Skip to content
Development
Skill

/assess-exposure-and-impact

Prioritize a vulnerability using actual asset exposure and impact. Use when versions, reachability, prerequisites, privileges, data, exploit maturity, mitigations, detection, business criticality, and urgency matter beyond CVSS.

From plugin
socket
7200 skills5 MCP
Install
$ npx -y skills add gaelic-ghost/socket --skill assess-exposure-and-impact --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/assess-exposure-and-impact

Context preview

The summary Claude sees to decide when to auto-load this skill.

Prioritize a vulnerability using actual asset exposure and impact. Use when versions, reachability, prerequisites, privileges, data, exploit maturity, mitigations, detection, business criticality, and urgency matter beyond CVSS.

SKILL.md

assess-exposure-and-impact.SKILL.md
name: assess-exposure-and-impact
description: Prioritize a vulnerability using actual asset exposure and impact. Use when versions, reachability, prerequisites, privileges, data, exploit maturity, mitigations, detection, business criticality, and urgency matter beyond CVSS.

Assess Exposure And Impact

Overview

Translate a technical finding into asset-specific risk and action. Treat CVSS as one technical severity input and current exploitation intelligence as another; neither replaces deployed context.

Read [references/exposure-impact-model.md](references/exposure-impact-model.md) for the decision factors.

Workflow

1. Confirm finding confidence and exact affected/fixed versions. 2. Inventory affected assets.

  • Record internet/internal/local reachability, environment, owner, business function, data, users, privileges, and compensating controls.

3. Model attacker requirements.

  • Record access position, authentication, user interaction, configuration, chaining, reliability, and detection likelihood.

4. Check current intelligence.

  • Review vendor advisory, fixed release, exploit maturity, CISA KEV/ransomware status, ecosystem advisories, and known active campaigns; date sources.

5. Evaluate consequence.

  • Assess confidentiality, integrity, availability, privilege, blast radius, persistence, recovery difficulty, safety/legal/privacy obligations, and business interruption.

6. Evaluate mitigations.

  • Test whether configuration, network controls, feature disablement, isolation, monitoring, or virtual patching actually blocks the validated path.

7. Prioritize action.

  • Recommend patch, mitigate, isolate, monitor, accept temporarily with owner/expiry, or investigate further; include retest criteria.

Output

Return affected assets, exposure path, impact, current exploitation context, mitigations, priority/rationale, action owner/deadline, and residual uncertainty.

Read more
Ships withsocket

Stuff for Agents on macOS Promo audio: Socket Codex Marketplace Promo

Get the whole plugin

Other skills on socket.