SkillAgentSearch skills...

cve-source-check

Audit CVE/vulnerability source coverage for a technology stack. Maps each component (container, library, base image, runtime) to authoritative CVE feeds, flags gaps, and produces audit-ready reports. Generic: works for any service or stack.

Install / Use

npx skills add notque/vexjoy-agent --skill cve-source-check

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

85/100

Category

Security

Supported Platforms

Universal

Our assessment of cve-source-check

cve-source-check scores 85/100 on our quality scale, 705th of 1,092 Security skills we index.

Its SKILL.md is 5.4 KB long, well organised into 12 sections with 2 code examples: a solid amount of guidance for an agent.

It has 425 GitHub stars, a meaningful sign that others use it.

Substance
26/30
Structure
18/20
Description
15/15
Adoption
11/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated yesterday, so cve-source-check is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.

Automated pattern scan on 2026-10-04. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

cve-source-check compared with similar skills

All 4 of these similar skills score higher than cve-source-check; compare them before choosing.

SkillScoreStarsUpdatedFormat
cve-source-check (this skill)by notque854251d agoSKILL.md
LocalAIby mudler10049.4ktodayMCP Server
algorithmic-artby anthropics100177.9k12d agoSKILL.md
pptxby anthropics100177.9k12d agoSKILL.md
designby nextlevelbuilder100130.2k13d agoSKILL.md

Frequently asked questions

How do I install cve-source-check?
Run npx skills add notque/vexjoy-agent --skill cve-source-check. The install tabs above show the steps for each supported agent.
Which AI agents does cve-source-check work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is cve-source-check safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is cve-source-check still maintained?
The repository was last updated yesterday, so cve-source-check is actively maintained.

name: cve-source-check promoted_to: deploy description: "Audit CVE/vulnerability source coverage for a technology stack. Maps each component (container, library, base image, runtime) to authoritative CVE feeds, flags gaps, and produces audit-ready reports. Generic: works for any service or stack." user-invocable: false argument-hint: "[--inventory <file>] [--inline <tech-list>] [--current-sources <file>] [--service <name>] [--check-urls]" allowed-tools:

  • Bash
  • Read
  • Write
  • Edit
  • Glob
  • Grep routing: triggers:
    • "check cve sources"
    • "cve source coverage"
    • "audit cve feeds"
    • "vulnerability source audit"
    • "verify cve sources"
    • "security feed audit" category: infrastructure complexity: Simple pairs_with:
    • assessment

CVE Source Check

Audit CVE/vulnerability source coverage for a technology stack. Maps components to authoritative CVE feeds via a versioned registry, flags gaps, and produces audit-ready reports (JSON + Markdown).

In scope: component-to-feed mapping, coverage/gap reporting, optional URL reachability checks. Out of scope: running scanners (Trivy/Snyk), fetching CVE content, private vuln databases.

Quick Start

# Inline, offline
python3 scripts/check-cve-sources.py \
  --inline "go@1.22,alpine@3.19,postgres@16,redis@7,nginx@1.25" \
  --service my-service

# Inventory + monitored feeds + link verification
python3 scripts/check-cve-sources.py \
  --inventory examples/inventory.example.json \
  --current-sources examples/current-sources.example.txt \
  --service my-service --check-urls

Inputs

| Flag | Purpose | |---|---| | --inventory <file> | JSON: [{name, version?, type?}, ...] or {components: [...]}. | | --inline "name@ver,..." | Comma-separated list. Mutually exclusive with --inventory. | | --current-sources <file> | One URL per line. # comments and blank lines skipped. | | --service <name> | Name for report header and filenames. | | --check-urls | HEAD-check every source URL (5s timeout, graceful degradation). | | --registry <path> | Override default tech-source-registry.json. | | --out-dir <path> | Output directory (default: cwd). |

JSON only. YAML not supported (no stdlib parser).

Outputs

Files: cve-source-report-{service}-{YYYYMMDD}.{md,json} in --out-dir.

| Exit | Meaning | |---|---| | 0 | Full coverage. | | 1 | Gaps (unmapped components or unmonitored sources). | | 2 | Unreachable source URL (only with --check-urls). | | 3 | Input error (missing/malformed registry or inventory). |

Workflow

Phase 1: LOAD

  1. Locate tech-source-registry.json (next to SKILL.md by default, or --registry).
  2. Build inventory from --inventory (JSON list or {components: [...]}) or --inline (comma-split name@version).
  3. If --current-sources provided, read URLs and normalize for case-insensitive comparison.

Gate: at least one component present. Empty inventory -> exit 3.

Phase 2: MAP & VERIFY

  1. Look up each component name (and aliases) in the registry.
    • Found -> mapped, attach source list. Missing -> unmapped, sources [].
  2. If current sources loaded, mark each source monitored: true when its normalized URL appears.
  3. If --check-urls: HEAD-check each unique URL. Treat 200/301/302/403/405 as reachable. 4xx (except 403/405) and 5xx -> reachable: false. Timeout/DNS/TLS failure -> reachable: null (WARN, does not affect exit code). 5s timeout per URL, cached per run.

Gate: every component has status; every source has monitored and reachable fields.

Phase 3: REPORT

  1. Compute summary: components, mapped/unmapped, monitored, coverage %, gaps, unreachable.
  2. Write JSON report with per-component status and per-source monitored/reachable fields.
  3. Write Markdown report: summary table, components table (markers), gaps section (when gaps exist), unmapped section (when unmapped exist).
  4. Print one-screen summary to stdout. Set exit code per table above.

Gate: both files written, summary printed.

Registry Schema

tech-source-registry.json shape:

{
  "$schema_version": "1.0",
  "kinds": ["advisory-list", "github-security", "mailing-list", "distro-tracker", "vendor-page", "mitre"],
  "priorities": ["primary", "secondary"],
  "technologies": [
    {"name": "postgres", "aliases": ["postgresql","pg"], "type": "container",
     "sources": [{"url": "https://...", "kind": "advisory-list", "priority": "primary"}]}
  ]
}

Each technology: name (lowercase, unique), aliases (list), type (runtime/base-image/container/library), sources (1-3, at least one primary).

To add a technology: pick canonical name, list aliases, add 1-3 sources (lead with vendor advisory page), re-run against a sample inventory.

Error Handling

| Error | Cause | Fix | |---|---|---| | Failed to load registry | Missing or malformed JSON | Validate with python3 -m json.tool | | Failed to load inventory | Missing, malformed, or wrong shape | Validate JSON; must be list or {components: [...]} | | Inventory empty | No usable components | Each entry needs name. Inline needs non-empty tokens. | | Coverage stuck at 0% | --current-sources URLs don't match registry | Copy URLs from registry. Scheme/host case and trailing slash are normalized; rest must match. | | Many [--] entries with --check-urls | Network issues | Re-run without --check-urls. Network errors don't affect gap exit code. |

Related Skills

View on GitHub
GitHub Stars425
CategorySecurity
Updated1d ago
Forks48

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions