Skip to content

/cve-research

Use when checking a specific dependency or package version for known CVEs and security advisories.

shell
$ npx -y skills add fusengine/agents --skill cve-research --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/cve-research
How auto-invocation works

Context preview

The summary Claude sees to decide when to auto-load this skill.

Use when checking a specific dependency or package version for known CVEs and security advisories.

SKILL.md

cve-research.SKILL.md
name: cve-research
description: "Use when checking a specific dependency or package version for known CVEs and security advisories."
argument-hint: "<package-name> [version]"
user-invocable: true

<objective> This skill researches known vulnerabilities for a specific dependency across multiple sources: OSV.dev (npm, PyPI, Go, crates, Maven), NVD (CVSS scoring), GitHub Advisory Database (maintainer responses), and Exa web search for advisories not yet indexed.

It queries OSV.dev first for speed and accuracy, cross-checks NVD for CVSS scoring, uses Exa for recent advisories, and checks GitHub Advisory for maintainer responses, then cross-references findings and prioritizes by CVSS score and exploitability — CRITICAL (9.0-10.0) fixed immediately, HIGH (7.0-8.9) before merge, MEDIUM (4.0-6.9) planned, LOW (0.1-3.9) documented — reporting fix versions and workarounds.

Out of scope: this is a single-dependency lookup, not a full project dependency sweep (use dependency-audit for that). </objective>

CVE Research Skill

Overview

Research known vulnerabilities for project dependencies using multiple sources.

Data Sources

| Source | API | Coverage | |--------|-----|----------| | NVD | nvd.nist.gov/vuln/api | All CVEs | | OSV.dev | api.osv.dev | npm, PyPI, Go, crates, Maven | | GitHub Advisory | github.com/advisories | npm, pip, composer, cargo | | Exa Search | Via MCP | Real-time web search |

Workflow

1. **Extract** dependencies from project (package.json, etc.) 2. **Query** each source for known CVEs 3. **Cross-reference** findings across sources 4. **Prioritize** by CVSS score and exploitability 5. **Report** with fix versions and workarounds

Query Strategy

For each dependency: 1. Search OSV.dev first (fastest, most accurate for packages) 2. Cross-check NVD for CVSS scoring 3. Use Exa for recent advisories not yet in databases 4. Check GitHub Advisory for maintainer responses

Severity Mapping

| CVSS Score | Severity | Action | |------------|----------|--------| | 9.0 - 10.0 | CRITICAL | Fix immediately | | 7.0 - 8.9 | HIGH | Fix before merge | | 4.0 - 6.9 | MEDIUM | Plan fix | | 0.1 - 3.9 | LOW | Document |

References

  • [CVE APIs Reference](references/cve-apis.md)
  • [Query Templates](references/templates/cve-query.md)
Read more
Read it on GitHub ↗
Ships withfusengine-agents

A plugin ecosystem that turns Claude Code into a supervised, multi-agent development environment.

Get the whole plugin, auto-invoked
Stats
22
Stars
0
Views
3
Forks
Active
Maintenance
CSS
Language
MIT
License
1d ago
Last commit
6mo ago
Created

Repo: fusengine/agents