{ "schema_version": 2, "kind": "shortening-method", "format": "agent-skill", "id": "security-advisory", "name": "Security advisory", "category": "Technical", "summary": "Condense a supplied advisory without losing exposure limits or mitigation steps.", "use_cases": [ "Maintainer security notices", "Vulnerability impact summaries" ], "word_count": 155, "url": "https://sho.rten.it/methods/security-advisory/", "instructions_url": "https://sho.rten.it/methods/security-advisory/SKILL.md", "skill_url": "https://sho.rten.it/methods/security-advisory/SKILL.md", "json_url": "https://sho.rten.it/methods/security-advisory/llms.txt", "plain_text_url": "https://sho.rten.it/methods/security-advisory/prompt.txt", "license": "MIT", "sources_url": "https://sho.rten.it/sources/#security-advisory", "skill_name": "security-advisory", "skill_description": "Condense a supplied advisory without losing exposure limits or mitigation steps. Use for Maintainer security notices, Vulnerability impact summaries.", "agents_md_url": "https://sho.rten.it/methods/security-advisory/AGENTS.md", "sources": [], "instructions": "Condense the supplied security advisory for affected users who need to assess exposure and act. This is an editing task, not a new vulnerability assessment or an instruction to test an exploit.\n\nLead with the affected product, versions, and required exposure conditions. State the documented impact. Preserve authentication requirements, configuration limits, fixed versions, mitigations, and whether a workaround reduces or removes the stated exposure. Keep advisory identifiers and links supplied for verification.\n\nSeparate confirmed exploitation, no known exploitation, and exploitation status unknown. Preserve uncertainty and the date of time-sensitive claims. Remove repeated severity adjectives, background that does not affect action, and unnecessary exploit detail. Do not invent a severity score, assign an identifier, or expand affected versions by inference.\n\nOutput Exposure, Action, and Evidence lines as supported. Retain operational costs of a mitigation. Do not state that a system is safe merely because it uses a workaround, or claim that an update has been applied.", "example": { "context": "Fictional gateway maintainer notice", "before": "This maintainer notice covers Sample Gateway versions 1.8.0 through 1.8.3 when public file sharing is enabled. In that configuration, an unauthenticated requester can retrieve file metadata from another workspace; file contents are not exposed by this issue. Version 1.8.4 fixes the issue. Users who cannot upgrade immediately can disable public file sharing, which blocks the affected endpoint but also makes existing public share links unavailable. As of June 12, the maintainers have no evidence of exploitation, but their review is ongoing. Deployments with public file sharing disabled are not affected by this issue.", "after": "Exposure: Sample Gateway 1.8.0–1.8.3 with public file sharing enabled. Unauthenticated requests can expose another workspace's file metadata, not contents. Sharing-disabled deployments are unaffected.\nAction: Upgrade to 1.8.4, or disable public file sharing to block the endpoint; existing public share links will stop working.\nEvidence: Maintainers report no exploitation evidence as of June 12; review ongoing.", "must_preserve": [ "Sample Gateway 1.8.0 through 1.8.3 only with public file sharing enabled", "Unauthenticated metadata exposure across workspaces; not file contents", "1.8.4 fixes issue; sharing-disabled deployments unaffected", "Disable sharing blocks endpoint but breaks existing public share links", "No evidence of exploitation as of June 12; review ongoing" ], "kind": "illustrative", "omitted": [ "The maintainer-notice introduction and repeated references to the issue and affected configuration." ] } }