---
title: "github-security-investigations"
description: "Reusable Agent Plugin workflows for GitHub organization security posture and repository CVE reachability."
canonical: https://agentpluginsdirectory.com/plugins/github-security-investigations
last-updated: 2026-10-07
---

# github-security-investigations
Reusable Agent Plugin workflows for GitHub organization security posture and repository CVE reachability.
- Slug: github-security-investigations
- Publisher: mappedsky
- Repository: https://github.com/mappedsky/seizu
- Manifest: .config/dev/seizu/plugins/github-security-investigations/plugin.json
- Version: 1.3.1
- Category (editorial): security
- Skills: 4 (github-org-security-overview, repo-cve-exploitability, repo-cve-findings, repo-cve-reachability)
- MCP servers: 2 (deps, github)
- Stars: 5
- Repository created: 2022-06-09
- Repository last pushed: 2026-10-01
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/github-security-investigations
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## Skills

- github-org-security-overview: Guide an agent through a GitHub organization security investigation using the github_security
- repo-cve-exploitability: Find the CVEs recorded against one GitHub repository, then read that repository's manifests
- repo-cve-findings: Resolve a GitHub repository in the security graph and list the CVEs recorded against it,
- repo-cve-reachability: Judge whether already-identified CVEs are reachable in a repository's own code, by reading

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.

## MCP servers

- deps: transport: streamable-http; url: https://mcp.deps.test/mcp
- github: transport: streamable-http; url: https://mcp.github.test/mcp

Read from the plugin's own mcp.json. Environment variable names only, never values.
