Skip to main content

grav-inbox-triage

Use when Andy asks to clean out / triage / process his GitHub notifications inbox for the Grav org (getgrav/*), or says "do my inbox", "triage my notifications", "review my github inbox", or runs his weekly security-advisory batch. Covers the full workflow: pull the inbox via `gh` and group it (security advisories, bug issues, PRs, other); fan out read-only agents to validate each item against the real checked-out repos under ~/Projects/grav; for security advisories — match against the KNOWN BUG-FAMILY REGISTER first (scope-cap, detectXss, Host-header, timing, admin-file-manager traversal — these are pre-decided and close in minutes), map the notification to its GHSA record, CONFIRM it against code, CHECK IF ALREADY FIXED on develop/tags (most reports are against an old snapshot), then assign one of THREE dispositions — not-a-vulnerability / fix-quietly-no-advisory / publish-advisory — using Grav's SECURITY.md trust-boundary rubric (NOT the reporter's CVSS), and confirm the correct fix repo (advisories filed

Jump to install

Source facts

Repository
getgrav/grav-skills
Last source activity
August 21, 2026 at 10:16
Detected SKILL.md language
English
Stars
4
Forks
1

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.