cve-research
Use when checking a specific dependency or package version for known CVEs and security advisories.
Works with
--- name: cve-research description: Use when checking a specific dependency or package version for known CVEs and security advisories. license: MIT --- <objective> This skill researches known vulnerabilities for a specific dependency across multiple sources: OSV.dev (npm, PyPI, Go, crates, Maven), NVD (CVSS scoring), GitHub Advisory Database (maintainer responses), and Exa web search for advisories not yet indexed. It queries OSV.dev first for speed and accuracy, cross-checks NVD for CVSS scoring, uses Exa for recent advisories, and checks GitHub Advisory for maintainer responses, then cross-references findings and prioritizes by CVSS score and exploitability — CRITICAL (9.0-10.0) fixed immediately, HIGH (7.0-8.9) before merge, MEDIUM (4.0-6.9) planned, LOW (0.1-3.9) documented — reporting fix versions and workarounds. Out of scope: this is a single-dependency lookup, not a full project dependency sweep (use dependency-audit for that). </objective> # CVE Research Skill ## Overview Research known vulnerabilities for project dependencies using multiple sources. ## Data Sources | Source | API | Coverage | |--------|-----|----------| | NVD | nvd.nist.gov/vuln/api | All CVEs | | OSV.dev | api.osv.dev | npm, PyPI, Go, crates, Maven | | GitHub Advisory | github.com/advisories | npm, pip, composer, cargo | | Exa Search | Via MCP | Real-time web search | ## Workflow 1. **Extract** dependencies from project (package.json, etc.) 2. **Query** each source for known CVEs 3. **Cross-reference** findings across sources 4. **Prioritize** by CVSS score and exploitability 5. **Report** with fix versions and workarounds ## Query Strategy For each dependency: 1. Search OSV.dev first (fastest, most accurate for packages) 2. Cross-check NVD for CVSS scoring 3. Use Exa for recent advisories not yet in databases 4. Check GitHub Advisory for maintainer responses ## Severity Mapping | CVSS Score | Severity | Action | |------------|----------|--------| | 9.0 - 10.0 | CRITICAL | Fix immediately | | 7.0 - 8.9 | HIGH | Fix before merge | | 4.0 - 6.9 | MEDIUM | Plan fix | | 0.1 - 3.9 | LOW | Document | ## References - [CVE APIs Reference](references/cve-apis.md) - [Query Templates](references/templates/cve-query.md)
More General & Other skills
find-skills
vercel-labs/skills
Helps users discover and install agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities. This skill should be used when the user is looking for functionality that might exist as an installable skill.
grill-me
mattpocock/skills
A relentless interview to sharpen a plan or design.
grill-with-docs
mattpocock/skills
A relentless interview to sharpen a plan or design, which also creates docs (ADR's and glossary) as we go.

