model-onboarding
Onboard a new model generation or sibling into oh-my-hermes: probe router recognition,…
[omh] Security event on the code already shipped -- a CVE in a dependency, a secret committed to the repo, a license question, an advisory: triage reachability and severity, contain in order, and never close a leaked secret before its rotation is observed. Use when the user
$ npx -y skills add rlaope/oh-my-hermes --skill omh-security-event-response --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/omh-security-event-responseContext preview
The summary Claude sees to decide when to auto-load this skill.
[omh] Security event on the code already shipped -- a CVE in a dependency, a secret committed to the repo, a license question, an advisory: triage reachability and severity, contain in order, and never close a leaked secret before its rotation is observed. Use when the user
name: "omh-security-event-response"
description: "[omh] Security event on the code already shipped -- a CVE in a dependency, a secret committed to the repo, a license question, an advisory: triage reachability and severity, contain in order, and never close a leaked secret before its rotation is observed. Use when the user says: security-event-response, security event response, cve, triage this cve, cve in our dependency, cve in a dependency, security advisory, dependabot alert."
metadata:
hermes:
tags: [workflow, oh-my-hermes, review]
category: review
phase: security-event-response
role: reviewer
quality_tier: event-closure-gatedThis is a Hermes-native `security-event-response` workflow skill.
`security-event-response` exists because an event had no owner: `security-safety-review` and `application-threat-model` review a design before it ships, and a CVE, a committed secret, or a license question was answered by onboarding, review, or an achievements lane with no containment order at all.
Good example:
Bad example:
Use when a security event has already happened to code that exists: a CVE or advisory in a dependency, a secret or credential committed or pushed, a dependency whose license may not fit the product, or an advisory that forces a major version. The output is reachability, a severity call, containment steps in order, and what must be observed before the event closes; OMH never scans, never contacts a registry, and rotates nothing.
Strong routing signals: `security-event-response`, `security event response`, `cve`, `triage this cve`, `cve in our dependency`, `cve in a dependency`, `security advisory`, `dependabot alert`, `dependabot security`, `vulnerable dependency`, `vulnerability in our dependency`, `reachability analysis`, `npm audit`, `committed a secret`, `committed an api key`, `leaked secret`, `leaked a secret`, `leaked credential`, `leaked api key`, `leaked an api key`, `leaked aws key`, `leaked an aws key`, `secret in git history`, `secret in the history`, `dependency license`, `dependency's license`, `license ok`, `license compatibility`, `license compatible`, `gpl dependency`, `agpl dependency`
Category: `review` Phase: `security-event-response` Hermes role: `reviewer` Quality tier: `event-closure-gated` Reasoning demand: `standard`
Quality bar:
Handoff policy:
Keep the event record, the reachability call, the ordered containment plan, and the closure verdict in Hermes. Scanner output, advisory text, registry metadata, rotations, revocations, and history rewrites are recorded o
English | 한국어 | 日本語 | 中文 Install once. Keep Hermes. Add a stronger operating layer. Planning, research, creation, coding handoffs, operations, and project memory with explicit evidence boundaries.
Repo: rlaope/oh-my-hermes
Onboard a new model generation or sibling into oh-my-hermes: probe router recognition,…
Review oh-my-hermes pull requests that have not been reviewed at their current head commit.…
Backfill labels across oh-my-hermes issues and pull requests. Run manually to sweep…
[omh] Screen-reader or keyboard accessibility gaps: prepare WCAG, keyboard, focus,…
[omh] Hermes badges unlocked and achievement progress: achievements observation: summarize…
[omh] Technical proposal facing adversarial scrutiny: independent perspectives attack a…