and environment details.

5. Check authoritative context.

  • Use vendor advisories, source/release history, OSV/ecosystem advisories, CISA KEV, and current disclosure state; date lookups.

6. Route ownership.

  • Use Codex Security for repository/diff scanning or attack-path work when available.
  • Route to vulnerability validation for a supplied claim and to the owning stack for remediation only after acceptance criteria are clear.

7. Define immediate action.

  • Identify exposed assets, reversible mitigations, missing evidence, safe validation, and disclosure/notification needs.

Output

Return normalized identity, claim, evidence grade, asset applicability, duplicates/advisories, urgency, validation plan, and owner.

Read more
Ships withsocket

Stuff for Agents on macOS Promo audio: Socket Codex Marketplace Promo

Get the whole plugin

Other skills on socket.