open-sec
星标0
分支0
更新时间2026年7月3日 08:21
Triage findings; bridge OpenSec to OpenTicket.
安装
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
SKILL.md
readonly菜单
Triage findings; bridge OpenSec to OpenTicket.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Browser automation via Playwright MCP (official Microsoft headless browser)
Image generation and manipulation via MCP
PDF parsing and extraction via MCP
Autonomous tool discovery, evaluation, and integration for agent self-enhancement
Route OpenOS tasks to the correct product skill.
Enrich CRM contacts with LinkedIn and décideur data.
| name | open-sec |
| description | Triage findings; bridge OpenSec to OpenTicket. |
| version | 1.0.0 |
| author | OpenPro |
| license | MIT |
| platforms | ["linux","macos","windows"] |
| metadata | {"hermes":{"tags":["OpenSec","security","W3","findings","mesh"],"category":"open-ecosystem","related_skills":["open-ticket","open-contract","open-rec","open-brain"]}} |
Aggregates scanner findings → tickets → agent remediation (W3 mesh).
Not for whistleblower intake — use open-whistle (separate compliance boundary).
| Piece | Port | Role |
|---|---|---|
| OpenSec API | TBD | Findings CRUD, severity |
| OpenTicket bridge | CC-W3-* | Finding → ticket |
| OpenRec | rec_event | finding.* audit |
Query contracts: search_knowledge(domain=openos, query=CC-W3).
OPENSEC_API_URL when API is runningOPENTICKET_API_URL + MCP openticket for ticket bridgesecurity (PO-style ticket create)search_knowledge for W3 contract IDs and payload shapescreate_ticket with type: bug, AC = remediation steps, labels securitydeveloper → W4 (open-dev-workflow)| Severity | Action |
|---|---|
| critical/high | Ticket priority high; risk_level ≥ 3 on orchestrator goal |
| low/info | Batch or backlog per policy |
| False positive | Comment + close in OpenSec, no ticket |
finding_id in metadatacorrelation_id spans finding → ticket → fixfinding.triaged or equivalent emitted