cve-triage
Installation
SKILL.md
CVE Triage Skill
A structured workflow for triaging CVE reports against a codebase. Coordinates security analysis, reproduction assessment, and patch verification.
Triage Phases
Phase 1: CVE Intake
- Parse CVE identifier and advisory details
- Identify affected component, version range, and CWE classification
- Determine if codebase uses the affected component
Phase 2: Impact Assessment
- Locate affected code paths via grep/CodeQL
- Assess exploitability in the project's specific context
- Determine severity (CRITICAL/HIGH/MEDIUM/LOW/NONE)
- Check if existing mitigations reduce impact