CVE research and security patch workflow for Ark. Provides CVE API integration, mitigation strategies, and security-focused PR templates. Works with research, analysis, and setup skills for comprehensive vulnerability fixing.
61
46%
Does it follow best practices?
Impact
79%
1.01xAverage score across 3 eval scenarios
Advisory
Suggest reviewing before use
Optimize this skill with Tessl
npx tessl skill review --optimize ./.claude/skills/vulnerability-fixer/SKILL.mdCVE API research and mitigation planning
CIRCL API usage
0%
100%
CVSS score reported
100%
100%
Affected version range
100%
100%
Recommended/patched version
100%
100%
Vendor/advisory sources
100%
100%
Multiple mitigation options
66%
100%
Vulnerability Details section
100%
100%
Impact on Ark section
75%
100%
Ark deployment context in risk assessment
100%
100%
User approval gate
100%
100%
Recommendation section
100%
100%
Node.js transitive dependency vulnerability resolution
All lockfiles searched
100%
100%
jq or equivalent version inspection
100%
100%
Identifies parent packages
100%
100%
Identifies conflicting versions
100%
100%
npm overrides global risk warning
100%
100%
Parent package upgrade recommendation
100%
100%
Remediation script produced
100%
100%
find command for lockfiles
100%
0%
Security branch naming and PR template
Branch naming convention
50%
0%
go get + go mod tidy
30%
100%
Verification commands
100%
87%
Commit message prefix
0%
16%
Commit Vulnerability Details section
50%
25%
Commit References with CIRCL URL
0%
0%
Push uses branch name
50%
50%
gh pr create used
100%
100%
PR vulnerability details table
66%
83%
PR Risk Assessment section
100%
0%
fc5746e
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.