security-changelog-disclosure-review
Installation
SKILL.md
Security Changelog Disclosure Review
Use this skill to convert security changelog, vulnerability disclosure, advisory, release notes, trust center update, customer security notification, embargo, and remediation-timeline questions into a concrete artifact with owners, gates, metrics, and recovery paths.
Workflow
- Identify security change, affected versions, severity, exploitability, remediation state, customer exposure, disclosure audience, legal/security owner, embargo constraints, and support impact.
- Read
references/security-changelog-disclosure-patterns.md. - Classify the situation as routine hardening, dependency update, vulnerability fix, customer-impacting advisory, incident-related disclosure, CVE coordination, trust center update, or embargoed disclosure.
- Define severity language, affected scope, mitigation, upgrade path, customer notice, release-note wording, support macro, trust center update, monitoring, and post-disclosure review.
- Produce security disclosure plan, state machine, decision table, event schema, disclosure checklist, customer message, and monitoring plan.
When not to use
- Do not use for generic advice the base model already handles without this skill's specific artifact contract.