cve-research · git:20260729.3b91eed · 2026-07-29 · sha256 c8c72892432e4408
cve-research git:20260729.3b91eedA
Immutable. This exact content is served forever at /api/v1/blob/c8c72892432e4408.
--- name: cve-research description: "Use when checking a specific dependency or package version for known CVEs and security advisories." argument-hint: "<package-name> [version]" user-invocable: true --- <objective> This skill researches known vulnerabilities for a specific dependency across multiple sources: OSV.dev (npm, PyPI, Go, crates, Maven), NVD (CVSS scoring), GitHub Advisory Database (maintainer responses), and Exa web search for advisories not yet indexed. It queries OSV.dev first for speed and accuracy, cross-checks NVD for CVSS scoring, uses Exa for recent advisories, and checks GitHub Advisory for maintainer responses, then cross-references findings and prioritizes by CVSS score and exploitability — CRITICAL (9.0-10.0) fixed immediately, HIGH (7.0-8.9) before merge, MEDIUM (4.0-6.9) planned, LOW (0.1-3.9) documented — reporting fix versions and workarounds. Out of scope: this is a single-dependency lookup, not a full project dependency sweep (use dependency-audit for that). </objective> # CVE Research Skill ## Overview Research known vulnerabilities for project dependencies using multiple sources. ## Data Sources | Source | API | Coverage | |--------|-----|----------| | NVD | nvd.nist.gov/vuln/api | All CVEs | | OSV.dev | api.osv.dev | npm, PyPI, Go, crates, Maven | | GitHub Advisory | github.com/advisories | npm, pip, composer, cargo | | Exa Search | Via MCP | Real-time web search | ## Workflow 1. **Extract** dependencies from project (package.json, etc.) 2. **Query** each source for known CVEs 3. **Cross-reference** findings across sources 4. **Prioritize** by CVSS score and exploitability 5. **Report** with fix versions and workarounds ## Query Strategy For each dependency: 1. Search OSV.dev first (fastest, most accurate for packages) 2. Cross-check NVD for CVSS scoring 3. Use Exa for recent advisories not yet in databases 4. Check GitHub Advisory for maintainer responses ## Severity Mapping | CVSS Score | Severity | Action | |------------|----------|--------| | 9.0 - 10.0 | CRITICAL | Fix immediately | | 7.0 - 8.9 | HIGH | Fix before merge | | 4.0 - 6.9 | MEDIUM | Plan fix | | 0.1 - 3.9 | LOW | Document | ## References - [CVE APIs Reference](references/cve-apis.md) - [Query Templates](references/templates/cve-query.md)