From 221a44b18a37daf8fafd9cb65026f31e8ba6a139 Mon Sep 17 00:00:00 2001 From: Cesar Acosta Date: Thu, 17 Sep 2026 10:13:02 -0400 Subject: [PATCH 1/2] Fix vulnerability skill YAML description Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- .github/skills/vuln-triage-reporter/SKILL.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/skills/vuln-triage-reporter/SKILL.md b/.github/skills/vuln-triage-reporter/SKILL.md index a591bafb..8864cf99 100644 --- a/.github/skills/vuln-triage-reporter/SKILL.md +++ b/.github/skills/vuln-triage-reporter/SKILL.md @@ -1,6 +1,6 @@ --- name: vuln-triage-reporter -description: Triage and remediate MSRC/ITD security vulnerabilities for Android Authenticator and Broker. Use evidence-based codebase analysis to right-size filed severity, identify defense-in-depth, and produce per-finding/on-call/WBR reports. When explicitly asked, execute remediation end-to-end: implement the fix, add tests, and open a public-repo-safe PR. Use during on-call for [MSRC]/[ITD] IcMs, FireWatch findings, severity disputes, won't-fix decisions, or remediation requests. Triggers include triage MSRC, investigate ITD findings, classify vulnerabilities, review FireWatch, on-call security report, is this a real vulnerability, what severity is this security bug, fix/remediate this finding, or execute the fix and open a PR. Public-repo safety rules and required preflight, codebase-researcher investigation, adversarial verification, and private-workspace output requirements are defined in this skill. +description: "Triage and remediate MSRC/ITD security vulnerabilities for Android Authenticator and Broker. Use evidence-based codebase analysis to right-size filed severity, identify defense-in-depth, and produce per-finding/on-call/WBR reports. When explicitly asked, execute remediation end-to-end: implement the fix, add tests, and open a public-repo-safe PR. Use during on-call for [MSRC]/[ITD] IcMs, FireWatch findings, severity disputes, won't-fix decisions, or remediation requests. Triggers include triage MSRC, investigate ITD findings, classify vulnerabilities, review FireWatch, on-call security report, is this a real vulnerability, what severity is this security bug, fix/remediate this finding, or execute the fix and open a PR. Public-repo safety rules and required preflight, codebase-researcher investigation, adversarial verification, and private-workspace output requirements are defined in this skill." --- # Vulnerability Triage, Reporter & Remediation From 3f198b91a799fd0e7fb0bf099103b53b0f97fd2f Mon Sep 17 00:00:00 2001 From: Cesar Acosta Date: Thu, 17 Sep 2026 12:00:12 -0400 Subject: [PATCH 2/2] Align vulnerability skill frontmatter format Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --- .github/skills/vuln-triage-reporter/SKILL.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/skills/vuln-triage-reporter/SKILL.md b/.github/skills/vuln-triage-reporter/SKILL.md index 8864cf99..065db9c9 100644 --- a/.github/skills/vuln-triage-reporter/SKILL.md +++ b/.github/skills/vuln-triage-reporter/SKILL.md @@ -1,6 +1,6 @@ --- name: vuln-triage-reporter -description: "Triage and remediate MSRC/ITD security vulnerabilities for Android Authenticator and Broker. Use evidence-based codebase analysis to right-size filed severity, identify defense-in-depth, and produce per-finding/on-call/WBR reports. When explicitly asked, execute remediation end-to-end: implement the fix, add tests, and open a public-repo-safe PR. Use during on-call for [MSRC]/[ITD] IcMs, FireWatch findings, severity disputes, won't-fix decisions, or remediation requests. Triggers include triage MSRC, investigate ITD findings, classify vulnerabilities, review FireWatch, on-call security report, is this a real vulnerability, what severity is this security bug, fix/remediate this finding, or execute the fix and open a PR. Public-repo safety rules and required preflight, codebase-researcher investigation, adversarial verification, and private-workspace output requirements are defined in this skill." +description: Triage and remediate MSRC/ITD security vulnerabilities for Android Authenticator and Broker. Use evidence-based codebase analysis to right-size filed severity, identify defense-in-depth, and produce per-finding/on-call/WBR reports. When explicitly asked, execute remediation end-to-end, implement the fix, add tests, and open a public-repo-safe PR. Use during on-call for [MSRC]/[ITD] IcMs, FireWatch findings, severity disputes, won't-fix decisions, or remediation requests. Triggers include triage MSRC, investigate ITD findings, classify vulnerabilities, review FireWatch, on-call security report, is this a real vulnerability, what severity is this security bug, fix/remediate this finding, or execute the fix and open a PR. Public-repo safety rules and required preflight, codebase-researcher investigation, adversarial verification, and private-workspace output requirements are defined in this skill. --- # Vulnerability Triage, Reporter & Remediation