A security-advisory drafting skill that generates GHSA/CVE-style markdown with affected versions, mitigations, and a deliberate refusal to include exploit details.

Stars

7

7-day growth

No data

Forks

4

Open issues

0

License

MIT

Last updated

2026-07-30

AI repository intelligence
FR-AI / ANALYSIS

Why it is worth attention

It addresses a real need for maintainers and security teams preparing coordinated disclosures by structuring advisory drafts and explicitly blocking weaponized content, while offering multilingual and multi-format options.

Who it is for

  • Open-source maintainers preparing security release notes
  • Security teams drafting coordinated disclosures
  • Project maintainers needing GHSA/CVE-format advisory fields
  • Developers writing security changelog blurbs

Use cases

  • Draft a GHSA-style advisory before public disclosure
  • Generate CVE-field markdown for a security release
  • Create a bilingual (English/Chinese) advisory draft
  • Add a security changelog blurb and internal notes to a release

Strengths

  • Refuses exploit recipes and PoC code, keeping drafts safe
  • Supports multiple output formats: ghsa, cve-fields, markdown, and all
  • Configurable language, severity, and readiness options
  • Deliverable includes a field table, advisory body, changelog security blurb, and internal notes

Considerations

  • Not designed for dependency triage or generating working exploits
  • Only drafts advisory content; no scanning or vulnerability discovery is described
  • Severity and readiness default to tbd and draft, so final values need user input

README quick start

Security Advisory

Open-source security advisory draft: affected versions, high-level preconditions, fixes, mitigations — no weaponized detail.

中文简介: 开源安全公告草稿(影响版本、前提概要、修复、缓解;无利用细节)。 — 详见 README.zh.md.

What this skill does

  • Drafts GHSA/CVE-style advisory markdown
  • Fills version ranges, severity, credit, timeline
  • Emphasizes upgrade paths and safe mitigations
  • Refuses exploit recipes and PoC code

Install

npx skills add / --skill security-advisory

Local monorepo: skills/security-advisory/.

Options

OptionValuesDefault
langen · zh · bilingualen
formatghsa · cve-fields · markdown · allmarkdown
severitydraft · public-readydraft
severitylow · moderate · high · critical · tbdtbd

When to use

UseDon't
Preparing disclosure / security release notesGenerate working exploits
Coordinated disclosure draftDependency triage only
Maintainer advisory fieldsPublish unfixed 0-day how-to

Deliverable

Field table + advisory body + short changelog security blurb + internal notes.

See SKILL.md.

Example

../../output/samples/security-advisory-example-01.md

License

MIT — see LICENSE.

Related repositories

Similar projects matched by category, topics, and programming language.

m-novotny
Featured
m-novotny GitHub avatar

memguard-rs

A Rust library that provides secure memory handling primitives including zeroization on drop, memory locking, constant-time comparison, and compile-time guarded regions, with zero dependencies and no_std support.

Embedded & IoTSecurity
131
MoonshotAI
Featured
MoonshotAI GitHub avatar

Kimi-K3

Kimi K3 is an open-weight, 2.8T-parameter native multimodal agentic model with a 1M-token context window, designed for frontier coding, knowledge work, and reasoning tasks.

AI & Machine LearningAI Agents
3,348
xuchonglang
Featured
xuchonglang GitHub avatar

investing-for-beginners

A structured investing guide for Chinese beginners covering US stocks, options, and cryptocurrency, with focus on foundational concepts and risk awareness.

Blockchain & Web3
2,739