Agent skill

Cve Watchlist Action Recommendation Generator

by ArabelaTso in ArabelaTso/Skills-4-SE

Generate prioritized CVE watchlists and actionable security recommendations for repositories.

Apache-2.0Auto-check passedSecurity

Install Cve Watchlist Action Recommendation Generator

skills CLI
$ npx skills add ArabelaTso/Skills-4-SE --skill cve-watchlist-action-recommendation-generator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArabelaTso/Skills-4-SE cve-watchlist-action-recommendation-generator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cve-watchlist-action-recommendation-generator .claude/skills/cve-watchlist-action-recommendation-generator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cve-watchlist-action-recommendation-generator
GitHub stars
253
Token cost
~1.7k tokens
SKILL.md length
271 words
Files
6 (incl. scripts, references, assets)
Skills in repo
170
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generate prioritized CVE watchlists and actionable security recommendations for repositories.

  • Works in 4 steps: Gather Input Data → Calculate Risk Scores → Generate Recommendations → …
  • Analyzing CVE scan results
  • SKILL.md covers Workflow, Input Formats and Example Output
  • Runs Python scripts from its folder; calls python

What it does

Cve Watchlist Action Recommendation Generator is an agent skill from ArabelaTso/Skills-4-SE. Generate prioritized CVE watchlists and actionable security recommendations for repositories. Use when analyzing CVE scan results, creating security reports, prioritizing vulnerability remediation, or generating security gate reports for CI/CD. Takes CVE scan results (JSON/SARIF from npm audit, pip-audit, Snyk), reachability analysis, and cutoff date as input. Combines severity, reachability, exploitability, and dependency criticality to rank CVEs by practical risk. Outputs markdown reports with concrete…

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts, reference files and assets (for example `assets/report_template.md`, `references/action_guidelines.md` and `references/risk_scoring.md`).

It sits in Security, covering Vulnerability scanning. It works with Snyk. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.

When your agent uses it

  • Analyzing CVE scan results
  • Creating security reports
  • Prioritizing vulnerability remediation
  • Generating security gate reports for CI/CD

Example prompts

  • “/cve-watchlist-action-recommendation-generator”

Requirements

  • Python 3
  • Node.js

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Gather Input Data
  2. Calculate Risk Scores
  3. Generate Recommendations
  4. Generate Report

What it can do on your machine

Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cve Watchlist Action Recommendation Generator loads about 1.7k tokens when it runs, and up to ~5.1k if it reads all its reference files. Until then it costs about 180 tokens; SKILL.md has 271 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~180
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 271 words, ~1,663 tokens.

Download SKILL.mdSave it as .claude/skills/cve-watchlist-action-recommendation-generator/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
cve-watchlist-action-recommendation-generator
description
Generate prioritized CVE watchlists and actionable security recommendations for repositories. Use when analyzing CVE scan results, creating security reports, prioritizing vulnerability remediation, or generating security gate reports for CI/CD. Takes CVE scan results (JSON/SARIF from npm audit, pip-audit, Snyk), reachability analysis, and cutoff date as input. Combines severity, reachability, exploitability, and dependency criticality to rank CVEs by practical risk. Outputs markdown reports with concrete next-step guidance (immediate upgrade, monitor, ignore with justification, apply mitigation) suitable for issue trackers, security reviews, and CI security gates.

CVE Watchlist & Action Recommendation Generator

Generate prioritized CVE watchlists with actionable security recommendations for development and security teams.

Workflow

1. Gather Input Data

Collect required inputs:

Required:

  • Repository name/path
  • CVE scan results (JSON/SARIF format from npm audit, pip-audit, Snyk, etc.)
  • Cutoff date (YYYY-MM-DD) for filtering new CVEs

Optional but recommended:

  • Reachability analysis results (which vulnerable code paths are actually used)
  • Exploit intelligence data (CISA KEV, ExploitDB)
  • Dependency criticality ratings (how critical each dependency is)

Parse scan results:

bash
python scripts/parse_scan_results.py scan_results.json auto 2024-01-01 > parsed_cves.json
2. Calculate Risk Scores

Combine multiple risk factors to prioritize CVEs:

bash
python scripts/calculate_risk_score.py parsed_cves.json reachability.json exploits.json criticality.json > scored_cves.json

Risk scoring formula:

Risk Score = (Severity × 0.35) + (Reachability × 0.30) + (Exploitability × 0.20) + (Dependency Criticality × 0.15)

See risk_scoring.md for detailed methodology.

3. Generate Recommendations

For each CVE, determine appropriate action based on risk score and context:

Decision tree:

  • Risk ≥ 80 (Critical) → Immediate upgrade (24-48h)
  • Risk 60-79 (High) → Upgrade within days (3-5 days)
  • Risk 40-59 (Medium) → Next maintenance cycle (2-4 weeks)
  • Risk 20-39 (Low) → Monitor or defer
  • Risk < 20 (Minimal) → Ignore with justification

See action_guidelines.md for complete decision tree and recommendation templates.

4. Generate Report

Create markdown-formatted report using template:

Report structure:

  1. Executive Summary (CVE counts by risk tier)
  2. Prioritized CVE Watchlist (grouped by risk tier)
  3. For each CVE:
    • Risk score and breakdown
    • Affected package and versions
    • Reachability status
    • Exploit availability
    • Concrete action recommendation
    • Upgrade commands
    • Mitigation options (if applicable)
  4. Summary of Actions (immediate, short-term, medium-term)
  5. Dependency Overview
  6. Next Steps

Use template from assets/report_template.md.

Input Formats

CVE Scan Results

npm audit (JSON):

json
{
  "vulnerabilities": {
    "package-name": {
      "via": [{
        "cve": ["CVE-2024-1234"],
        "severity": "high",
        "title": "SQL Injection",
        "url": "https://..."
      }],
      "fixAvailable": {"version": "2.0.0"}
    }
  }
}

pip-audit (JSON):

json
{
  "dependencies": [{
    "name": "package-name",
    "version": "1.0.0",
    "vulns": [{
      "id": "CVE-2024-1234",
      "fix_versions": ["2.0.0"],
      "description": "..."
    }]
  }]
}

Snyk (JSON):

json
{
  "vulnerabilities": [{
    "id": "SNYK-...",
    "identifiers": {"CVE": ["CVE-2024-1234"]},
    "packageName": "package-name",
    "severity": "high",
    "cvssScore": 7.5
  }]
}
Reachability Analysis
json
{
  "package-name": {
    "status": "direct_call",
    "details": "Called from src/auth.js:42"
  },
  "other-package": {
    "status": "not_reachable",
    "details": "Dev dependency only"
  }
}

Status values: direct_call, indirect_call, imported_unused, not_reachable, unknown

Exploit Intelligence
json
{
  "CVE-2024-1234": {
    "actively_exploited": true,
    "public_exploit": true,
    "poc_available": true,
    "source": "CISA KEV"
  }
}
Dependency Criticality
json
{
  "package-name": {
    "level": "critical",
    "reason": "Handles authentication and authorization"
  },
  "dev-tool": {
    "level": "minimal",
    "reason": "Development-only linting tool"
  }
}

Levels: critical, high, medium, low, minimal

Example Output

markdown
# CVE Security Report

**Repository**: my-app
**Cutoff Date**: 2024-01-01
**New CVEs**: 5

| Risk Tier | Count | Action Required |
|-----------|-------|-----------------|
| 🔴 Critical | 1 | Immediate (24-48h) |
| 🟠 High | 2 | Within days (3-5d) |
| 🟡 Medium | 1 | Next cycle (2-4w) |
| 🟢 Low | 1 | Monitor |

---

### 🔴 Critical Risk

#### CVE-2024-1234: SQL Injection in database-driver

**Risk Score**: 96 / 100 (Critical)

**Affected Package**: database-driver@1.2.3

**Severity**: Critical (CVSS 9.8)

**Reachability**: Direct call from src/db/query.js:42

**Exploitability**: Public exploit available (ExploitDB)

**Action**: Immediate upgrade required

**Steps**:
1. Upgrade database-driver from 1.2.3 to 2.0.0
2. Run full test suite
3. Deploy with rollback plan

**Command**:
```bash
npm install database-driver@2.0.0

Risk if not addressed: Attackers can execute arbitrary SQL queries, leading to data breach


## Tips

- **Always include reachability data** when available - it significantly improves prioritization accuracy
- **Check for breaking changes** in fix versions before recommending immediate upgrades
- **Document assumptions** when data is missing (e.g., "Assuming moderate risk due to unknown reachability")
- **Provide specific commands** for each package manager (npm, pip, maven, etc.)
- **Include mitigation options** for high-risk CVEs when upgrades are blocked
- **Link to CVE details** and security advisories for further investigation
- **Group multiple CVEs** in the same package when a single upgrade fixes all

## Resources

### scripts/
- `parse_scan_results.py` - Parse CVE scan results from npm audit, pip-audit, Snyk, SARIF
- `calculate_risk_score.py` - Calculate composite risk scores from multiple factors

### references/
- `risk_scoring.md` - Risk scoring methodology and factor calculations
- `action_guidelines.md` - Decision tree for generating recommendations

### assets/
- `report_template.md` - Markdown report template structure

© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references, assets) in skills/cve-watchlist-action-recommendation-generator of ArabelaTso/Skills-4-SE.

  • SKILL.md
  • assets/report_template.md
  • references/action_guidelines.md
  • references/risk_scoring.md
  • scripts/calculate_risk_score.py
  • scripts/parse_scan_results.py

Open the folder on GitHubat commit 4f38503

Compare with similar skills

Cve Watchlist Action Recommendation Generator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cve Watchlist Action Recommendation Generator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cve Watchlist Action Recommendation Generator this skillArabelaTso/Skills-4-SE253—~1.7kAutomated safety check: PassApache-2.0
Dep Securitytinyfish-io/tinyfish-cookbook2.2k—~2.4kAutomated safety check: PassMIT
Security AuditAedelon/claude-code-blueprint120—~1.6kAutomated safety check: NotesCustom licence
Security Scanbagofwords1/bagofwords459—~1.7kAutomated safety check: PassCustom licence
Vul Analyseinfometa/workbuddyskills348—~3.9kAutomated safety check: PassNone
Vulnerability Scanningsecondsky/claude-skills227—~799Automated safety check: PassMIT

Similar skills

  • Dep Security

    tinyfish-io/tinyfish-cookbook

    Check every dependency in a package.json against live CVE databases and security advisories in real time — specifically targeting vulnerabilities disclosed in the last 48 hours, the window that…

    2.2k GitHub stars~2.4k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Security Audit

    Aedelon/claude-code-blueprint

    Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults.

    120 GitHub stars~1.6k tokensUpdated 7 mo ago
    SecurityAuto-check: notes
  • Security Scan

    bagofwords1/bagofwords

    Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes.

    459 GitHub stars~1.7k tokensUpdated today
    SecurityAuto-check passed
  • Vul Analyse

    infometa/workbuddyskills

    漏扫报告分析 Skill。输入主流厂商漏扫报告(绿盟/深信服/悬镜/明鉴/等保/奇安信/启明/华云安/长亭/Nessus/Trivy/Grype/Snyk/OpenVAS 等 Excel/HTML/JSON/XML/.nessus 格式),自动提取漏洞并去重,可选对接知识库 Provider(修复历史)和威胁情报 Provider(CVE 情报),生成 7…

    348 GitHub stars~3.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Vulnerability Scanning

    secondsky/claude-skills

    Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit.

    227 GitHub stars~799 tokensUpdated 13 days ago
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 12 days ago
    SecurityAuto-check passed

More from ArabelaTso/Skills-4-SE

All 170 skills in this repo
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Metamorphic Test Generator

    ArabelaTso/Skills-4-SE

    Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.

    253 GitHub stars~798 tokensUpdated 1 mo ago
    Auto-check passed
  • Reproduction Trace Instrumenter

    ArabelaTso/Skills-4-SE

    Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.

    253 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spring Mvc To Boot Migrator

    ArabelaTso/Skills-4-SE

    Automatically migrate Spring MVC applications to Spring Boot.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • State Snapshot Instrumenter

    ArabelaTso/Skills-4-SE

    Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Taint Instrumentation Assistant

    ArabelaTso/Skills-4-SE

    Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations.

    253 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Cve Watchlist Action Recommendation Generator

What does Cve Watchlist Action Recommendation Generator do?

Generate prioritized CVE watchlists and actionable security recommendations for repositories. Cve Watchlist Action Recommendation Generator is an agent skill from ArabelaTso/Skills-4-SE. Generate prioritized CVE watchlists and actionable security recommendations for repositories.

When should I use Cve Watchlist Action Recommendation Generator?

Cve Watchlist Action Recommendation Generator fits situations like: analyzing CVE scan results; creating security reports; prioritizing vulnerability remediation; generating security gate reports for CI/CD.

How do I install Cve Watchlist Action Recommendation Generator in Claude Code?

Run `npx skills add ArabelaTso/Skills-4-SE --skill cve-watchlist-action-recommendation-generator -a claude-code`. Or copy the skill folder (skills/cve-watchlist-action-recommendation-generator in ArabelaTso/Skills-4-SE) into .claude/skills/cve-watchlist-action-recommendation-generator in your project. Claude Code loads it when a task matches its description.

How do I install Cve Watchlist Action Recommendation Generator in Codex?

Run `npx skills add ArabelaTso/Skills-4-SE --skill cve-watchlist-action-recommendation-generator -a codex`. Or copy the skill folder (skills/cve-watchlist-action-recommendation-generator in ArabelaTso/Skills-4-SE) into .agents/skills/cve-watchlist-action-recommendation-generator in your project. Codex loads it when a task matches its description.

Can I use Cve Watchlist Action Recommendation Generator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill cve-watchlist-action-recommendation-generator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cve-watchlist-action-recommendation-generator, .gemini/skills/cve-watchlist-action-recommendation-generator, .github/skills/cve-watchlist-action-recommendation-generator and .opencode/skills/cve-watchlist-action-recommendation-generator in your project.

What does Cve Watchlist Action Recommendation Generator need to run?

Going by SKILL.md and its folder, Cve Watchlist Action Recommendation Generator needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3; Node.js.

Does Cve Watchlist Action Recommendation Generator access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cve Watchlist Action Recommendation Generator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Cve Watchlist Action Recommendation Generator use?

Cve Watchlist Action Recommendation Generator is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cve Watchlist Action Recommendation Generator use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to Cve Watchlist Action Recommendation Generator?

Skills that share tags, products or a category with Cve Watchlist Action Recommendation Generator: Dep Security (tinyfish-io/tinyfish-cookbook, 2.2k stars), Security Audit (Aedelon/claude-code-blueprint, 120 stars), Security Scan (bagofwords1/bagofwords, 459 stars) and Vul Analyse (infometa/workbuddyskills, 348 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cve Watchlist Action Recommendation Generator?

ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 170 skills in this directory. The repository was last updated on August 21, 2026.

Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.