Agent skill

Security Advisory Rewriter

by obot-platform in obot-platform/obot

Turns a verbose, reporter-submitted obot security advisory into a short, deployer-facing writeup covering impact, affected versions and mitigation.

MITAuto-check passedSecurity

Install Security Advisory Rewriter

skills CLI
$ npx skills add obot-platform/obot --skill rewrite-security-advisory -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install obot-platform/obot rewrite-security-advisory --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/obot-platform/obot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/rewrite-security-advisory .claude/skills/rewrite-security-advisory && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rewrite-security-advisory
GitHub stars
1.1k
Token cost
~1.3k tokens
SKILL.md length
596 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Turns a verbose, reporter-submitted obot security advisory into a short, deployer-facing writeup covering impact, affected versions and mitigation.

  • Works in 5 steps: Fetch the advisory → Read the comments — they matter → Confirm the patched version → …
  • Rewriting a verbose security advisory into Obot's short user-facing format
  • SKILL.md covers 1. Fetch the advisory, 2. Read the comments — they…, 3. Confirm the patched version and 4. Write in Obot's format, plus 2 more sections
  • Calls gh; reaches github.com

What it does

Pulls the advisory through the authenticated GitHub API rather than the web URL, since a private draft advisory 404s for an unauthenticated fetch, retrieving the summary, full description, CVSS vector and score, affected range and credited reporters in one call. The advisory's comment thread is not exposed by either the REST or GraphQL API and the draft page also 404s for a plain fetch, so the user is asked to paste the comments directly, especially the team's own response, since that thread often reframes the issue, for example clarifying that a reported mechanism was actually a fail-safe.

Affected versions are always expressed as release tags rather than commit hashes, because deployers reason about releases, not commits; when the patched field is empty or recorded as a commit, the user is asked which release contains the fix so the affected range can be written as everything up to and including the last release before that fix.

The rewrite itself follows Obot's fixed section order: a plain-language title that reflects the real, team-confirmed impact rather than just copying a reporter's headline mechanism, followed by a short Summary, Am I affected, Details, Impact, Mitigation, Severity and Credits. The result is written to a markdown file at the repo root for the user to review and paste into the advisory editor themselves, never pushed to GitHub automatically.

When your agent uses it

  • Rewriting a verbose security advisory into Obot's short user-facing format
  • Simplifying a GHSA report so deployers can tell if they're affected
  • Expressing a security advisory's affected range as release tags instead of commit hashes
  • Incorporating the advisory's comment thread into the final writeup

Example prompts

  • “Rewrite GHSA-m3cp-8xr4-pq29 into our short advisory format.”
  • “Simplify this advisory for deployers — I'll paste the comment thread now.”
  • “Reformat this draft advisory and express the affected range as release tags.”

Requirements

  • The gh CLI, authenticated against the obot repository

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Fetch the advisory
  2. Read the comments — they matter
  3. Confirm the patched version
  4. Write in Obot's format
  5. Write the file and present it

What it can do on your machine

Read from SKILL.md and the folder at commit 43a9522. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Advisory Rewriter loads about 1.3k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 596 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from obot-platform/obot at commit 43a9522, republished under its MIT licence (© obot-platform). 596 words, ~1,267 tokens.

Download SKILL.mdSave it as .claude/skills/rewrite-security-advisory/SKILL.md (or your agent's skills folder).
name
rewrite-security-advisory
description
Rewrite an obot GitHub security advisory into Obot's short, user-facing format (Summary / Am I affected? / Details / Impact / Mitigation / Severity / Credits). Use when the user gives a GHSA id or advisory URL and asks to rewrite, simplify, or reformat it. Writes the result to a markdown file in the repo root for the user to paste into the advisory editor.

Rewrite Security Advisory

Take a verbose, reporter-submitted obot security advisory and rewrite it into Obot's concise, user-facing format. The goal is a short writeup a deployer can read and immediately know whether they're affected and what to do — not a reproduction of the researcher's full report.

Output is a markdown file at the repo root named <GHSA-id>.md. The user reviews it and pastes it into the GitHub advisory editor themselves. Do not push it to GitHub or modify the live advisory unless explicitly asked.

1. Fetch the advisory

The advisory is usually a private draft, so the web URL 404s for WebFetch. Pull it via the authenticated API instead:

bash
gh api repos/obot-platform/obot/security-advisories/<GHSA-id> --jq '{summary, description, severity, cvss: .cvss.vector_string, score: .cvss.score, vuln_range: .vulnerabilities[0].vulnerable_version_range, patched: .vulnerabilities[0].patched_versions, credits: [.credits_detailed[].user.login], cwes: [.cwes[].cwe_id]}'

This gives you the title, the reporter's full description (Summary/Details/PoC/Impact), CVSS vector + score, affected range, and the credited reporters.

2. Read the comments — they matter

The advisory's comment thread is NOT exposed by the GitHub API (REST or GraphQL), and the web page 404s for WebFetch on drafts. Ask the user to paste the comments, especially the obot team's response (often from the lead eng). The comments frequently change the framing — e.g. clarifying that the reporter's headline mechanism was actually a fail-safe and the real fix was something else, or noting which parts were disputed. Do not finalize the rewrite without them.

3. Confirm the patched version

The advisory's patched field is often empty and vuln_range may be recorded as a commit hash. Always express versions as release tags, never commit hashes (users reason about releases, not commits). Ask the user which release contains the fix if it isn't obvious; the affected range is then <= <last release before the fix> (e.g. fixed in v0.23.0 → affected <= v0.22.1).

Show full SKILL.md (321 more words)Show less

4. Write in Obot's format

Use exactly these sections, in this order. Keep it tight — a few sentences per section. This is a summary for deployers, not the researcher's report.

  • Title (# ...): a plain-language description of the actual issue and its real impact. Don't just copy the reporter's title if it leads with a mechanism that the team's comments downgraded (e.g. don't headline "audience confusion" if that turned out to be a fail-safe). Keep the (incomplete fix of GHSA-...) style suffix when the advisory metadata has one.
  • ## Summary: 2-4 sentences. What the flaw is and what an attacker could do.
  • ## Am I affected?: the affected release range (<= vX.Y.Z) plus the preconditions (config flags, required role, required user interaction). Note when a configuration makes it a non-issue.
  • ## Details: one paragraph on the root cause, written generically. Do NOT cite internal function names, file paths, or line numbers — those are implementation details that don't belong in a user-facing advisory. Describe behavior ("the authorizer default-allows unrecognized top-level paths"), not symbols (checkUI). Mention the relationship to prior advisories if any.
  • ## Impact: worst-case consequence in plain terms. Mirror what the user has liked before: state the worst case, then clarify what is NOT exposed/possible (e.g. "No credential values are exposed").
  • ## Mitigation: "Upgrade to vX.Y.Z or later, which ..." — describe what the fix does at a behavioral level (again, no symbol/commit references). If the team's comments listed multiple protections, summarize them.
  • ## Severity: CVSS v3.1 Score: **<score>/10 (<Severity>)** — \<vector>``
  • ## Credits: the fixed boilerplate below.
Credits boilerplate
The Obot team would like to thank [@<reporter>](https://github.com/<reporter>) for responsibly disclosing this issue in accordance with our [security policy](https://github.com/obot-platform/obot/?tab=security-ov-file).

If there are multiple reporters, thank each ([@a](...) and [@b](...)).

5. Write the file and present it

Write to <repo-root>/<GHSA-id>.md, then paste the full rendered text back in the chat so the user can review inline. Flag anything you assumed (patched version, title change) so they can correct it.

Reference: a finished example

See the advisory writeups already in the repo root (e.g. GHSA-jgh3-fggc-mcpm.md, GHSA-pr6h-vr44-xq8j.md, GHSA-xwmw-prc4-v3cr.md) for the exact tone and length to match.

© obot-platform, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/rewrite-security-advisory of obot-platform/obot.

Open the folder on GitHubat commit 43a9522

Compare with similar skills

Security Advisory Rewriter next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Advisory Rewriter compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Advisory Rewriter this skillobot-platform/obot1.1k—~1.3kAutomated safety check: PassMIT
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence
Symfony Security Reviewsymfony/symfony31k—~2.9kAutomated safety check: PassMIT
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
Slowmist Agent Securityslowmist/slowmist-agent-security508—~1.4kAutomated safety check: PassMIT
SkepticRaoFoundation/subtensor389—~660Automated safety check: PassApache-2.0

Similar skills

  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Review a change (a PR, the current branch diff, or a set of files) or audit a component or the whole tree for missing or incorrect security hardening.

    31k GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check passed
  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Slowmist Agent Security

    slowmist/slowmist-agent-security

    Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security.

    508 GitHub stars~1.4k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Skeptic

    RaoFoundation/subtensor

    Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

    389 GitHub stars~660 tokensUpdated today
    SecurityAuto-check passed
  • Kedro Plugins Security Review

    kedro-org/kedro-plugins

    Run a security scan on the kedro-plugins codebase or a pull request.

    119 GitHub stars~3.1k tokensUpdated yesterday
    SecurityAuto-check passed

More from obot-platform/obot

  • Obot Release Notes Drafter

    obot-platform/obot

    Drafts release notes for an upcoming Obot minor release and saves them as an unpublished GitHub draft release, never tagging or publishing.

    1.1k GitHub stars~4.5k tokensUpdated today
    Auto-check passed
  • Release Blog Drafter

    obot-platform/obot

    Drafts a release announcement blog post for an obot release as a Markdown file, with an optional WordPress draft through MCP and no live publishing without confirmation.

    1.1k GitHub stars~4.6k tokensUpdated today
    Auto-check passed

Works with

Questions about Security Advisory Rewriter

What does Security Advisory Rewriter do?

Turns a verbose, reporter-submitted obot security advisory into a short, deployer-facing writeup covering impact, affected versions and mitigation. Pulls the advisory through the authenticated GitHub API rather than the web URL, since a private draft advisory 404s for an unauthenticated fetch, retrieving the summary, full description, CVSS vector and score, affected range and credited reporters in one call. The advisory's comment thread is not exposed by either the REST or GraphQL API and the draft page also 404s for a plain fetch, so the user is asked to paste the comments directly, especially the team's own response, since that thread often reframes the issue, for example clarifying that a reported mechanism was actually a fail-safe.

When should I use Security Advisory Rewriter?

Security Advisory Rewriter fits situations like: rewriting a verbose security advisory into Obot's short user-facing format; simplifying a GHSA report so deployers can tell if they're affected; expressing a security advisory's affected range as release tags instead of commit hashes; incorporating the advisory's comment thread into the final writeup.

How do I install Security Advisory Rewriter in Claude Code?

Run `npx skills add obot-platform/obot --skill rewrite-security-advisory -a claude-code`. Or copy the skill folder (.claude/skills/rewrite-security-advisory in obot-platform/obot) into .claude/skills/rewrite-security-advisory in your project. Claude Code loads it when a task matches its description.

How do I install Security Advisory Rewriter in Codex?

Run `npx skills add obot-platform/obot --skill rewrite-security-advisory -a codex`. Or copy the skill folder (.claude/skills/rewrite-security-advisory in obot-platform/obot) into .agents/skills/rewrite-security-advisory in your project. Codex loads it when a task matches its description.

Can I use Security Advisory Rewriter in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add obot-platform/obot --skill rewrite-security-advisory -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rewrite-security-advisory, .gemini/skills/rewrite-security-advisory, .github/skills/rewrite-security-advisory and .opencode/skills/rewrite-security-advisory in your project.

What does Security Advisory Rewriter need to run?

Going by SKILL.md and its folder, Security Advisory Rewriter needs the command-line tools its instructions call (gh). Our summary lists: The gh CLI, authenticated against the obot repository.

Does Security Advisory Rewriter access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Security Advisory Rewriter safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Advisory Rewriter use?

Security Advisory Rewriter is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Advisory Rewriter use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Advisory Rewriter?

Skills that share tags, products or a category with Security Advisory Rewriter: Kedro Security Review (kedro-org/kedro, 11k stars), Symfony Security Review (symfony/symfony, 31k stars), Pyspector Security Audit (ParzivalHack/PySpector, 151 stars) and Slowmist Agent Security (slowmist/slowmist-agent-security, 508 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Advisory Rewriter?

obot-platform (a GitHub organization) maintains it in obot-platform/obot, which has 1,095 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 8, 2026.

Source: obot-platform/obot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.