open-sec
Triage findings; bridge OpenSec to OpenTicket.
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Menu
Triage findings; bridge OpenSec to OpenTicket.
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Based on SOC occupation classification
Browser automation via Playwright MCP (official Microsoft headless browser)
Image generation and manipulation via MCP
PDF parsing and extraction via MCP
Autonomous tool discovery, evaluation, and integration for agent self-enhancement
Route OpenOS tasks to the correct product skill.
Enrich CRM contacts with LinkedIn and décideur data.
| name | open-sec |
| description | Triage findings; bridge OpenSec to OpenTicket. |
| version | 1.0.0 |
| author | OpenPro |
| license | MIT |
| platforms | ["linux","macos","windows"] |
| metadata | {"hermes":{"tags":["OpenSec","security","W3","findings","mesh"],"category":"open-ecosystem","related_skills":["open-ticket","open-contract","open-rec","open-brain"]}} |
Aggregates scanner findings → tickets → agent remediation (W3 mesh).
Not for whistleblower intake — use open-whistle (separate compliance boundary).
| Piece | Port | Role |
|---|---|---|
| OpenSec API | TBD | Findings CRUD, severity |
| OpenTicket bridge | CC-W3-* | Finding → ticket |
| OpenRec | rec_event | finding.* audit |
Query contracts: search_knowledge(domain=openos, query=CC-W3).
OPENSEC_API_URL when API is runningOPENTICKET_API_URL + MCP openticket for ticket bridgesecurity (PO-style ticket create)search_knowledge for W3 contract IDs and payload shapescreate_ticket with type: bug, AC = remediation steps, labels securitydeveloper → W4 (open-dev-workflow)| Severity | Action |
|---|---|
| critical/high | Ticket priority high; risk_level ≥ 3 on orchestrator goal |
| low/info | Batch or backlog per policy |
| False positive | Comment + close in OpenSec, no ticket |
finding_id in metadatacorrelation_id spans finding → ticket → fixfinding.triaged or equivalent emitted