Reference vocabulary for interpreting vulnerability findings — detector-vs-impact distinction, severity anchoring on demonstrated evidence, the eleven-item interpretation rubric, delegation transparency, primitive-extent scaling, the disqualifier taxonomy (D-0..D-4), CVSS Achievable / Environmental framing, hedging-phrase elimination, and falsification asymmetry. Read when interpreting a finding to decide whether the demonstrated evidence supports the severity it would warrant. Surface-neutral; pulls in the relevant surface skill (e.g. memory-safety-c-cpp) for bug-class-specific exploitability factors.
$npx -y skills add provos/ironcurtain --skill vulnerability-triageInstalls into the current project.
Run `npx skills use "https://github.com/provos/ironcurtain" --skill "provos/ironcurtain/vulnerability-triage"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/provos/ironcurtain" that are relevant to the current task. Run `npx skills add "https://github.com/provos/ironcurtain"` and select the relevant skills, then follow their instructions.