agentsclimarketplace

Vuln triage

Skill runxhq/runx/skills/vuln-triage

the governed runtime for agent skill workflows, off the leash but on the record

Install
npx -y skills add runxhq/runx --skill vuln-triage

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

What its author says it does

Copied from the file, not written here

Turn verified exact-version vulnerability evidence into bounded remediation and advisory packets without inventing exposure or claiming publication.

SKILL.md

4.2 KB, as published. Nobody here has run it

Vulnerability Triage

Translate verified vulnerability identities into an operator decision: what is affected, what exposure is established or unknown, how urgent the response is, what remediation is justified, and whether an advisory should be prepared. This is the judgment layer of the security chain, not another scanner.

Use cve-audit first to prove the exact dependency versions and OSV advisory identities. vuln-triage then reasons about operational exposure and priority without changing those facts. An advisory draft can later move to vuln-disclosure, which owns the publication boundary.

Runners

scan accepts the exact CVE audit result, its independent verification packet, and the sealed receipt reference. Every assessment remains bound to dependency, installed version, and advisory id. Judgment may classify priority, distinguish established from unknown exposure, and propose remediation, but confidence must describe only that judgment—the CVE identity is already verified.

advisory accepts only a validated triage packet. It prepares precise wording for the admitted advisory ids and returns a review packet with publication_status: not_published. It does not call a repository, advisory, email, or social provider.

Operating standard

  • Keep verified identity, exposure judgment, and remediation confidence separate.
  • State affected versions, preconditions, impact, and mitigations precisely.
  • Treat unknown exposure as a reason to investigate or escalate, not as proof of exploitation or safety.
  • Avoid alarmism and vague severity labels. Explain the operational reason for priority and the evidence still missing.
  • Preserve every verified finding. Adding a new CVE or silently omitting one invalidates the packet.

The finalized triage packet adds deterministic escalation criteria for high priority, unknown exposure, and low-confidence judgments. A clean audit returns no_verified_findings; it does not certify the target secure.

Inputs and result

The scan runner consumes the target-bound audit result, verification result, and receipt reference plus any bounded operational context needed to assess exposure. It returns one assessment per verified finding, a remediation plan, operator summary, evidence binding, confidence, and escalation criteria.

The advisory runner consumes that validated triage packet and returns a title, summary, body, exact affected advisory ids, and disclosure checklist. That artifact is a draft for review, not external publication.

Stop conditions

  • Return needs_verified_evidence when the audit, independent verification, or receipt reference is missing or invalid.
  • Return needs_more_evidence when an assessment adds or omits a finding, changes a version or advisory identity, or lacks bounded confidence.
  • Reject advisory wording that cites an unknown id or states exposure the triage packet did not establish.
  • Never mutate the target, query another provider, repair dependencies, or claim disclosure.

Example

An audit proves that exact version x.y.z matches one OSV advisory. Triage may find that the vulnerable code path is reachable, assign high priority, and recommend a tested upgrade; or it may record exposure as unknown and request a named runtime trace. It cannot add a related CVE from memory. The advisory draft may describe only the admitted finding and the remediation evidence present in the packet.

Agent task contracts

vuln-triage-assess

Assess only the verified finding identities. Return one assessment per exact dependency, version, and advisory id plus the remediation plan and operator summary. State high, medium, or low confidence for exposure and priority judgment. Do not add CVEs, versions, provider claims, or publication claims.

vuln-triage-advisory

Draft a precise advisory using only the admitted advisory ids, target, remediation, and evidence binding. Return the affected ids and disclosure checklist with the draft. Do not claim publication, provider execution, or exposure that the triage packet does not establish.

Gives 0 of the 12 instructions most debug triage skills give

Counted across 839 of the 1,149 authors here whose files we hold, read 2026-08-06

  • investigate root cause before proposing any fixin 102 of 839, across 65 files
  • read error messages completelyin 90 of 839, across 48 files
  • create a failing test case before fixingin 84 of 839, across 44 files
  • reproduce the issue consistentlyin 82 of 839, across 40 files
  • change one variable at a timein 82 of 839, across 42 files
  • check recent changesin 74 of 839, across 35 files
  • write the regression test before fixingin 74 of 839, across 36 files
  • fix the root cause not the symptomin 60 of 839, across 43 files
  • implement a single fix at a timein 59 of 839, across 20 files
  • trace data flow backward to the sourcein 50 of 839, across 20 files
  • remove all debug instrumentationin 49 of 839, across 13 files
  • form a single hypothesisin 48 of 839, across 18 files

Said here and by no other author read

  • run cve-audit first to verify versions
  • separate verified identity from exposure judgment
  • state affected versions and impact precisely
  • treat unknown exposure as a reason to investigate
  • preserve every verified finding
  • add deterministic escalation criteria to triage packets

Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.