cve-watchlist-action-recommendation-generator

Solid

Generate prioritized CVE watchlists and actionable security recommendations for repositories. Use when analyzing CVE scan results, creating security reports, prioritizing vulnerability remediation, or generating security gate reports for CI/CD. Takes CVE scan results (JSON/SARIF from npm audit, pip-audit, Snyk), reachability analysis, and cutoff date as input. Combines severity, reachability, exploitability, and dependency criticality to rank CVEs by practical risk. Outputs markdown reports with concrete next-step guidance (immediate upgrade, monitor, ignore with justification, apply mitigation) suitable for issue trackers, security reviews, and CI security gates.

Data & Documents 252 stars 24 forks Updated 1 months ago Apache-2.0

Install

View on GitHub

Quality Score: 84/100

Stars 20%
80
Recency 20%
75
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# CVE Watchlist & Action Recommendation Generator Generate prioritized CVE watchlists with actionable security recommendations for development and security teams. ## Workflow ### 1. Gather Input Data Collect required inputs: **Required:** - Repository name/path - CVE scan results (JSON/SARIF format from npm audit, pip-audit, Snyk, etc.) - Cutoff date (YYYY-MM-DD) for filtering new CVEs **Optional but recommended:** - Reachability analysis results (which vulnerable code paths are actually used) - Exploit intelligence data (CISA KEV, ExploitDB) - Dependency criticality ratings (how critical each dependency is) **Parse scan results:** ```bash python scripts/parse_scan_results.py scan_results.json auto 2024-01-01 > parsed_cves.json ``` ### 2. Calculate Risk Scores Combine multiple risk factors to prioritize CVEs: ```bash python scripts/calculate_risk_score.py parsed_cves.json reachability.json exploits.json criticality.json > scored_cves.json ``` **Risk scoring formula:** ``` Risk Score = (Severity × 0.35) + (Reachability × 0.30) + (Exploitability × 0.20) + (Dependency Criticality × 0.15) ``` See [risk_scoring.md](references/risk_scoring.md) for detailed methodology. ### 3. Generate Recommendations For each CVE, determine appropriate action based on risk score and context: **Decision tree:** - Risk ≥ 80 (Critical) → Immediate upgrade (24-48h) - Risk 60-79 (High) → Upgrade within days (3-5 days) - Risk 40-59 (Medium) → Next maintenance cycle (2-4 weeks) - Risk 20-39...

Details

Author
ArabelaTso
Repository
ArabelaTso/Skills-4-SE
Created
7 months ago
Last Updated
1 months ago
Language
Python
License
Apache-2.0

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Listed

vulnerability-triage

Prioritise vulnerabilities and produce a ranked remediation plan using CVSS v3.1/v4.0, EPSS, CISA KEV, exploit maturity, asset exposure and criticality, compensating controls, and business context, with tiers (P1..P4), SLAs, risk statements, and asset-owner communications. Use it whenever someone shares a scanner export, a CVE list, a vendor advisory, a "should we patch this now" question, a KEV notification, or a Patch Tuesday summary and wants to know what to fix first, how urgent a specific CVE is for their environment, what to do when a system cannot be patched, how to write a risk acceptance or exception, or how to explain a vulnerability decision to an asset owner or executive. Also use it to tune a scoring model or SLA policy.

0 Updated 1 weeks ago
ftrout
AI & Automation Solid

cve-reachability-analyzer

Analyze CVE reachability in software repositories by examining how vulnerable dependencies are imported and used. Determines whether vulnerable components, classes, or functions are reachable from project code through call chain analysis, reflection detection, dynamic loading patterns, and configuration-gated behavior. Classifies each CVE as likely reachable, possibly reachable, or likely unreachable with supporting evidence. Use when analyzing security vulnerabilities in dependencies, performing post-disclosure CVE triage, assessing vulnerability impact, or when users ask to analyze CVE reachability, check if vulnerabilities are exploitable, or evaluate dependency security risks.

252 Updated 1 months ago
ArabelaTso
AI & Automation Listed

vuln-assessment

Use when producing a vulnerability assessment report — scoring, prioritizing, and remediating findings with CVSS v4.0, EPSS, CISA KEV, CIS Controls v8.1, and NIST SP 800-40. Triggers on "vulnerability assessment", "vuln scan report", "CVE prioritization", "patch compliance", "remediation plan".

0 Updated yesterday
noctua84