Agent skill

Cisco Psirt Advisories

by automateyournetwork in automateyournetwork/netclaw

Check whether a running Cisco software version is affected by a published PSIRT security advisory - by OS version, CVE, or advisory ID, with severity and CVSS.

Apache-2.0Auto-check passedSecurity

Install Cisco Psirt Advisories

skills CLI
$ npx skills add automateyournetwork/netclaw --skill cisco-psirt-advisories -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install automateyournetwork/netclaw cisco-psirt-advisories --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/automateyournetwork/netclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/workspace/skills/cisco-psirt-advisories .claude/skills/cisco-psirt-advisories && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cisco-psirt-advisories
GitHub stars
676
Token cost
~2.2k tokens
SKILL.md length
989 words
Files
1
Skills in repo
120
Repo updated
First seen
Licence
Apache-2.0

At a glance

Check whether a running Cisco software version is affected by a published PSIRT security advisory - by OS version, CVE, or advisory ID, with severity and CVSS.

  • Works in 6 steps: check_version — is this version affected? → check_versions — a fleet in one call → check_cve — which Cisco advisories cover… → …
  • Asked if a device
  • SKILL.md covers Read this first — an empty…, The two-step chain, Available Tools and Version formats differ per…, plus 5 more sections
  • Calls python3

What it does

Cisco Psirt Advisories is an agent skill from automateyournetwork/netclaw. Check whether a running Cisco software version is affected by a published PSIRT security advisory - by OS version, CVE, or advisory ID, with severity and CVSS. Covers IOS, IOS-XE, NX-OS, ASA, FTD, FMC and ACI. Use when asked if a device or fleet is vulnerable, when triaging a Cisco CVE, or when auditing software versions against Cisco advisories.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning. It works with iOS. The repository describes itself as: An AI agent that claws through your network. The licence is Apache-2.0.

When your agent uses it

  • Asked if a device
  • Fleet is vulnerable
  • Triaging a Cisco CVE
  • Auditing software versions against Cisco advisories

Example prompts

  • “/cisco-psirt-advisories”

Requirements

  • Python 3
  • A credential in CISCO_CLIENT_SECRET

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. check_version — is this version affected?
  2. check_versions — a fleet in one call
  3. check_cve — which Cisco advisories cover this CVE?
  4. check_advisory — one advisory by id
  5. list_recent — what has Cisco published lately?
  6. psirt_status — check the budget before a sweep

What it can do on your machine

Read from SKILL.md and the folder at commit aa90e7d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cisco Psirt Advisories loads about 2.2k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 989 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from automateyournetwork/netclaw at commit aa90e7d, republished under its Apache-2.0 licence (© automateyournetwork). 989 words, ~2,181 tokens.

Download SKILL.mdSave it as .claude/skills/cisco-psirt-advisories/SKILL.md (or your agent's skills folder).
name
cisco-psirt-advisories
description
Check whether a running Cisco software version is affected by a published PSIRT security advisory - by OS version, CVE, or advisory ID, with severity and CVSS. Covers IOS, IOS-XE, NX-OS, ASA, FTD, FMC and ACI. Use when asked if a device or fleet is vulnerable, when triaging a Cisco CVE, or when auditing software versions against Cisco advisories.
license
Apache-2.0
user-invocable
true

Cisco PSIRT Advisory Checks

Answers one question well: is the software this device is running affected by a Cisco security advisory?

Read this first — an empty result is not a clean bill of health

Every tool returns one of five outcome values. Two of them look similar in the data and mean completely different things:

outcomeWhat it means
advisories_foundCisco has published advisories for this version
none_publishedCisco has published nothing for this version — NOT "the device is secure"
normalisation_failedThe version could not be parsed. Nothing was checked.
unsupported_ostypeNot a PSIRT OS family (includes iosxr and every non-Cisco platform)
api_errorAuth failure, rate limit, or a version Cisco has no record of

Never report "no advisories" as "not vulnerable". none_published means Cisco has published nothing matching that exact version string. It says nothing about unpatched-but-unpublished issues, configuration weaknesses, or anything outside Cisco's PSIRT process.

Never treat normalisation_failed or api_error as good news. Both mean the question went unasked. In a fleet sweep, check the outcome_summary counts before telling anyone the fleet is clean — devices in those two buckets were never checked at all.

The two-step chain

This server never contacts a device. It has no transport, no credentials for your network, and no way to read a version. You supply the version:

Step 1 — read the version off the device.

bash
# Cisco platforms: pyATS
python3 $MCP_CALL "python3 -u $PYATS_MCP_SCRIPT" run_show_command \
  '{"device_name":"cat9k-1","command":"show version"}'

# Anything else, or when pyATS has no parser: the multivendor CLI driver
python3 $MCP_CALL "python3 -u $MULTIVENDOR_MCP_SCRIPT" device_run_command \
  '{"device":"rtr-1","command":"show version"}'

Step 2 — pass it here. Full show version output is fine; the banner is parsed.

bash
python3 $MCP_CALL "python3 -u $CISCO_PSIRT_MCP_SCRIPT" check_version \
  '{"ostype":"iosxe","version":"17.3.1"}'

Do not skip step 1 and guess a version. The server refuses to infer one — a guessed version returns advisories for software the device is not running, which is worse than no answer.

Available Tools

1. check_version — is this version affected?
bash
python3 $MCP_CALL "python3 -u $CISCO_PSIRT_MCP_SCRIPT" check_version \
  '{"ostype":"iosxe","version":"17.3.1"}'
  • ostype (required): ios | iosxe | nxos | asa | fmc | ftd | aci
  • version (required): bare version or full show version output
  • refresh (optional, default false): bypass the 6-hour cache

Verified: iosxe + 17.3.1 returns 122 advisories.

2. check_versions — a fleet in one call
bash
python3 $MCP_CALL "python3 -u $CISCO_PSIRT_MCP_SCRIPT" check_versions \
  '{"devices":[{"name":"cat9k-1","ostype":"iosxe","version":"17.3.1"},
               {"name":"n9k-1","ostype":"nxos","version":"9.3(5)"}]}'

Prefer this over looping check_version. It de-duplicates by version first, so 60 devices running 12 distinct versions cost 12 API calls rather than 60 — the difference between one-third of the per-minute budget and twice it. One device failing never aborts the others.

3. check_cve — which Cisco advisories cover this CVE?
bash
python3 $MCP_CALL "python3 -u $CISCO_PSIRT_MCP_SCRIPT" check_cve '{"cve":"CVE-2024-20353"}'
4. check_advisory — one advisory by id
bash
python3 $MCP_CALL "python3 -u $CISCO_PSIRT_MCP_SCRIPT" check_advisory \
  '{"advisory_id":"cisco-sa-bootp-WuBhNBxA"}'
5. list_recent — what has Cisco published lately?
bash
python3 $MCP_CALL "python3 -u $CISCO_PSIRT_MCP_SCRIPT" list_recent \
  '{"severity":"critical","start_date":"2026-01-01","end_date":"2026-07-31"}'

Verified: critical across 2026 to date returns 15 advisories.

6. psirt_status — check the budget before a sweep
bash
python3 $MCP_CALL "python3 -u $CISCO_PSIRT_MCP_SCRIPT" psirt_status '{}'

Reports auth state, remaining rate budget, cache statistics, and which OS families are supported. Contains no credential values. Worth calling before a large sweep.

Version formats differ per family — and they contradict each other

This is the most common source of a wrong answer. The server normalises for you, but you must collect the right number in the first place.

OSTypeFormat Cisco expectsExample
iosxedotted17.3.1, 17.03.01, 17.3.1a
iosparenthesised, letter outside15.2(4)E, 15.2(4)E10
nxosparenthesised9.3(5)
asadotted9.16.1
ftd / fmcdotted7.0.1
aciparenthesised, letter inside15.2(3e), 16.0(3e)

Note the contradiction: iosxe rejects 17.3(1) while ios rejects 15.2.4E. The same-looking transformation runs in opposite directions depending on family. The server handles the conversion; pass whatever the device reported.

ACI is the trap. It wants the switch image version (15.2(3e)), not the APIC controller version — 5.2(3e) is rejected outright. Collect it from a switch, not the APIC.

IOS-XR is not supported, and this will surprise you

iosxr is not an OSType on this API. Every version tried (7.5.2, 6.6.3, 24.1.1) returns HTTP 404, against an iosxe 200 control in the same session.

This is worth flagging to the user rather than working around silently, because NetClaw can reach IOS-XR devices through pyATS — so an operator will reasonably expect the version check to work. For IOS-XR, fall back to check_cve or advisory lookup by product id, and say plainly that per-version checking is unavailable for that platform.

Show full SKILL.md (352 more words)Show less

Where this ends and nvd-cve begins

Both answer vulnerability questions; they are not interchangeable, and neither is a substitute for the other.

QuestionUse
"Is this Cisco version affected by a Cisco advisory?"this skill
"What is CVE-2024-20353, what is its CVSS, what is affected?"nvd-cve
"Has Cisco issued an advisory for this CVE?"this skill (check_cve)
"Does any vendor have a known CVE matching this software?"nvd-cve

Either can legitimately be empty while the other is not. Cisco may publish an advisory before an NVD entry exists; NVD may hold a CVE for which Cisco has issued no advisory. When a security question matters, check both and say which one answered.

Rate limits are shared and tight

5 calls/second and 30 calls/minute, shared across every caller of the credential. 30/minute is the real constraint. The server handles this automatically — de-duplicating by version, serving from a 6-hour cache, pacing, and backing off on 429 — but two habits defeat it:

  • Looping check_version per device instead of using check_versions.
  • Passing refresh: true routinely. It disables the cache. Use it during an incident when cache age is itself the question, not as a default.

What this API does not provide

Measured, not inferred from documentation — do not spend time re-testing these:

  • Bug, EoX, Case and Serial-to-Info APIs return 403 under the API Console grant.
  • CX Cloud returns 504 on all seven paths tried. It needs a separate tenant subscription.
  • IOS-XR returns 404, as above.

Reporting results to a user

Lead with the count and the worst severity, not the whole list. Then, if the answer was none_published, say what that does and does not mean — the distinction is the point of this skill, and it is the part a reader will otherwise get wrong.

Good: "cat9k-1 on IOS-XE 17.3.1 has 122 published advisories, 4 of them Critical (highest CVSS 9.8). Recommend reviewing the Critical set first."

Good: "n9k-1 on NX-OS 9.3(5) — Cisco has published no advisory matching this exact version. That is not confirmation the device is secure; it means nothing is published for this version string."

Bad: "n9k-1 is not vulnerable." Never say this.

© automateyournetwork, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in workspace/skills/cisco-psirt-advisories of automateyournetwork/netclaw.

Open the folder on GitHubat commit aa90e7d

Compare with similar skills

Cisco Psirt Advisories next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cisco Psirt Advisories compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cisco Psirt Advisories this skillautomateyournetwork/netclaw676—~2.2kAutomated safety check: PassApache-2.0
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT
Cve Remediationrundeck/rundeck6.3k—~2.9kAutomated safety check: PassApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Cve Remediation

    rundeck/rundeck

    Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    190 GitHub stars~2.5k tokensUpdated 14 days ago
    SecurityAuto-check: notes
  • Write Cve Rule

    evdenis/cvehound

    Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.

    138 GitHub stars~2.5k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from automateyournetwork/netclaw

All 120 skills in this repo
  • EVE-NG Lab Topology Design

    automateyournetwork/netclaw

    Entry point for designing EVE-NG network labs: classifies the request, gathers missing requirements, proposes options and validates the resulting topology.

    677 GitHub stars~612 tokensUpdated today
    Auto-check passed
  • ACI Policy Change Deployment

    automateyournetwork/netclaw

    Deploys Cisco ACI policy changes only behind an approved ServiceNow Change Request, capturing pre and post-change fault baselines and rolling back automatically on a fault delta.

    677 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Cisco ACI Fabric Health Audit

    automateyournetwork/netclaw

    Runs a phased health audit of a Cisco ACI fabric through MCP tools: node status, links, tenant and policy review, faults and endpoint learning.

    677 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Anta Validation

    automateyournetwork/netclaw

    Validate Arista EOS network state against ANTA's pre-built 208-test catalogue, with structured pass/fail verdicts.

    677 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Arista Cvp

    automateyournetwork/netclaw

    Arista CloudVision Portal (CVP) automation via REST API — device inventory, events, connectivity monitoring, tag management (4 tools).

    677 GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • AWS Cloud Monitoring

    automateyournetwork/netclaw

    AWS CloudWatch monitoring — metrics, alarms, log queries, VPC flow log analysis, network performance.

    677 GitHub stars~1k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Cisco Psirt Advisories

What does Cisco Psirt Advisories do?

Check whether a running Cisco software version is affected by a published PSIRT security advisory - by OS version, CVE, or advisory ID, with severity and CVSS. Cisco Psirt Advisories is an agent skill from automateyournetwork/netclaw. Check whether a running Cisco software version is affected by a published PSIRT security advisory - by OS version, CVE, or advisory ID, with severity and CVSS.

When should I use Cisco Psirt Advisories?

Cisco Psirt Advisories fits situations like: asked if a device; fleet is vulnerable; triaging a Cisco CVE; auditing software versions against Cisco advisories.

How do I install Cisco Psirt Advisories in Claude Code?

Run `npx skills add automateyournetwork/netclaw --skill cisco-psirt-advisories -a claude-code`. Or copy the skill folder (workspace/skills/cisco-psirt-advisories in automateyournetwork/netclaw) into .claude/skills/cisco-psirt-advisories in your project. Claude Code loads it when a task matches its description.

How do I install Cisco Psirt Advisories in Codex?

Run `npx skills add automateyournetwork/netclaw --skill cisco-psirt-advisories -a codex`. Or copy the skill folder (workspace/skills/cisco-psirt-advisories in automateyournetwork/netclaw) into .agents/skills/cisco-psirt-advisories in your project. Codex loads it when a task matches its description.

Can I use Cisco Psirt Advisories in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add automateyournetwork/netclaw --skill cisco-psirt-advisories -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cisco-psirt-advisories, .gemini/skills/cisco-psirt-advisories, .github/skills/cisco-psirt-advisories and .opencode/skills/cisco-psirt-advisories in your project.

What does Cisco Psirt Advisories need to run?

Going by SKILL.md and its folder, Cisco Psirt Advisories needs the command-line tools its instructions call (python3). Our summary lists: Python 3; A credential in CISCO_CLIENT_SECRET.

Does Cisco Psirt Advisories access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cisco Psirt Advisories safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cisco Psirt Advisories use?

Cisco Psirt Advisories is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cisco Psirt Advisories use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cisco Psirt Advisories?

Skills that share tags, products or a category with Cisco Psirt Advisories: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Shiro Attack CLI (SummerSec/ShiroAttack2, 2.6k stars), Cve Remediation (rundeck/rundeck, 6.3k stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cisco Psirt Advisories?

automateyournetwork (a GitHub user) maintains it in automateyournetwork/netclaw, which has 676 GitHub stars. The repository holds 120 skills in this directory. The repository was last updated on October 9, 2026.

Source: automateyournetwork/netclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.