Generate prioritized CVE watchlists and actionable security recommendations for repositories. Use when analyzing CVE scan results, creating security reports, prioritizing vulnerability remediation, or generating security gate reports for CI/CD. Takes CVE scan results (JSON/SARIF from npm audit, pip-audit, Snyk), reachability analysis, and cutoff date as input. Combines severity, reachability, exploitability, and dependency criticality to rank CVEs by practical risk. Outputs markdown reports with concrete next-step guidance (immediate upgrade, monitor, ignore with justification, apply mitigation) suitable for issue trackers, security reviews, and CI security gates.
90
90%
Does it follow best practices?
Impact
86%
1.38xAverage score across 3 eval scenarios
Low
Low-risk findings worth noting
| Run | Type | Date | Status |
|---|---|---|---|
baseline vs usage-spec With / without contextCompleted | With / without context | Completed |
019cc49e-ce1c-776a-851c-0516bc55c114
Run
The run is available. Its result stats will appear here when they are ready.
4f38503
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.