Cyberowlai
karimhabush/cyberowl
Check if recent cybersecurity alerts from 10 international CERTs affect your current project.
Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.
$ npx skills add warpdotdev/warp --skill triage-vulnerabilities -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install warpdotdev/warp triage-vulnerabilities --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/warpdotdev/warp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/resources/channel-gated-skills/dogfood/triage-vulnerabilities .claude/skills/triage-vulnerabilities && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "triage-vulnerabilities" agent skill from https://github.com/warpdotdev/warp/tree/master/resources/channel-gated-skills/dogfood/triage-vulnerabilities into .claude/skills/triage-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-vulnerabilities", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/warpdotdev/warp/tree/master/resources/channel-gated-skills/dogfood/triage-vulnerabilitiesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add warpdotdev/warp --skill triage-vulnerabilities -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install warpdotdev/warp triage-vulnerabilities --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/warpdotdev/warp.git skills-src && mkdir -p .agents/skills && cp -r skills-src/resources/channel-gated-skills/dogfood/triage-vulnerabilities .agents/skills/triage-vulnerabilities && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "triage-vulnerabilities" agent skill from https://github.com/warpdotdev/warp/tree/master/resources/channel-gated-skills/dogfood/triage-vulnerabilities into .agents/skills/triage-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-vulnerabilities", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add warpdotdev/warp --skill triage-vulnerabilities -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install warpdotdev/warp triage-vulnerabilities --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/warpdotdev/warp.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/resources/channel-gated-skills/dogfood/triage-vulnerabilities .cursor/skills/triage-vulnerabilities && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "triage-vulnerabilities" agent skill from https://github.com/warpdotdev/warp/tree/master/resources/channel-gated-skills/dogfood/triage-vulnerabilities into .cursor/skills/triage-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-vulnerabilities", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/warpdotdev/warp.git --path resources/channel-gated-skills/dogfood/triage-vulnerabilities--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add warpdotdev/warp --skill triage-vulnerabilities -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install warpdotdev/warp triage-vulnerabilities --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/warpdotdev/warp.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/resources/channel-gated-skills/dogfood/triage-vulnerabilities .gemini/skills/triage-vulnerabilities && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "triage-vulnerabilities" agent skill from https://github.com/warpdotdev/warp/tree/master/resources/channel-gated-skills/dogfood/triage-vulnerabilities into .gemini/skills/triage-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-vulnerabilities", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install warpdotdev/warp triage-vulnerabilitiesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add warpdotdev/warp --skill triage-vulnerabilities -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/warpdotdev/warp.git skills-src && mkdir -p .github/skills && cp -r skills-src/resources/channel-gated-skills/dogfood/triage-vulnerabilities .github/skills/triage-vulnerabilities && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "triage-vulnerabilities" agent skill from https://github.com/warpdotdev/warp/tree/master/resources/channel-gated-skills/dogfood/triage-vulnerabilities into .github/skills/triage-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-vulnerabilities", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add warpdotdev/warp --skill triage-vulnerabilities -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install warpdotdev/warp triage-vulnerabilities --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/warpdotdev/warp.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/resources/channel-gated-skills/dogfood/triage-vulnerabilities .opencode/skills/triage-vulnerabilities && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "triage-vulnerabilities" agent skill from https://github.com/warpdotdev/warp/tree/master/resources/channel-gated-skills/dogfood/triage-vulnerabilities into .opencode/skills/triage-vulnerabilities/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "triage-vulnerabilities", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
triage-vulnerabilitiesGathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.
The skill covers four sources. Dependabot alerts come from the GitHub API for a named set of repos, internal service images are scanned through GCP Artifact Registry in production and staging projects, public images under the warpdotdev org on Docker Hub are checked with Docker Scout for critical and high CVEs, and Linear issues carrying the Security label capture findings other tools do not report. Only the latest tagged image in each registry repo is scanned, since older ones are not actionable.
The workflow starts by gathering findings, using a TODO per source and writing results to temporary TSV files such as dependabot_alerts.tsv, gcp_vulns.tsv and scout_vulns.tsv with CVE, package, severity and fix details. A caveat is that Linear issues are not closed automatically when a fix lands elsewhere, so duplicates across sources are expected. The excerpt ends before the later triage and remediation steps.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit f571865. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
dockerghgcloudFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comnvd.nist.govlinear.appFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Warp Vulnerability Triage loads about 2.1k tokens when it runs. Until then it costs about 87 tokens; SKILL.md has 758 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from warpdotdev/warp at commit f571865, republished under its AGPL-3.0 licence (© warpdotdev). 758 words, ~2,071 tokens.
.claude/skills/triage-vulnerabilities/SKILL.md (or your agent's skills folder).Triage and remediate security vulnerabilities across four sources: GitHub Dependabot, GCP container registry scanning, Docker Scout, and Linear security issues.
Repos with Dependabot enabled: warp-internal, warp-server, warp-terraform, session-sharing-server.
Fetch open alerts:
# All open alerts for a repo (returns JSON array)
gh api /repos/warpdotdev/<repo>/dependabot/alerts?state=open
# Useful fields per alert:
# .number, .state, .html_url
# .dependency.package.name, .dependency.package.ecosystem, .dependency.manifest_path
# .security_advisory.cve_id, .security_advisory.summary, .security_advisory.severity
# .security_vulnerability.first_patched_version.identifier
# Summary view: CVE/GHSA, package, severity, fix version, manifest
gh api /repos/warpdotdev/<repo>/dependabot/alerts?state=open \
--jq '.[] | [.number, .security_advisory.cve_id // .security_advisory.ghsa_id, .dependency.package.name, .security_advisory.severity, (.security_vulnerability.first_patched_version.identifier // "no fix"), .dependency.manifest_path] | @tsv'Internal service images in us-east4 across two projects:
astral-field-294621): warp-server, warp-server-jobs, warp-server-migrations, session-sharing-server, pgbouncer-rtcwarp-server-staging): same repos plus cloud-run-source-deployScan steps:
# List images in a repo (get digest for vulnerability query)
gcloud artifacts docker images list \
us-east4-docker.pkg.dev/<project>/<repo> \
--include-tags --sort-by=~create_time --limit=5
# List vulnerabilities for a specific image
gcloud artifacts vulnerabilities list \
"us-east4-docker.pkg.dev/<project>/<repo>/<image>@sha256:<digest>" \
--format=jsonOnly scan the latest (most recently tagged) image per repo — older images are not actionable.
Public images on Docker Hub under warpdotdev/ org. Currently enrolled repos: dev-base (and potentially others — check with docker scout repo list --org warpdotdev).
# List CVEs (critical and high only)
docker scout cves warpdotdev/<image> --only-severity critical,high
# Check for base image update recommendations
docker scout recommendations warpdotdev/<image>Linear issues with the Security label track vulnerabilities that may not be auto-reported by other tools (e.g., internal findings, manual triages, or organizational security concerns). Note that Linear issues are not automatically closed when vulnerabilities are fixed elsewhere (e.g., via Dependabot PRs), so there may be duplicates across sources.
Find open security issues:
# Use the Linear MCP to search for issues with Security label
# Example query structure (use Linear MCP tool call):
# - Search for issues with label: "Security"
# - Filter for state: "Backlog", "Todo", "In Progress" (exclude "Done", "Cancelled")
# - Return issue number, title, URL, and current status
# Useful fields per issue:
# - Issue ID/number (e.g., CLD-2726)
# - Title (usually contains CVE ID, e.g., "warp-server-GHSA-8r9q-7v3j-jr4g")
# - URL (e.g., https://linear.app/warpdotdev/issue/CLD-2726/...)
# - Status (Backlog, Todo, In Progress, Done, Cancelled)
# - Description (contains CVE details and affected package info)IMPORTANT: Use TODOs to track each source.
Query all four sources. Write results to temporary files for reference:
dependabot_alerts.tsv — CVE, package, severity, repo, fix versiongcp_vulns.tsv — CVE, severity, package, image, fix availablescout_vulns.tsv — CVE, severity, package, imagelinear_security.tsv — Issue ID, CVE/Title, status, URLThe same CVE may appear across multiple sources (e.g. a base image vuln reported by both GCP scanning and Docker Scout, or a Dependabot alert duplicated as a Linear issue). Group by CVE ID and note all affected sources/images. When a Linear issue duplicates a vulnerability that's already being tracked (e.g., via Dependabot), note this and consider it resolved once the underlying fix is applied.
IMPORTANT: Add a TODO for each unique vulnerability.
Make sure that you've checked ALL sources and deduplicated vulnerabilities before remediating any.
For each unique vulnerability, starting with critical severity first:
security_vulnerability.first_patched_versionFIX_AVAILABLE fielddocker scout recommendations for base image updateshttps://nvd.nist.gov/vuln/detail/<CVE-ID>https://github.com/advisorieshttps://github.com/GoogleContainerTools/distroless/issuesIf no upstream fix exists, report the vulnerability and move on. Do NOT attempt to deactivate/dismiss alerts — only a human can do this.
Fixes fall into three categories:
Dependabot auto-fix available: The simplest case. Check if Dependabot has already created a PR:
gh pr list --repo warpdotdev/<repo> --author app/dependabot --state open --json title,urlIf a PR exists, review and approve it. If not, the fix may require manual intervention.
Dependency update: When Dependabot can't auto-fix (e.g. major version bump needed), update the dependency manually in the appropriate manifest (Cargo.toml, go.mod, package.json, etc.), run tests, and submit a PR.
regex to pull in a fixed version of aho-corasick).Infrastructure change: For container image vulnerabilities, the fix may involve:
Dockerfile)session-sharing-server)When submitting a fix PR, include:
create-pr skill for PR creationIf a vulnerability has no available fix (e.g. waiting on distroless base image update), report:
Suggest that a human deactivate the alert until a fix is available. NEVER dismiss or deactivate alerts yourself.
astral-field-294621), then staging© warpdotdev, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in resources/channel-gated-skills/dogfood/triage-vulnerabilities of warpdotdev/warp.
Open the folder on GitHubat commit f571865
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in warpdotdev/warp, which our catalogue first saw on October 7, 2026.
Warp Vulnerability Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Warp Vulnerability Triage this skillwarpdotdev/warp | 65k | 1 repos | ~2.1k | Automated safety check: Pass | AGPL-3.0 | |
| Cyberowlaikarimhabush/cyberowl | 263 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Container Scanning with GrypeAgentSecOps/SecOpsAgentKit | 219 | 1 repos | ~2.5k | Automated safety check: Pass | Custom licence | |
| Container Securityhardw00t/ai-security-arsenal | 104 | — | ~2.8k | Automated safety check: Pass | None | |
| Sca TrivyAgentSecOps/SecOpsAgentKit | 219 | 2 repos | ~3.7k | Automated safety check: Pass | Custom licence | |
| Container Security Hardeningsickn33/agentic-awesome-skills | 47k | 1 repos | ~1k | Automated safety check: Notes | MIT |
karimhabush/cyberowl
Check if recent cybersecurity alerts from 10 international CERTs affect your current project.
AgentSecOps/SecOpsAgentKit
Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds.
hardw00t/ai-security-arsenal
Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
sickn33/agentic-awesome-skills
Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.
mukul975/Anthropic-Cybersecurity-Skills
Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…
warpdotdev/warp
Builds or updates a design system in Figma from a codebase in ordered phases: discovery, variables and tokens, components, theming and documentation, with checkpoints.
warpdotdev/warp
Required groundwork before any use_figma call: the rules and reference files for running JavaScript in a Figma file through the Plugin API without common failures.
warpdotdev/warp
Authors and edits file-based Warp software factory definitions rooted at factory.yaml, covering agents, automations, scorers and webhooks, and validates them before a pull request.
warpdotdev/warp
Turns a Figma frame or component into production code that matches the design, using the Figma MCP server and the project's own design system.
warpdotdev/warp
Migrates the compatible subset of settings and global file-based MCP servers from the Warp desktop app into Warp Agent CLI without exposing credentials or state.
warpdotdev/warp
Creates project-specific design system rules from your codebase so coding agents implement Figma designs with your components, naming and tokens.
Works with
Categories
Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images. The skill covers four sources. Dependabot alerts come from the GitHub API for a named set of repos, internal service images are scanned through GCP Artifact Registry in production and staging projects, public images under the warpdotdev org on Docker Hub are checked with Docker Scout for critical and high CVEs, and Linear issues carrying the Security label capture findings other tools do not report.
Warp Vulnerability Triage fits situations like: checking all open Dependabot alerts across the organization's repos; triaging CVEs found in container images; updating base images or dependencies to clear vulnerabilities; reconciling Linear security tickets with scanner findings.
Run `npx skills add warpdotdev/warp --skill triage-vulnerabilities -a claude-code`. Or copy the skill folder (resources/channel-gated-skills/dogfood/triage-vulnerabilities in warpdotdev/warp) into .claude/skills/triage-vulnerabilities in your project. Claude Code loads it when a task matches its description.
Run `npx skills add warpdotdev/warp --skill triage-vulnerabilities -a codex`. Or copy the skill folder (resources/channel-gated-skills/dogfood/triage-vulnerabilities in warpdotdev/warp) into .agents/skills/triage-vulnerabilities in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add warpdotdev/warp --skill triage-vulnerabilities -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/triage-vulnerabilities, .gemini/skills/triage-vulnerabilities, .github/skills/triage-vulnerabilities and .opencode/skills/triage-vulnerabilities in your project.
Going by SKILL.md and its folder, Warp Vulnerability Triage needs the command-line tools its instructions call (docker, gh and gcloud). Our summary lists: GitHub CLI access to Dependabot alerts; gcloud with access to Artifact Registry; Docker Scout; A Linear MCP connection.
SKILL.md names 3 domains. In commands or code: github.com, nvd.nist.gov and linear.app; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Warp Vulnerability Triage is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Warp Vulnerability Triage: Cyberowlai (karimhabush/cyberowl, 263 stars), Container Scanning with Grype (AgentSecOps/SecOpsAgentKit, 219 stars), Container Security (hardw00t/ai-security-arsenal, 104 stars) and Sca Trivy (AgentSecOps/SecOpsAgentKit, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
warpdotdev (a GitHub organization) maintains it in warpdotdev/warp, which has 65,380 GitHub stars. The repository holds 46 skills in this directory. The repository was last updated on October 7, 2026.
Source: warpdotdev/warp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.