Home / fusengine / agents · plugins/security-expert/skills/cve-research/SKILL.md · GitHub

cve-research skillA

cve-research is agent-read markdown (skill) from fusengine/agents: Use when checking a specific dependency or package version for known CVEs and security advisories..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

<objective>
This skill researches known vulnerabilities for a specific dependency across multiple
sources: OSV.dev (npm, PyPI, Go, crates, Maven), NVD (CVSS scoring), GitHub Advisory
Database (maintainer responses), and Exa web search for advisories not yet indexed.

It queries OSV.dev first for speed and accuracy, cross-checks NVD for CVSS scoring, uses Exa
for recent advisories, and checks GitHub Advisory for maintainer responses, then
cross-references findings and prioritizes by CVSS score and exploitability — CRITICAL
(9.0-10.0) fixed immediately, HIGH (7.0-8.9) before merge, MEDIUM (4.0-6.9) planned, LOW
(0.1-3.9) documented — reporting fix versions and workarounds.

Out of scope: this is a single-dependency lookup, not a full project dependency sweep (use
dependency-audit for that).
</objective>

# CVE Research Skill

## Overview

Research known vulnerabilities for project dependencies using multiple sources.

## Data Sources

| Source | API | Coverage |
|--------|-----|----------|
| NVD | nvd.nist.gov/vuln/api | All CVEs |
| OSV.dev | api.osv.dev | npm, PyPI, Go, crates, Maven |
| GitHub Advisory | github.com/advisories | npm, pip, composer, cargo |
…

Read the whole file at its exact version.

How to install

Latest version
mdr add fusengine/agents/cve-research@git:20260729.3b91eed
Exact content
mdr add fusengine/agents/cve-research@sha256:c8c72892432e4408

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_lzhdeqer7leuc3d2.svg)](https://markdownregistry.com/a/art_lzhdeqer7leuc3d2)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260729.3b91eed latest2026-07-29 3b91eed 2,296 BA view · diff
git:20260705.ba8ee522026-07-05 ba8ee52 1,631 BA view · diff
git:20260705.8c2f9bc2026-07-05 8c2f9bc 1,629 BA view · diff
git:20260221.ef8fc892026-02-21 ef8fc89 1,529 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (2296 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

fusengine/agents · 28 stars · license MIT · pushed 2026-09-24 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_lzhdeqer7leuc3d2
GET https://markdownregistry.com/api/v1/resolve?ref=fusengine/agents/cve-research
GET https://markdownregistry.com/api/v1/blob/c8c72892432e4408260e9d5311d71a6279742cbb135430c5501f45d885171139

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from fusengine/agents

agent-creator skill
fusengine/agents · plugins/ai-pilot/skills/agent-creator/SKILL.md · Use when creating expert agents. Generates agent.md with frontmatter, hooks, required sections, and skill references.
git:20260904.5f1d30f · audit A · 28 stars
apex-methodology skill
fusengine/agents · plugins/ai-pilot/skills/apex-methodology/SKILL.md · Use when starting ANY development task -- feature, bug fix, refactor, hotfix (triggers: implement, create, build, fix…
git:20260729.3b91eed · audit A · 28 stars
brainstorming skill
fusengine/agents · plugins/ai-pilot/skills/brainstorming/SKILL.md · Use when creating a feature/component or adding functionality. Fires BEFORE APEX Analyze to refine requirements via…
git:20260904.5f1d30f · audit A · 28 stars
challenge skill
fusengine/agents · plugins/ai-pilot/skills/challenge/SKILL.md · Use before a root-cause, done/verified claim, irreversible action, or 2nd-time fix reaches the owner (APEX or plain…
git:20260729.3b91eed · audit A · 28 stars
code-quality skill
fusengine/agents · plugins/ai-pilot/skills/code-quality/SKILL.md · Use when validating code quality after modifications -- SOLID compliance, DRY duplication, linter errors, architecture…
git:20260729.3b91eed · audit A · 28 stars
elicitation skill
fusengine/agents · plugins/ai-pilot/skills/elicitation/SKILL.md · Use when an expert agent self-reviews and self-corrects code after the Execute phase, before sniper validation…
git:20260729.3b91eed · audit A · 28 stars
exploration skill
fusengine/agents · plugins/ai-pilot/skills/exploration/SKILL.md · Use when exploring an unfamiliar codebase -- architecture analysis, pattern detection, dependency mapping, rapid…
git:20260729.3b91eed · audit A · 28 stars
fuse-browser-usage skill
fusengine/agents · plugins/ai-pilot/skills/fuse-browser-usage/SKILL.md · Use when about to call any mcp__fuse-browser__* tool. Routes fetch/crawl/SERP vs live browser session vs screenshot…
git:20260729.3b91eed · audit A · 28 stars
modularize skill
fusengine/agents · plugins/ai-pilot/skills/modularize/SKILL.md · Use when converting existing code to modular architecture (Laravel, Next.js, React). Triggers: "modularize", "convert…
git:20260729.3b91eed · audit A · 28 stars
pr-summary skill
fusengine/agents · plugins/ai-pilot/skills/pr-summary/SKILL.md · Summarize current pull request with diff, comments, and changed files. Use when reviewing PRs or before merging.
git:20260729.3b91eed · audit A · 28 stars
react-effects-audit skill
fusengine/agents · plugins/ai-pilot/skills/react-effects-audit/SKILL.md · Use when auditing React or Next.js components for unnecessary or unsafe useEffect usage -- detects 9 anti-patterns from…
git:20260729.3b91eed · audit A · 28 stars
research skill
fusengine/agents · plugins/ai-pilot/skills/research/SKILL.md · Use when researching documentation, best practices, or complex technical investigations -- Context7 + Exa + Sequential…
git:20260729.3b91eed · audit A · 28 stars

Every file in fusengine/agents

Browse by kind, by grade A, or by owner.