diff --git a/skills/security-cve-allocate/SKILL.md b/skills/security-cve-allocate/SKILL.md index 020eff9e..c52185dc 100644 --- a/skills/security-cve-allocate/SKILL.md +++ b/skills/security-cve-allocate/SKILL.md @@ -463,12 +463,12 @@ re-invoke this skill with the CVE ID as an override argument to resume from Step 4. **Fallback when no governance-authorised member is reachable:** -if every authorised member is unavailable or unresponsive, send -an email to `security@apache.org` with subject -`CVE request for `. The ASF Security Team -will allocate the CVE and send the ID back. Re-invoke this skill -with the returned `CVE-YYYY-NNNNN` as an override to resume from -Step 4. +if every authorised member is unavailable or unresponsive, follow +the fallback path documented by the active CVE-tool adapter (for +the Vulnogram adapter, see +[`tools/cve-tool-vulnogram/allocation.md` § *PMC-gated access*](../../tools/cve-tool-vulnogram/allocation.md#pmc-gated-access)). +When the fallback returns a `CVE-YYYY-NNNNN`, re-invoke this skill +with that ID as an override to resume from Step 4. **Wait for the user** to report back a `CVE-\d{4}-\d+` token. Do not proceed to Step 4 until that token has arrived. If the user diff --git a/skills/security-issue-sync/github-advisory.md b/skills/security-issue-sync/github-advisory.md index 8c0239d5..c5d50280 100644 --- a/skills/security-issue-sync/github-advisory.md +++ b/skills/security-issue-sync/github-advisory.md @@ -126,7 +126,7 @@ path. ### Delivery — an email relay (draft, never auto-sent) Create a **draft** email to the org's advisory-admin security team -(``; for ASF, `security@apache.org`) with +(``) with `oauth-draft-create` — never send directly (SKILL Golden rule 1; and the Gmail MCP mangles the `security/advisories/GHSA-…` URLs into redirects, so use oauth-draft). **Always CC the project ``** so the