security-vulnerability-management
Installation
SKILL.md
Security Vulnerability Management
Overview
Use this skill to run vulnerability handling as an evidence-based lifecycle instead of ad hoc ticket triage.
Scope Boundaries
- Vulnerabilities arrive from SAST/DAST/dependency scans, bug bounty, or manual review.
- Teams need severity ranking, SLA targets, and remediation sequencing.
- Fix validation and closure criteria must be standardized.
Templates And Assets
- Vulnerability triage template:
assets/vulnerability-triage-template.csv
Inputs To Gather
- Vulnerability source, technical details, and reproduction evidence.
- Asset criticality, exploitability context, and external exposure.
- Available mitigations, patch options, and rollout constraints.
- Regulatory or contractual remediation time limits.