Loading...
Loading...
Guides technical program management for security coordinated vulnerability disclosure (CVD)— disclosure policy, intake and triage SLAs, researcher coordination, fix/remediation tracking, embargo and publication timelines, CVE/advisory coordination, bug bounty program operations, and cross-functional gates (security engineering, legal, comms, product). Use when running a CVD or responsible disclosure program, disclosure calendar, bounty ops, or unblocking multi-team remediation for reported vulnerabilities—not for hands-on pentest (offensive-security-analyst), SOC triage (defensive-security-analyst), vuln scanning in CI (devsecops), enterprise security strategy (cybersecurity), generic non-security programs (technical-program-manager), or contract redlines (commercial-counsel).
npx skill4agent add daemon-blockint-tech/agentic-enteprises-skill technical-program-manager-security-cvdoffensive-security-analystdefensive-security-analystdevsecopsinformation-security-engineersenior-software-engineercybersecuritycompliance-engineertechnical-program-managercommercial-counselcommunication-lead| Need | Skill |
|---|---|
| Generic TPM patterns (charter, RAID, status) | |
| Security strategy and vuln management program | |
| Fix implementation and validation in infra | |
| Pipeline scanning and CI evidence | |
| Pentest / offensive validation | |
| Legal terms for bounty / safe harbor | |
| Public messaging for security incidents | |
| Audit evidence for vuln SLAs | |
| AI-specific red team findings | |
references/program_charter_cvd.mdreferences/intake_triage.mdreferences/remediation_tracking.mdreferences/disclosure_timeline.mdreferences/advisory_publication.mdreferences/bug_bounty_operations.mdincident-management-engineer