Prioritizes vulnerability findings from scanners, pentest reports, and bug bounty submissions by real-world exploitability rather than raw CVSS, assigning internal severity tiers with fix SLAs. Use when someone asks "which of these CVEs do we fix first", "triage this scanner report", "is this CVSS 9.8 actually critical for us", or is facing a wall of security findings and needs an actionable queue. Do NOT use for enumerating threats in a design that has not shipped - use threat-model-stride instead; for an active exploitation incident in production, use sev-triage; for reviewing the code itself, use secure-code-review.
Click to play with sound.
---
name: Vulnerability Triage
description: Prioritizes vulnerability findings from scanners, pentest reports, and bug bounty submissions by real-world exploitability rather than raw CVSS, assigning internal severity tiers with fix SLAs. Use when someone asks "which of these CVEs do we fix first", "triage this scanner report", "is this CVSS 9.8 actually critical for us", or is facing a wall of security findings and needs an actionable queue. Do NOT use for enumerating threats in a design that has not shipped - use threat-model-stride instead; for an active exploitation incident in production, use sev-triage; for reviewing the code itself, use secure-code-review.
---
# Vulnerability Triage
Vulnerability scanners produce volume, not priority. Effective triage cuts the list to an actionable queue engineers can work without burning out or quietly ignoring legitimate risk. The costly mistake this skill prevents is sorting by CVSS descending - which puts an unreachable library bug ahead of a trivially exploitable flaw on the public edge, and spends the team's scarce patching capacity in exactly the wrong order.
## Operating procedure
Grouping comes before scoring because one root-cause fix can close ten findings; scoring before grouping wastes ten triage passes on one bug.
### Step 1: Gather inputs
- The finding list with source (scanner, pentest, bounty) and reported CVSS per item.
- An exposure map: which services are internet-facing, which are internal-only, and what sits behind VPN, WAF, or MFA. If none exists, build a rough one from the load balancer and DNS config and label it a guess.
- Deployed versions and configuration for the affected components - the vulnerable config often is not the deployed config.
- Access to the CISA KEV catalog and exploit-availability data for the findings in question.
- The team's remediation capacity, so SLAs are commitments rather than fiction.
### Step 2: Deduplicate and group by root cause
Scanners report the same root cause through multiple symptoms. Group findings by shared cause (example: every XSS finding traced to the same template-engine misconfiguration) before scoring anything. One fix may close ten findings - identify these first for maximum leverage.
… load the full skill through Skill Me