Skip to content

Agentic software factory Part 10: security-advisory skill; reconcile SECURITY.md with the advisory backlog #4870

Description

@cliffhall

Part of the agentic software factory tracker #4858, Wave 3. Proposed as S9 in docs/agent-guidance-inception.md (PR #4861) §9, from #4859.

Depends on

After Part 2 (AGENTS.md), Part 3 (skills infrastructure) and Part 6 (#4866). The flow uses board-ops for the draft card and issue-create for public tracking.

Scope

  • Adapt the Inspector's security-advisory skill (§6 of the doc) for a single release line:
    • a draft [GHSA-…] card
    • the ownership check: is it this server, or the SDK underneath (route it to the SDK repo)?
    • accept or reject
    • the private fork and the fix
    • publish, then public tracking
  • Accepting and publishing stay human-only. Never automate or bulk-apply either.
  • Add the two narrow advisory exceptions to AGENTS.md's board rules, as the Inspector does:
    • a [GHSA-…] draft card is the one allowed non-issue card
    • accepting an advisory moves its (necessarily unmilestoned) draft from Incoming to Todo
  • Give the board audit the matching [GHSA- carve-out. Whichever of this issue and Part 8 (Agentic software factory Part 8: issue-triage skill and board audit, for community inflow #4868) lands second adds it.
  • Cover the reach classes: path traversal, symlink escape and Roots bypass (filesystem, git); SSRF and robots bypass (fetch).
  • Rewrite SECURITY.md. It tells reporters this repo isn't eligible, yet private vulnerability reporting is on, 61 advisories are in triage, and 6 have been published.
  • Plan how the backlog will be worked. The plan only, not the triage itself.

Acceptance criteria

  • The skill is merged with eval cases.
  • SECURITY.md is consistent with the repo settings.
  • An issue for triaging the backlog is filed.
  • If this is the first skill PR to merge, remove Part 3's empty-skills bootstrap allowance from verify:skills.

Branch

Targets v2/main. Closes #N won't auto-close an issue on a non-default branch, so close this one by hand on merge and move the card to Done.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

documentationImprovements or additions to documentationv2

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions