cve-source-check
Audit CVE/vulnerability source coverage for a technology stack. Maps each component (container, library, base image, runtime) to authoritative CVE feeds, flags gaps, and produces audit-ready reports. Generic: works for any service or stack.
Install / Use
npx skills add notque/vexjoy-agent --skill cve-source-checkInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of cve-source-check
cve-source-check scores 85/100 on our quality scale, 705th of 1,092 Security skills we index.
Its SKILL.md is 5.4 KB long, well organised into 12 sections with 2 code examples: a solid amount of guidance for an agent.
It has 425 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated yesterday, so cve-source-check is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-10-04. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
cve-source-check compared with similar skills
All 4 of these similar skills score higher than cve-source-check; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| cve-source-check (this skill)by notque | 85 | 425 | 1d ago | SKILL.md |
| LocalAIby mudler | 100 | 49.4k | today | MCP Server |
| algorithmic-artby anthropics | 100 | 177.9k | 12d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 12d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 13d ago | SKILL.md |
Frequently asked questions
- How do I install cve-source-check?
- Run
npx skills add notque/vexjoy-agent --skill cve-source-check. The install tabs above show the steps for each supported agent. - Which AI agents does cve-source-check work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is cve-source-check safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is cve-source-check still maintained?
- The repository was last updated yesterday, so cve-source-check is actively maintained.
Skill content
View source on GitHubname: cve-source-check promoted_to: deploy description: "Audit CVE/vulnerability source coverage for a technology stack. Maps each component (container, library, base image, runtime) to authoritative CVE feeds, flags gaps, and produces audit-ready reports. Generic: works for any service or stack." user-invocable: false argument-hint: "[--inventory <file>] [--inline <tech-list>] [--current-sources <file>] [--service <name>] [--check-urls]" allowed-tools:
- Bash
- Read
- Write
- Edit
- Glob
- Grep
routing:
triggers:
- "check cve sources"
- "cve source coverage"
- "audit cve feeds"
- "vulnerability source audit"
- "verify cve sources"
- "security feed audit" category: infrastructure complexity: Simple pairs_with:
- assessment
CVE Source Check
Audit CVE/vulnerability source coverage for a technology stack. Maps components to authoritative CVE feeds via a versioned registry, flags gaps, and produces audit-ready reports (JSON + Markdown).
In scope: component-to-feed mapping, coverage/gap reporting, optional URL reachability checks. Out of scope: running scanners (Trivy/Snyk), fetching CVE content, private vuln databases.
Quick Start
# Inline, offline
python3 scripts/check-cve-sources.py \
--inline "go@1.22,alpine@3.19,postgres@16,redis@7,nginx@1.25" \
--service my-service
# Inventory + monitored feeds + link verification
python3 scripts/check-cve-sources.py \
--inventory examples/inventory.example.json \
--current-sources examples/current-sources.example.txt \
--service my-service --check-urls
Inputs
| Flag | Purpose |
|---|---|
| --inventory <file> | JSON: [{name, version?, type?}, ...] or {components: [...]}. |
| --inline "name@ver,..." | Comma-separated list. Mutually exclusive with --inventory. |
| --current-sources <file> | One URL per line. # comments and blank lines skipped. |
| --service <name> | Name for report header and filenames. |
| --check-urls | HEAD-check every source URL (5s timeout, graceful degradation). |
| --registry <path> | Override default tech-source-registry.json. |
| --out-dir <path> | Output directory (default: cwd). |
JSON only. YAML not supported (no stdlib parser).
Outputs
Files: cve-source-report-{service}-{YYYYMMDD}.{md,json} in --out-dir.
| Exit | Meaning |
|---|---|
| 0 | Full coverage. |
| 1 | Gaps (unmapped components or unmonitored sources). |
| 2 | Unreachable source URL (only with --check-urls). |
| 3 | Input error (missing/malformed registry or inventory). |
Workflow
Phase 1: LOAD
- Locate
tech-source-registry.json(next to SKILL.md by default, or--registry). - Build inventory from
--inventory(JSON list or{components: [...]}) or--inline(comma-splitname@version). - If
--current-sourcesprovided, read URLs and normalize for case-insensitive comparison.
Gate: at least one component present. Empty inventory -> exit 3.
Phase 2: MAP & VERIFY
- Look up each component
name(and aliases) in the registry.- Found ->
mapped, attach source list. Missing ->unmapped, sources[].
- Found ->
- If current sources loaded, mark each source
monitored: truewhen its normalized URL appears. - If
--check-urls: HEAD-check each unique URL. Treat 200/301/302/403/405 as reachable. 4xx (except 403/405) and 5xx ->reachable: false. Timeout/DNS/TLS failure ->reachable: null(WARN, does not affect exit code). 5s timeout per URL, cached per run.
Gate: every component has status; every source has monitored and reachable fields.
Phase 3: REPORT
- Compute summary: components, mapped/unmapped, monitored, coverage %, gaps, unreachable.
- Write JSON report with per-component status and per-source
monitored/reachablefields. - Write Markdown report: summary table, components table (markers), gaps section (when gaps exist), unmapped section (when unmapped exist).
- Print one-screen summary to stdout. Set exit code per table above.
Gate: both files written, summary printed.
Registry Schema
tech-source-registry.json shape:
{
"$schema_version": "1.0",
"kinds": ["advisory-list", "github-security", "mailing-list", "distro-tracker", "vendor-page", "mitre"],
"priorities": ["primary", "secondary"],
"technologies": [
{"name": "postgres", "aliases": ["postgresql","pg"], "type": "container",
"sources": [{"url": "https://...", "kind": "advisory-list", "priority": "primary"}]}
]
}
Each technology: name (lowercase, unique), aliases (list), type (runtime/base-image/container/library), sources (1-3, at least one primary).
To add a technology: pick canonical name, list aliases, add 1-3 sources (lead with vendor advisory page), re-run against a sample inventory.
Error Handling
| Error | Cause | Fix |
|---|---|---|
| Failed to load registry | Missing or malformed JSON | Validate with python3 -m json.tool |
| Failed to load inventory | Missing, malformed, or wrong shape | Validate JSON; must be list or {components: [...]} |
| Inventory empty | No usable components | Each entry needs name. Inline needs non-empty tokens. |
| Coverage stuck at 0% | --current-sources URLs don't match registry | Copy URLs from registry. Scheme/host case and trailing slash are normalized; rest must match. |
| Many [--] entries with --check-urls | Network issues | Re-run without --check-urls. Network errors don't affect gap exit code. |
Related Skills
LocalAI
49.4kLocalAI is the open-source AI engine. Run any model - LLMs, vision, voice, image, video - on any hardware. No GPU required.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
