pwnote-cve-research
Installation
SKILL.md
CVE Research & Disclosure Workflow
Reference for running a vulnerability research + responsible disclosure engagement from initial finding through published advisory and CVE assignment.
1. Disclosure Timeline Tracking
Track every engagement as a timestamped activity log (maps to pwnote activity blocks or a timeline block):
| Stage | What to log |
|---|---|
| Discovery | date, affected product/version, initial severity assessment |
| Vendor contact | date, channel used (security.txt, PSIRT email, HackerOne if they run a VDP), response received y/n |
| Vendor acknowledgment | date, vendor's stated timeline/SLA |
| Fix development | vendor updates, patch ETA changes |
| Embargo date | agreed public disclosure date — track any renegotiation |
| CVE assignment | date requested, date assigned, CVE ID |
| Publication | advisory published date, links |
Default disclosure window if the vendor is unresponsive: industry norm is 90 days from initial contact before considering public disclosure, with recognition that this can extend if the vendor engages in good faith and needs more time for a complex fix. State your policy explicitly in the first vendor contact so there's no ambiguity later.