一键导入
github-security-reporting
Use when you need a consistent run summary across remediation units, outcomes, and remaining blockers.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Use when you need a consistent run summary across remediation units, outcomes, and remaining blockers.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Use when asked to reduce GitHub security alerts across all active repositories in one selected profile.
Use when asked to remediate GitHub Dependabot alerts across the repositories defined in one selected profile.
Use when a remediation diff already exists and you need a policy decision for merged, opened_pr, blocked, skipped, or failed.
Use when you need to validate a selected profile, inspect the runtime contract, and map repository entries to local clone paths before any remediation work starts.
Use when asked to remediate allowlisted deterministic GitHub code-scanning alerts across the repositories defined in one selected profile.
Use when asked to inspect GitHub code-scanning alerts across the repositories defined in one selected profile.
| name | github-security-reporting |
| description | Use when you need a consistent run summary across remediation units, outcomes, and remaining blockers. |
Use this skill at the end of a run or when summarizing current remediation status.
Read these files first:
../../docs/operating-model.md../../docs/reporting-model.mdprofile.yamlThis skill does not patch repositories. It summarizes what happened.
code_scanning remediation unit.secret_scanning remediation unit.secret_scanning remediation unit.secret_scanning remediation unit.platform_constraints when they explain why a target is manual_only, review-required, or blocked by environment/runtime assumptions.blocked, skipped, and failed outcome.{clone_root}/.github-security-agent/runs/{profile_id}/{iso8601_utc}.jsonl and overwrite the companion latest.json summary.target_id in every per-unit summary.merged unless the merge actually completed via the GitHub merge API.../../docs/operating-model.md. Do not invent new reason codes.Return:
target_id