review-security-report
Installation
SKILL.md
Review a FastMCP security report
A working proof of concept establishes behavior, not ownership or classification. Identify the component that violates a promised security boundary before changing code or advisory state.
Preserve the evidence
Before editing an advisory, export the report, comments, proof of concept, configuration, and claimed affected versions. Record the reproduced commit and derive affected releases from history.
Keep the investigation read-only until classification. Do not mutate the advisory or prepare a fix merely because the proof of concept works.
Reproduce the claim
Use the smallest end-to-end reproduction against a supported release. Record: