Skip to content
Development
Skill

/cve-research

Use when checking a specific dependency or package version for known CVEs and security advisories.

From plugin
fusengine-agents
27196 skills37 agents33 commands
Install
$ npx -y skills add fusengine/agents --skill cve-research --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/cve-research

Context preview

The summary Claude sees to decide when to auto-load this skill.

Use when checking a specific dependency or package version for known CVEs and security advisories.

SKILL.md

cve-research.SKILL.md
name: cve-research
description: "Use when checking a specific dependency or package version for known CVEs and security advisories."
argument-hint: "<package-name> [version]"
user-invocable: true

<objective> This skill researches known vulnerabilities for a specific dependency across multiple sources: OSV.dev (npm, PyPI, Go, crates, Maven), NVD (CVSS scoring), GitHub Advisory Database (maintainer responses), and Exa web search for advisories not yet indexed.

It queries OSV.dev first for speed and accuracy, cross-checks NVD for CVSS scoring, uses Exa for recent advisories, and checks GitHub Advisory for maintainer responses, then cross-references findings and prioritizes by CVSS score and exploitability — CRITICAL (9.0-10.0) fixed immediately, HIGH (7.0-8.9) before merge, MEDIUM (4.0-6.9) planned, LOW (0.1-3.9) documented — reporting fix versions and workarounds.

Out of scope: this is a single-dependency lookup, not a full project dependency sweep (use dependency-audit for that). </objective>

CVE Research Skill

Overview

Research known vulnerabilities for project dependencies using multiple sources.

Data Sources

| Source | API | Coverage | |--------|-----|----------| | NVD | nvd.nist.gov/vuln/api | All CVEs | | OSV.dev | api.osv.dev | npm, PyPI, Go, crates, Maven | | GitHub Advisory | github.com/advisories | npm, pip, composer, cargo | | Exa Search | Via MCP | Real-time web search |

Workflow

1. **Extract** dependencies from project (package.json, etc.) 2. **Query** each source for known CVEs 3. **Cross-reference** findings across sources 4. **Prioritize** by CVSS score and exploitability 5. **Report** with fix versions and workarounds

Query Strategy

For each dependency: 1. Search OSV.dev first (fastest, most accurate for packages) 2. Cross-check NVD for CVSS scoring 3. Use Exa for recent advisories not yet in databases 4. Check GitHub Advisory for maintainer responses

Severity Mapping

| CVSS Score | Severity | Action | |------------|----------|--------| | 9.0 - 10.0 | CRITICAL | Fix immediately | | 7.0 - 8.9 | HIGH | Fix before merge | | 4.0 - 6.9 | MEDIUM | Plan fix | | 0.1 - 3.9 | LOW | Document |

References

  • [CVE APIs Reference](references/cve-apis.md)
  • [Query Templates](references/templates/cve-query.md)
Read more
Ships withfusengine-agents

A plugin ecosystem that turns Claude Code into a supervised, multi-agent development environment.

Get the whole plugin

Other skills on fusengine-agents.