From db41c9c6ff67453c4496f98fc58978baf75c38a4 Mon Sep 17 00:00:00 2001 From: Cesar Acosta Date: Wed, 16 Sep 2026 17:39:37 -0400 Subject: [PATCH] Trim vulnerability triage skill description Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- .github/skills/vuln-triage-reporter/SKILL.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/skills/vuln-triage-reporter/SKILL.md b/.github/skills/vuln-triage-reporter/SKILL.md index f6a1c87b..a591bafb 100644 --- a/.github/skills/vuln-triage-reporter/SKILL.md +++ b/.github/skills/vuln-triage-reporter/SKILL.md @@ -1,6 +1,6 @@ --- name: vuln-triage-reporter -description: Triage, classify, AND remediate MSRC/ITD security vulnerabilities filed against Android Authenticator & Broker. Right-sizes the security team's filed severity with evidence-based codebase analysis, produces on-call/WBR reports, and (when asked) executes the fix end-to-end — implementing the change, writing tests, and opening a public-repo-safe PR. Use this skill when an on-call engineer needs to process recent [MSRC]- or [ITD]-tagged IcMs, decide whether to agree with the filed severity or rebut it with code evidence, generate per-finding + aggregate reports, OR implement and ship the remediation for a kept finding. Triggers include "triage MSRC", "my MSRC", "I have an MSRC", "look at this MSRC/ITD", "classify these vulnerabilities", "investigate ITD findings", "on-call security report", "review FireWatch findings", "are these MSRCs really that severe", "should we fix this MSRC", "is this a real vulnerability", "can we mark this won't-fix", "what severity is this security bug", "security bug filed against us", "fix this finding", "remediate the MSRC", "execute the fix and open a PR", or any request to assess/right-size OR remediate a security vulnerability for Android Auth. +description: Triage and remediate MSRC/ITD security vulnerabilities for Android Authenticator and Broker. Use evidence-based codebase analysis to right-size filed severity, identify defense-in-depth, and produce per-finding/on-call/WBR reports. When explicitly asked, execute remediation end-to-end: implement the fix, add tests, and open a public-repo-safe PR. Use during on-call for [MSRC]/[ITD] IcMs, FireWatch findings, severity disputes, won't-fix decisions, or remediation requests. Triggers include triage MSRC, investigate ITD findings, classify vulnerabilities, review FireWatch, on-call security report, is this a real vulnerability, what severity is this security bug, fix/remediate this finding, or execute the fix and open a PR. Public-repo safety rules and required preflight, codebase-researcher investigation, adversarial verification, and private-workspace output requirements are defined in this skill. --- # Vulnerability Triage, Reporter & Remediation