Triage a GitHub security advisory (GHSA) reported against a repo you maintain — verify the claim empirically, re-derive an honest severity, correct the advisory fields, and draft a reply to the reporter. Use whenever the user mentions a GHSA id or security advisory URL, asks whether a security report is valid or overstated, says a severity looks too high, asks whether something deserves a CVE, or wants help answering a vulnerability reporter. Also use for a bulk drop of several advisories from one reporter, where cross-report chaining and consistent severity matter.