Skip to content
Back to skills

Cve Research

ASecurity

Research CVEs and security advisories for project dependencies. Uses Exa, NVD API, OSV.dev, and GitHub Advisory Database to find known vulnerabilities.

  • 29 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added May 28, 2026
ai-agentsgogitapidatabasesecurity

Works with

  • api
  • mcp

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned May 28, 2026

npx -y skills add fusengine/agents --skill cve-research --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cve Research?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cve Research
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/fusengine-cve-research/badge)](https://www.skillsdirectory.com/skills/fusengine-cve-research)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cve-research
description: Research CVEs and security advisories for project dependencies. Uses Exa, NVD API, OSV.dev, and GitHub Advisory Database to find known vulnerabilities.
argument-hint: "<package-name> [version]"
user-invocable: true
---

# CVE Research Skill

## Overview

Research known vulnerabilities for project dependencies using multiple sources.

## Data Sources

| Source | API | Coverage |
|--------|-----|----------|
| NVD | nvd.nist.gov/vuln/api | All CVEs |
| OSV.dev | api.osv.dev | npm, PyPI, Go, crates, Maven |
| GitHub Advisory | github.com/advisories | npm, pip, composer, cargo |
| Exa Search | Via MCP | Real-time web search |

## Workflow

1. **Extract** dependencies from project (package.json, etc.)
2. **Query** each source for known CVEs
3. **Cross-reference** findings across sources
4. **Prioritize** by CVSS score and exploitability
5. **Report** with fix versions and workarounds

## Query Strategy

For each dependency:
1. Search OSV.dev first (fastest, most accurate for packages)
2. Cross-check NVD for CVSS scoring
3. Use Exa for recent advisories not yet in databases
4. Check GitHub Advisory for maintainer responses

## Severity Mapping

| CVSS Score | Severity | Action |
|------------|----------|--------|
| 9.0 - 10.0 | CRITICAL | Fix immediately |
| 7.0 - 8.9 | HIGH | Fix before merge |
| 4.0 - 6.9 | MEDIUM | Plan fix |
| 0.1 - 3.9 | LOW | Document |

## References

- [CVE APIs Reference](references/cve-apis.md)
- [Query Templates](references/templates/cve-query.md)

Files in this skill

  • SKILL.md1.5 KB
  • references/cve-apis.md1.6 KB
  • references/templates/cve-query.md1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…