security-vulnerability-response
Installation
SKILL.md
Security Vulnerability Response
Classify severity, contain exposure, define owner and expiry for exceptions, plan remediation, and verify release gates.
Process
- Inspect the changed behavior and data flow before listing risks.
- Check negative paths, bypasses, tenant/object boundaries, logs, cache, async jobs, and release impact where relevant.
- For review, report findings by severity with file references and concrete exploit or failure scenarios.
- For implementation, add controls and tests in the backend or trusted boundary; do not rely on frontend-only enforcement.
Evidence
Prefer code, tests, logs, config, API contracts, and data examples over assumptions.
Focused References
- 01-severity-and-exceptions.md - Severity And Exceptions
- 02-release-detection-process.md - Release Detection And Process