mcpbeat Sign in

Cve Source Check Agent Skill

Audit CVE/vulnerability source coverage for a technology stack. Maps each component (container, library, base image, runtime) to authoritative CVE feeds, flags gaps, and produces audit-ready reports. Generic: works for any service or stack.

9k tokens
context cost
the whole folder, loaded on every use
8
files
ships runnable scripts
0
copies elsewhere
how many repositories repackaged it
413
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/notque/vexjoy-agent --skill cve-source-check

The instruction itself

17 sections, as written by the author

CVE Source Check

Audits CVE/vulnerability source coverage for a technology stack. Given an inventory

of components and (optionally) the feeds you currently monitor, it maps each

component to authoritative CVE sources, flags gaps, and emits audit-ready reports.

Scope

| In scope | Out of scope |

|---|---|

| Mapping components → authoritative feeds via a versioned registry | Running vulnerability scanners (Trivy/Snyk/etc.) |

| Reporting coverage and gaps in JSON + Markdown | Fetching CVE content or ranking by severity |

| Optional HEAD-check for source URL reachability | Integrating with private/commercial vuln databases |

| Audit-ready output (deterministic, reproducible) | Live LLM research per run |

Inputs

| Flag | Purpose |

|---|---|

| --inventory <file> | JSON inventory: [{name, version?, type?}, ...] or {components: [...]}. |

| --inline "name@ver,name,..." | Quick comma-separated list. Mutually exclusive with --inventory. |

| --current-sources <file> | Optional. One URL per line. Blank lines and # comments skipped. |

| --service <name> | Free-form name used in report header and filenames. |

| --check-urls | HEAD-check every source URL (5s timeout, graceful degradation). |

| --registry <path> | Override default tech-source-registry.json. |

| --out-dir <path> | Output directory (default: cwd). |

JSON inventory format only. YAML is not supported — stdlib does not ship a YAML parser.

Outputs

| File | Format |

|---|---|

| cve-source-report-{service}-{YYYYMMDD}.md | Human-readable audit report. |

| cve-source-report-{service}-{YYYYMMDD}.json | Machine-readable per references/output-formats.md. |

| Exit code | Meaning |

|---|---|

| 0 | Full coverage. |

| 1 | Gaps exist (unmapped components or unmonitored sources). |

| 2 | At least one source URL is unreachable (only with --check-urls). |

| 3 | Input error (missing/malformed registry or inventory). |

Workflow

Phase 1: LOAD

  • Locate the registry: tech-source-registry.json next to this SKILL.md by default.
  • Build an inventory:
  • From --inventory: parse JSON; accept either a list or {components: [...]}.
  • From --inline: split on commas, parse name@version pairs.
  • If --current-sources is provided, read URLs (one per line); normalize for

case-insensitive comparison.

Gate: at least one inventory component is present. Empty inventory → exit 3.

Phase 2: MAP & VERIFY

  • For each component, look up name (and aliases) in the registry.
  • Found → status mapped, attach the registry's source list.
  • Missing → status unmapped, sources [].
  • If current sources were loaded, mark each source monitored: true when its

normalized URL appears in the set.

  • If --check-urls is set, HEAD-check every unique source URL. Treat

200/301/302/403/405 as reachable; record definite failures and network errors

distinctly. See references/source-verification.md.

Gate: every component has a status; every source has monitored and

reachable fields populated (reachable: null when checks are skipped).

Phase 3: REPORT

  • Compute the summary: components, mapped/unmapped, monitored, coverage %,

gaps, unreachable.

  • Write the JSON report.
  • Write the Markdown report:
  • Summary table.
  • Components table with ✅ / ⚠️ / ❌ markers.
  • Gaps section listing primary then secondary sources to add (only when

gaps exist).

  • Unmapped section listing registry-extension TODOs (only when unmapped

components exist).

  • Print a one-screen summary to stdout including report paths.
  • Set the exit code per the table above.

Gate: both files exist on disk and the summary printed; exit code reflects

the audit result.

Quick start

# Inline, offline, no monitoring data
python3 scripts/check-cve-sources.py \
  --inline "[email protected],[email protected],postgres@16,redis@7,[email protected]" \
  --service my-service

# Inventory file + current monitored feeds
python3 scripts/check-cve-sources.py \
  --inventory examples/inventory.example.json \
  --current-sources examples/current-sources.example.txt \
  --service my-service

# Same, with link verification
python3 scripts/check-cve-sources.py \
  --inventory examples/inventory.example.json \
  --current-sources examples/current-sources.example.txt \
  --service my-service \
  --check-urls

Extending the registry

To add a technology, edit tech-source-registry.json. Each entry needs name,

aliases, type, and 1–3 sources. Schema lives at

references/registry-schema.md.

Reference Loading Table

| Signal | Load These Files | Why |

|---|---|---|

| adding a technology to the registry | registry-schema.md | Defines registry shape and allowed values. |

| checking source URLs | source-verification.md | Defines HEAD-check semantics and graceful degradation. |

| generating audit reports | output-formats.md | Defines JSON and Markdown report contracts. |

Error handling

"ERROR: failed to load registry"

Cause: registry file missing or malformed JSON.

Solution: confirm tech-source-registry.json is at --registry (or default

location) and parses with python3 -m json.tool.

"ERROR: failed to load inventory"

Cause: inventory file missing, malformed JSON, or unexpected shape.

Solution: validate with python3 -m json.tool. Inventory must be a list or an

object with a components key.

"ERROR: inventory is empty"

Cause: no usable components after parsing.

Solution: confirm each entry has a name. Inline form requires non-empty tokens.

Coverage stuck at 0%

Cause: --current-sources URLs do not match registry URLs exactly (e.g., extra

path segments, trailing slashes).

Solution: copy URLs directly from the registry. The script normalizes scheme/host

case and trailing slash; everything else must match.

--check-urls flags many [—] entries

Cause: network issues (proxy, DNS, offline) — recorded as reachable: null.

Solution: re-run without --check-urls for the audit; investigate network

separately. Network errors do not affect the gap exit code.

Other skills for the same job

different authors, same section of the catalogue
Backend Security Coder
by ComeOnOliver
×2

Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.

5k tokens
Cloud Penetration Testing
by ComeOnOliver
×2

This skill should be used when the user asks to "perform cloud penetration testing", "assess Azure or AWS or GCP security", "enumerate cloud resources", "exploit cloud misconfigurations", "test O365 security", "extract secrets from cloud environments", or "audit cloud infrastructure". It provides comprehensive techniques for security assessment across major cloud platforms.

16k tokens
Codebase Cleanup Deps Audit
by ComeOnOliver
×2

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

10k tokens
Flow Nexus Platform
by ComeOnOliver
×2

Comprehensive Flow Nexus platform management - authentication, sandboxes, app deployment, payments, and challenges

14k tokens
Linux Privilege Escalation
by ComeOnOliver
×2

This skill should be used when the user asks to "escalate privileges on Linux", "find privesc vectors on Linux systems", "exploit sudo misconfigurations", "abuse SUID binaries", "exploit cron jobs for root access", "enumerate Linux systems for privilege escalation", or "gain root access from low-privilege shell". It provides comprehensive techniques for identifying and exploiting privilege escalation paths on Linux systems.

8k tokens
Malware Analyst
by ComeOnOliver
×2

Expert malware analyst specializing in defensive malware research, threat intelligence, and incident response. Masters sandbox analysis, behavioral analysis, and malware family identification. Handles static/dynamic analysis, unpacking, and IOC extraction. Use PROACTIVELY for malware triage, threat hunting, incident response, or security research.

4k tokens
Metasploit Framework
by ComeOnOliver
×2

This skill should be used when the user asks to "use Metasploit for penetration testing", "exploit vulnerabilities with msfconsole", "create payloads with msfvenom", "perform post-exploitation", "use auxiliary modules for scanning", or "develop custom exploits". It provides comprehensive guidance for leveraging the Metasploit Framework in security assessments.

7k tokens
Mobile Security Coder
by ComeOnOliver
×2

Expert in secure mobile coding practices specializing in input validation, WebView security, and mobile-specific security patterns. Use PROACTIVELY for mobile security implementations or mobile security code reviews.

6k tokens

How to use it

Copy the folder

Take notque/cve-source-check from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.