Agent skill

Time Aware Dependency Cve Scanner

by ArabelaTso in ArabelaTso/Skills-4-SE

Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date.

Apache-2.0Auto-check passedSecurity

Install Time Aware Dependency Cve Scanner

skills CLI
$ npx skills add ArabelaTso/Skills-4-SE --skill time-aware-dependency-cve-scanner -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArabelaTso/Skills-4-SE time-aware-dependency-cve-scanner --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/time-aware-dependency-cve-scanner .claude/skills/time-aware-dependency-cve-scanner && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
time-aware-dependency-cve-scanner
GitHub stars
253
Token cost
~2.1k tokens
SKILL.md length
584 words
Files
6 (incl. scripts, references)
Skills in repo
170
Repo updated
First seen
Licence
Apache-2.0

At a glance

Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date.

  • Works in 4 steps: Parse Dependencies → Query Vulnerability Databases → Filter by Cutoff Date → …
  • Performing security audits to find new vulnerabilities since last review
  • SKILL.md covers Quick Start, Workflow, Use Cases and Advanced Options, plus 3 more sections
  • Runs Python scripts from its folder; calls python, pip and git; needs GITHUB_TOKEN

What it does

Time Aware Dependency Cve Scanner is an agent skill from ArabelaTso/Skills-4-SE. Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date. Takes a repository path, cutoff date (YYYY-MM-DD), and optional parameters for transitive dependencies. Parses dependency manifests (package.json, pom.xml, requirements.txt, go.mod, Cargo.toml) and lockfiles to extract exact versions. Queries vulnerability databases (OSV.dev, NVD, GitHub Advisory) to identify CVEs disclosed strictly after the cutoff date. Distinguishes between newly disclosed CVEs and previously known CVEs…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `references/dependency_formats.md`, `references/vulnerability_databases.md` and `scripts/parse_dependencies.py`).

It sits in Security, covering Vulnerability scanning and Security review. It works with npm, Go, GitHub and Rust. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.

When your agent uses it

  • Performing security audits to find new vulnerabilities since last review
  • Checking if new CVEs affect a historical codebase version
  • Generating compliance reports showing vulnerability status at specific dates
  • Tracking security posture changes over time

Example prompts

  • “/time-aware-dependency-cve-scanner”

Requirements

  • Python 3
  • A credential in GITHUB_TOKEN

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Parse Dependencies
  2. Query Vulnerability Databases
  3. Filter by Cutoff Date
  4. Generate Report

What it can do on your machine

Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • pip
    • git
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • nvd.nist.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Time Aware Dependency Cve Scanner loads about 2.1k tokens when it runs, and up to ~5.2k if it reads all its reference files. Until then it costs about 226 tokens; SKILL.md has 584 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~226
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 584 words, ~2,100 tokens.

Download SKILL.mdSave it as .claude/skills/time-aware-dependency-cve-scanner/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
time-aware-dependency-cve-scanner
description
Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date. Takes a repository path, cutoff date (YYYY-MM-DD), and optional parameters for transitive dependencies. Parses dependency manifests (package.json, pom.xml, requirements.txt, go.mod, Cargo.toml) and lockfiles to extract exact versions. Queries vulnerability databases (OSV.dev, NVD, GitHub Advisory) to identify CVEs disclosed strictly after the cutoff date. Distinguishes between newly disclosed CVEs and previously known CVEs. Use when: (1) Performing security audits to find new vulnerabilities since last review, (2) Checking if new CVEs affect a historical codebase version, (3) Generating compliance reports showing vulnerability status at specific dates, (4) Tracking security posture changes over time. Supports npm, Maven, pip, Go modules, Cargo, and other major ecosystems.

Time-Aware Dependency CVE Scanner

Scan repositories for newly disclosed CVEs affecting dependencies after a specific cutoff date. This skill helps track when vulnerabilities were introduced and distinguish between pre-existing and newly disclosed security issues.

Quick Start

Basic scan:

bash
python scripts/scan_repository.py /path/to/repo 2023-01-01

Scan only direct dependencies:

bash
python scripts/scan_repository.py /path/to/repo 2023-01-01 --no-transitive

Output as JSON:

bash
python scripts/scan_repository.py /path/to/repo 2023-01-01 --json > report.json

Workflow

1. Parse Dependencies

The scanner automatically detects and parses dependency manifests:

Supported ecosystems:

  • npm: package.json, package-lock.json, yarn.lock
  • Maven: pom.xml
  • Python: requirements.txt, Pipfile.lock, poetry.lock
  • Go: go.mod, go.sum
  • Cargo: Cargo.toml, Cargo.lock

Manual parsing (if needed):

bash
python scripts/parse_dependencies.py /path/to/repo

This extracts:

  • Package names and exact versions
  • Direct vs transitive dependency classification
  • Ecosystem identification

For detailed manifest formats, see references/dependency_formats.md

2. Query Vulnerability Databases

The scanner queries multiple databases to find CVEs:

Primary source: OSV.dev (Open Source Vulnerabilities)

  • No authentication required
  • Broad ecosystem coverage (npm, PyPI, Maven, Go, crates.io, etc.)
  • Built-in version matching
  • Real-time updates

Additional sources:

  • NVD (National Vulnerability Database) - Official CVE records
  • GitHub Security Advisory - GitHub-curated vulnerabilities

Manual CVE query (for testing):

bash
python scripts/query_cves.py lodash 4.17.20 npm 2023-01-01

For database details and API usage, see references/vulnerability_databases.md

3. Filter by Cutoff Date

The scanner filters CVEs to include only those disclosed after the cutoff date:

  • Uses the published date from vulnerability databases
  • Excludes CVEs disclosed before or on the cutoff date
  • Distinguishes newly disclosed vulnerabilities from pre-existing ones

Example:

  • Cutoff date: 2023-01-01
  • CVE-2023-12345 published: 2023-06-15 → Included ✓
  • CVE-2022-98765 published: 2022-11-20 → Excluded ✗
4. Generate Report

The scanner produces a comprehensive report with:

Summary statistics:

  • Total dependencies (direct vs transitive)
  • Number of new CVEs found
  • CVEs affecting direct vs transitive dependencies
  • Severity breakdown (CRITICAL, HIGH, MEDIUM, LOW)

Detailed CVE list: For each CVE:

  • CVE identifier (CVE-XXXX-XXXXX or GHSA-XXXX-XXXX-XXXX)
  • Affected package and ecosystem
  • Version range affected
  • Severity score
  • Disclosure date
  • Summary description

Clear status: If no new CVEs found, explicitly reports "dependency set is clear since the given date"

Use Cases

Security Audit

Scenario: Periodic security review to find vulnerabilities disclosed since last audit

bash
# Last audit was on 2023-06-01, check for new CVEs since then
python scripts/scan_repository.py /path/to/repo 2023-06-01

Output: List of all CVEs disclosed after June 1, 2023 that affect your dependencies

Regression Testing

Scenario: Check if new CVEs affect a specific historical codebase version

bash
# Check if any CVEs disclosed after 2023-01-01 affect code from that date
git checkout <commit-from-2023-01-01>
python scripts/scan_repository.py . 2023-01-01

Output: Shows which vulnerabilities were discovered after the code was written

Show full SKILL.md (242 more words)Show less
Compliance Reporting

Scenario: Generate reports showing vulnerability status at specific dates

bash
# Generate quarterly reports
python scripts/scan_repository.py /path/to/repo 2023-01-01 --json > q1_report.json
python scripts/scan_repository.py /path/to/repo 2023-04-01 --json > q2_report.json
python scripts/scan_repository.py /path/to/repo 2023-07-01 --json > q3_report.json

Output: Time-series data showing when vulnerabilities were disclosed

Tracking Security Posture

Scenario: Monitor how security posture changes over time

bash
# Compare vulnerability counts at different dates
python scripts/scan_repository.py /path/to/repo 2022-01-01 | grep "new CVE"
python scripts/scan_repository.py /path/to/repo 2023-01-01 | grep "new CVE"
python scripts/scan_repository.py /path/to/repo 2024-01-01 | grep "new CVE"

Output: Trend analysis of vulnerability accumulation

Advanced Options

Limit Scan Scope

For large repositories, limit the number of dependencies scanned:

bash
python scripts/scan_repository.py /path/to/repo 2023-01-01 --max-deps 50
Direct Dependencies Only

Skip transitive dependencies to focus on direct dependencies:

bash
python scripts/scan_repository.py /path/to/repo 2023-01-01 --no-transitive
JSON Output for Automation

Output structured JSON for integration with other tools:

bash
python scripts/scan_repository.py /path/to/repo 2023-01-01 --json | jq '.summary'

Understanding Results

Report Structure
TIME-AWARE DEPENDENCY CVE SCAN REPORT
======================================================================
Repository: /path/to/repo
Cutoff Date: 2023-01-01
Scan Time: 2024-02-19T10:30:00

DEPENDENCY SUMMARY
----------------------------------------------------------------------
  Total Dependencies: 150
    - Direct: 25
    - Transitive: 125

CVE SUMMARY
----------------------------------------------------------------------
  ⚠ 5 new CVE(s) found after 2023-01-01
    - Affecting direct dependencies: 2
    - Affecting transitive dependencies: 3

  Severity Breakdown:
    - CRITICAL: 1
    - HIGH: 2
    - MEDIUM: 2

DETAILED CVE LIST
----------------------------------------------------------------------

CVE-2023-12345 [CRITICAL]
  Package: lodash (npm)
  Disclosed: 2023-06-15
  Affected Versions: >=4.0.0, <4.17.21
  Summary: Prototype pollution vulnerability...
Interpreting Severity
  • CRITICAL: Immediate action required, actively exploited
  • HIGH: Serious vulnerability, patch soon
  • MEDIUM: Moderate risk, plan remediation
  • LOW: Minor issue, low priority
  • UNKNOWN: Severity not yet assessed
Next Steps After Scan
  1. Review CVEs: Examine each vulnerability's details
  2. Check exploitability: Determine if your code uses affected functionality
  3. Update dependencies: Upgrade to patched versions
  4. Re-scan: Verify fixes with another scan
  5. Document: Record findings and remediation actions

Troubleshooting

No dependencies found
  • Ensure you're in the repository root
  • Check that manifest files exist (package.json, pom.xml, etc.)
  • Verify file permissions
API rate limits
Parsing errors
  • Ensure manifest files are valid JSON/XML/TOML
  • Check for syntax errors in dependency declarations
  • Some ecosystems may require additional tools (e.g., tomli for Python TOML files)

Dependencies

The scanner scripts require:

  • Python 3.7+
  • requests library: pip install requests
  • Optional: tomli for TOML parsing: pip install tomli

© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/time-aware-dependency-cve-scanner of ArabelaTso/Skills-4-SE.

  • SKILL.md
  • references/dependency_formats.md
  • references/vulnerability_databases.md
  • scripts/parse_dependencies.py
  • scripts/query_cves.py
  • scripts/scan_repository.py

Open the folder on GitHubat commit 4f38503

Compare with similar skills

Time Aware Dependency Cve Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Time Aware Dependency Cve Scanner compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Time Aware Dependency Cve Scanner this skillArabelaTso/Skills-4-SE253—~2.1kAutomated safety check: PassApache-2.0
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Sca AuditOWASP/secure-agent-playbook187—~494Automated safety check: PassCC-BY-4.0
Pre-Commit Security Scanzereight/gitlab-mcp2k1 repos~859Automated safety check: NotesMIT
SkepticRaoFoundation/subtensor389—~660Automated safety check: PassApache-2.0

Similar skills

  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Sca Audit

    OWASP/secure-agent-playbook

    Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.

    187 GitHub stars~494 tokensUpdated 14 days ago
    SecurityAuto-check passed
  • Pre-Commit Security Scan

    zereight/gitlab-mcp

    Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

    2k GitHub starsUsed in 1 repo~859 tokens
    SecurityAuto-check: notes
  • Skeptic

    RaoFoundation/subtensor

    Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

    389 GitHub stars~660 tokensUpdated today
    SecurityAuto-check passed
  • Code Vuln Audit

    zebbern/claude-code-guide

    Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

    4.7k GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check passed

More from ArabelaTso/Skills-4-SE

All 170 skills in this repo
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Metamorphic Test Generator

    ArabelaTso/Skills-4-SE

    Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.

    253 GitHub stars~798 tokensUpdated 1 mo ago
    Auto-check passed
  • Reproduction Trace Instrumenter

    ArabelaTso/Skills-4-SE

    Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.

    253 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spring Mvc To Boot Migrator

    ArabelaTso/Skills-4-SE

    Automatically migrate Spring MVC applications to Spring Boot.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • State Snapshot Instrumenter

    ArabelaTso/Skills-4-SE

    Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Time Aware Dependency Cve Scanner

What does Time Aware Dependency Cve Scanner do?

Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date. Time Aware Dependency Cve Scanner is an agent skill from ArabelaTso/Skills-4-SE. Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date.

When should I use Time Aware Dependency Cve Scanner?

Time Aware Dependency Cve Scanner fits situations like: performing security audits to find new vulnerabilities since last review; checking if new CVEs affect a historical codebase version; generating compliance reports showing vulnerability status at specific dates; tracking security posture changes over time.

How do I install Time Aware Dependency Cve Scanner in Claude Code?

Run `npx skills add ArabelaTso/Skills-4-SE --skill time-aware-dependency-cve-scanner -a claude-code`. Or copy the skill folder (skills/time-aware-dependency-cve-scanner in ArabelaTso/Skills-4-SE) into .claude/skills/time-aware-dependency-cve-scanner in your project. Claude Code loads it when a task matches its description.

How do I install Time Aware Dependency Cve Scanner in Codex?

Run `npx skills add ArabelaTso/Skills-4-SE --skill time-aware-dependency-cve-scanner -a codex`. Or copy the skill folder (skills/time-aware-dependency-cve-scanner in ArabelaTso/Skills-4-SE) into .agents/skills/time-aware-dependency-cve-scanner in your project. Codex loads it when a task matches its description.

Can I use Time Aware Dependency Cve Scanner in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill time-aware-dependency-cve-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/time-aware-dependency-cve-scanner, .gemini/skills/time-aware-dependency-cve-scanner, .github/skills/time-aware-dependency-cve-scanner and .opencode/skills/time-aware-dependency-cve-scanner in your project.

What does Time Aware Dependency Cve Scanner need to run?

Going by SKILL.md and its folder, Time Aware Dependency Cve Scanner needs Python for the scripts in its folder, the command-line tools its instructions call (python, pip, git and jq) and credentials named GITHUB_TOKEN. Our summary lists: Python 3; A credential in GITHUB_TOKEN.

Does Time Aware Dependency Cve Scanner access the network?

SKILL.md names 1 domain. As links in the text: nvd.nist.gov. This is read from the text; nothing was executed.

Is Time Aware Dependency Cve Scanner safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Time Aware Dependency Cve Scanner use?

Time Aware Dependency Cve Scanner is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Time Aware Dependency Cve Scanner use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.

What are the alternatives to Time Aware Dependency Cve Scanner?

Skills that share tags, products or a category with Time Aware Dependency Cve Scanner: Pyspector Security Audit (ParzivalHack/PySpector, 151 stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Sca Audit (OWASP/secure-agent-playbook, 187 stars) and Pre-Commit Security Scan (zereight/gitlab-mcp, 2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Time Aware Dependency Cve Scanner?

ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 170 skills in this directory. The repository was last updated on August 21, 2026.

Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.