Skip to main content

grav-inbox-triage

Use when Andy asks to clean out / triage / process his GitHub notifications inbox for the Grav org (getgrav/*), or says "do my inbox", "triage my notifications", "review my github inbox", or runs his weekly security-advisory batch. Covers the full workflow: pull the inbox via `gh` and group it (security advisories, bug issues, PRs, other); fan out read-only agents to validate each item against the real checked-out repos under ~/Projects/grav; for security advisories — match against the KNOWN BUG-FAMILY REGISTER first (scope-cap, detectXss, Host-header, timing, admin-file-manager traversal — these are pre-decided and close in minutes), map the notification to its GHSA record, CONFIRM it against code, CHECK IF ALREADY FIXED on develop/tags (most reports are against an old snapshot), then assign one of THREE dispositions — not-a-vulnerability / fix-quietly-no-advisory / publish-advisory — using Grav's SECURITY.md trust-boundary rubric (NOT the reporter's CVSS), and confirm the correct fix repo (advisories filed

跳到安装

来源信息

仓库
getgrav/grav-skills
最近来源活动
2026年8月21日 10:16
检测到的 SKILL.md 语言
英语
星标
4
分支
1

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。