pwnote-cve-research

Installation
SKILL.md

CVE Research & Disclosure Workflow

Reference for running a vulnerability research + responsible disclosure engagement from initial finding through published advisory and CVE assignment.

1. Disclosure Timeline Tracking

Track every engagement as a timestamped activity log (maps to pwnote activity blocks or a timeline block):

Stage What to log
Discovery date, affected product/version, initial severity assessment
Vendor contact date, channel used (security.txt, PSIRT email, HackerOne if they run a VDP), response received y/n
Vendor acknowledgment date, vendor's stated timeline/SLA
Fix development vendor updates, patch ETA changes
Embargo date agreed public disclosure date — track any renegotiation
CVE assignment date requested, date assigned, CVE ID
Publication advisory published date, links

Default disclosure window if the vendor is unresponsive: industry norm is 90 days from initial contact before considering public disclosure, with recognition that this can extend if the vendor engages in good faith and needs more time for a complex fix. State your policy explicitly in the first vendor contact so there's no ambiguity later.

Installs
1
Repository
pwnote/skills
First Seen
12 days ago
pwnote-cve-research — pwnote/skills