一个生成安全公告草稿的开源技能,可输出 GHSA/CVE 风格的 Markdown,明确拒绝包含利用细节和 PoC 代码。

Stars

7

7 天增长

暂无数据

Fork 数

4

开放 Issue

0

开源协议

MIT

最近更新

2026-07-30

AI 仓库情报摘要
FR-AI / ANALYSIS

为什么值得关注

面向维护者与安全团队,在披露前快速生成结构化的安全公告草稿,支持中英文和多种格式,并主动避免武器化内容。

适合谁使用

  • 准备安全发布说明的开源维护者
  • 开展协同披露的安全团队
  • 需要填写 GHSA/CVE 字段的项目维护者
  • 需要中英文安全公告草稿的开发者

典型使用场景

  • 在公开披露前起草 GHSA 风格公告
  • 为安全发布生成 CVE 字段 Markdown
  • 生成中英双语公告草稿
  • 编写安全变更日志说明和内部备注

项目优势

  • 明确拒绝利用配方和 PoC 代码,保持草稿安全
  • 支持 ghsa、cve-fields、markdown、all 多种输出格式
  • 可配置语言、严重性和就绪度选项
  • 交付物包含字段表、公告正文、变更日志安全说明和内部备注

使用前须知

  • 不用于依赖项分流或生成可利用 PoC
  • 只生成公告草稿,不包含漏洞扫描或发现能力
  • 严重性默认 tbd、状态默认 draft,最终值需用户补充

README 快速开始

Security Advisory

Open-source security advisory draft: affected versions, high-level preconditions, fixes, mitigations — no weaponized detail.

中文简介: 开源安全公告草稿(影响版本、前提概要、修复、缓解;无利用细节)。 — 详见 README.zh.md.

What this skill does

  • Drafts GHSA/CVE-style advisory markdown
  • Fills version ranges, severity, credit, timeline
  • Emphasizes upgrade paths and safe mitigations
  • Refuses exploit recipes and PoC code

Install

npx skills add / --skill security-advisory

Local monorepo: skills/security-advisory/.

Options

OptionValuesDefault
langen · zh · bilingualen
formatghsa · cve-fields · markdown · allmarkdown
severitydraft · public-readydraft
severitylow · moderate · high · critical · tbdtbd

When to use

UseDon't
Preparing disclosure / security release notesGenerate working exploits
Coordinated disclosure draftDependency triage only
Maintainer advisory fieldsPublish unfixed 0-day how-to

Deliverable

Field table + advisory body + short changelog security blurb + internal notes.

See SKILL.md.

Example

../../output/samples/security-advisory-example-01.md

License

MIT — see LICENSE.

相关仓库与替代方案

根据分类、Topic 和编程语言匹配的相似项目。

m-novotny
精选
m-novotny GitHub avatar

memguard-rs

A Rust library that provides secure memory handling primitives including zeroization on drop, memory locking, constant-time comparison, and compile-time guarded regions, with zero dependencies and no_std support.

嵌入式与物联网安全
131
MoonshotAI
精选
MoonshotAI GitHub avatar

Kimi-K3

Kimi K3 is an open-weight, 2.8T-parameter native multimodal agentic model with a 1M-token context window, designed for frontier coding, knowledge work, and reasoning tasks.

AI 与机器学习AI 智能体
3,348
xuchonglang
精选
xuchonglang GitHub avatar

investing-for-beginners

A structured investing guide for Chinese beginners covering US stocks, options, and cryptocurrency, with focus on foundational concepts and risk awareness.

区块链与 Web3
2,739