Install the "cvss-score-extraction" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/cvss-score-extraction into .claude/skills/cvss-score-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cvss-score-extraction", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add benchflow-ai/skillsbench --skill cvss-score-extraction -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "cvss-score-extraction" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/cvss-score-extraction into .agents/skills/cvss-score-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cvss-score-extraction", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add benchflow-ai/skillsbench --skill cvss-score-extraction -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "cvss-score-extraction" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/cvss-score-extraction into .cursor/skills/cvss-score-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cvss-score-extraction", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add benchflow-ai/skillsbench --skill cvss-score-extraction -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "cvss-score-extraction" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/cvss-score-extraction into .gemini/skills/cvss-score-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cvss-score-extraction", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add benchflow-ai/skillsbench --skill cvss-score-extraction -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "cvss-score-extraction" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/cvss-score-extraction into .github/skills/cvss-score-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cvss-score-extraction", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add benchflow-ai/skillsbench --skill cvss-score-extraction -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "cvss-score-extraction" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/cvss-score-extraction into .opencode/skills/cvss-score-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cvss-score-extraction", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
cvss-score-extraction
GitHub stars
1.8k
Token cost
~2.3k tokens
SKILL.md length
389 words
Files
1
Skills in repo
189
Repo updated
First seen
Licence
Apache-2.0
At a glance
Extract CVSS (Common Vulnerability Scoring System) scores from vulnerability data sources with proper fallback handling.
Works in 3 steps: NVD (National Vulnerability Database) → GHSA (GitHub Security Advisory) → RedHat Security Data
SKILL.md covers Overview, What is CVSS?, Multiple Vulnerability Data… and Source Priority Strategy, plus 9 more sections
Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
What it does
Cvss Score Extraction is an agent skill from benchflow-ai/skillsbench. Extract CVSS (Common Vulnerability Scoring System) scores from vulnerability data sources with proper fallback handling. This skill covers understanding CVSS v3, handling multiple score sources (NVD, GHSA, RedHat), implementing source priority logic, and dealing with missing scores in security reporting.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: SkillsBench evaluates how well skills work and how effective agents are at using them. The licence is Apache-2.0.
Example prompts
“/cvss-score-extraction”
Requirements
Python 3
Workflow steps
3 steps, taken from the first numbered list in SKILL.md.
1NVD (National Vulnerability Database)
2GHSA (GitHub Security Advisory)
3RedHat Security Data
What it can do on your machine
Read from SKILL.md and the folder at commit 9a1f4dd. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
No scripts in the folder and no shell commands in SKILL.md (its code samples are python and json).
From the folder's file list and the shell code blocks in SKILL.md.
Network
Links to these hosts (documentation or services it may open):
first.org
nvd.nist.gov
github.com
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Cvss Score Extraction loads about 2.3k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 389 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~82
When it runs· the whole SKILL.md, loaded when a task matches
~2.3k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/cvss-score-extraction/SKILL.md (or your agent's skills folder).
name
cvss-score-extraction
description
Extract CVSS (Common Vulnerability Scoring System) scores from vulnerability data sources with proper fallback handling. This skill covers understanding CVSS v3, handling multiple score sources (NVD, GHSA, RedHat), implementing source priority logic, and dealing with missing scores in security reporting.
CVSS Score Extraction from Vulnerability Data
This skill provides guidance on extracting CVSS scores from vulnerability data—a critical component of security report generation.
Overview
CVSS (Common Vulnerability Scoring System) provides a standardized way to assess the severity of security vulnerabilities. When generating security reports, extracting the correct CVSS score from multiple data sources is essential for accurate risk assessment.
What is CVSS?
CVSS Scoring System
CVSS assigns a numerical score (0.0-10.0) representing vulnerability severity:
Score Range
Severity Level
Description
0.0
None
No impact
0.1-3.9
Low
Minimal impact
4.0-6.9
Medium
Moderate impact
7.0-8.9
High
Significant impact
9.0-10.0
Critical
Severe impact
CVSS Versions
CVSS v2: Legacy scoring system (0-10 scale)
CVSS v3: Current standard with refined metrics
CVSS v3.1: Minor refinement of v3
Best Practice: Prefer CVSS v3/v3.1 scores when available.
Multiple Vulnerability Data Sources
Vulnerability scanners often aggregate data from multiple sources, each providing their own CVSS assessment:
Common Sources
NVD (National Vulnerability Database)
Maintained by NIST (U.S. government)
Most authoritative source
Priority: Highest
GHSA (GitHub Security Advisory)
Community-driven vulnerability database
Strong for open-source packages
Priority: Medium
RedHat Security Data
RedHat's security team assessments
Focused on enterprise Linux ecosystem
Priority: Lower
Why Multiple Sources?
Not all sources have scores for every CVE
Scores may differ based on interpretation
Need fallback logic when primary source unavailable
Source Priority Strategy
When multiple sources provide scores, use a priority cascade:
NVD → GHSA → RedHat → N/A
Rationale: NVD is the most comprehensive and authoritative, followed by community sources, then vendor-specific databases.
Show full SKILL.md (145 more words)Show less
Data Structure
Trivy (and similar tools) return CVSS data in nested format:
def get_cvss_score(vuln_data):
"""
Extract CVSS v3 score from vulnerability data.
Uses priority: NVD > GHSA > RedHat
Args:
vuln_data: Dictionary containing vulnerability information
Returns:
CVSS v3 score as float, or 'N/A' if not available
"""
cvss = vuln_data.get('CVSS', {})
# Priority 1: NVD (National Vulnerability Database)
if 'nvd' in cvss:
score = cvss['nvd'].get('V3Score')
if score is not None:
return score
# Priority 2: GHSA (GitHub Security Advisory)
if 'ghsa' in cvss:
score = cvss['ghsa'].get('V3Score')
if score is not None:
return score
# Priority 3: RedHat
if 'redhat' in cvss:
score = cvss['redhat'].get('V3Score')
if score is not None:
return score
# No score available
return 'N/A'
Enhanced Version with V2 Fallback
python
def get_cvss_score_with_fallback(vuln_data):
"""
Extract CVSS score with v2 fallback.
Priority: NVD v3 > GHSA v3 > RedHat v3 > NVD v2 > N/A
"""
cvss = vuln_data.get('CVSS', {})
# Try v3 scores first
for source in ['nvd', 'ghsa', 'redhat']:
if source in cvss:
v3_score = cvss[source].get('V3Score')
if v3_score is not None:
return {'score': v3_score, 'version': 'v3', 'source': source}
# Fallback to v2 if v3 not available
if 'nvd' in cvss:
v2_score = cvss['nvd'].get('V2Score')
if v2_score is not None:
return {'score': v2_score, 'version': 'v2', 'source': 'nvd'}
return {'score': 'N/A', 'version': None, 'source': None}
Usage in Report Generation
Integrating CVSS Extraction
python
import json
def parse_vulnerabilities(json_file):
"""Parse Trivy JSON and extract vulnerabilities with CVSS scores."""
with open(json_file, 'r') as f:
data = json.load(f)
vulnerabilities = []
if 'Results' in data:
for result in data['Results']:
for vuln in result.get('Vulnerabilities', []):
# Extract basic fields
record = {
'Package': vuln.get('PkgName'),
'Version': vuln.get('InstalledVersion'),
'CVE_ID': vuln.get('VulnerabilityID'),
'Severity': vuln.get('Severity'),
'CVSS_Score': get_cvss_score(vuln), # Use extraction function
'Fixed_Version': vuln.get('FixedVersion', 'N/A'),
'Title': vuln.get('Title', 'No description')
}
vulnerabilities.append(record)
return vulnerabilities
Common Patterns
Pattern 1: Numeric Score or 'N/A'
python
cvss_score = get_cvss_score(vuln)
# Returns: 9.8 or 'N/A'
Use case: Simple reports where missing scores are acceptable
Use case: Detailed reports showing data provenance
Pattern 3: Filtering by Score Threshold
python
def is_high_severity(vuln_data, threshold=7.0):
"""Check if vulnerability meets severity threshold."""
score = get_cvss_score(vuln_data)
if score == 'N/A':
# If no score, use severity label
return vuln_data.get('Severity') in ['HIGH', 'CRITICAL']
return score >= threshold
Error Handling
Handling Missing Data
python
def safe_get_cvss_score(vuln_data):
"""Safely extract CVSS score with comprehensive error handling."""
try:
cvss = vuln_data.get('CVSS', {})
# Validate cvss is a dictionary
if not isinstance(cvss, dict):
return 'N/A'
for source in ['nvd', 'ghsa', 'redhat']:
if source in cvss and isinstance(cvss[source], dict):
score = cvss[source].get('V3Score')
# Validate score is numeric
if score is not None and isinstance(score, (int, float)):
return score
return 'N/A'
except (AttributeError, TypeError):
return 'N/A'
Best Practices
Always provide fallback: Use 'N/A' when scores unavailable
Prefer newer versions: V3 > V2
Respect source hierarchy: NVD is most authoritative
Validate data types: Ensure scores are numeric before using
Document source: In detailed reports, note which source provided the score
Complete Example
python
import json
def get_cvss_score(vuln_data):
"""Extract CVSS v3 score with source priority."""
cvss = vuln_data.get('CVSS', {})
for source in ['nvd', 'ghsa', 'redhat']:
if source in cvss:
score = cvss[source].get('V3Score')
if score is not None:
return score
return 'N/A'
def generate_report_with_cvss(json_file):
"""Generate vulnerability report with CVSS scores."""
with open(json_file, 'r') as f:
data = json.load(f)
print(f"{'Package':<20} {'CVE ID':<20} {'CVSS':<8} {'Severity':<10}")
print("-" * 60)
if 'Results' in data:
for result in data['Results']:
for vuln in result.get('Vulnerabilities', []):
pkg = vuln.get('PkgName', 'Unknown')
cve = vuln.get('VulnerabilityID', 'N/A')
cvss = get_cvss_score(vuln)
severity = vuln.get('Severity', 'UNKNOWN')
print(f"{pkg:<20} {cve:<20} {cvss:<8} {severity:<10}")
# Usage
generate_report_with_cvss('trivy_report.json')
Dependencies
Python Modules
json (standard library)
Data Format
Expects Trivy JSON format or similar structured vulnerability data
Cvss Score Extraction next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Cvss Score Extraction compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Cvss Score Extraction this skillbenchflow-ai/skillsbench
The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity.
Audit or refresh OpenClaw maturity scorecard docs from root taxonomy, maturity scores, and QA evidence artifacts without using maintainer discrawl data or committed inventory reports.
Perform OT vulnerability assessments using the Claroty xDome platform for asset discovery, risk scoring, and vulnerability correlation, combining passive traffic-based identification and active safe…
Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes.
This skill should be used when working on Lean 4 formalization projects to maintain persistent memory of successful proof patterns, failed approaches, project conventions, and user preferences…
AC branch pi-model power flow equations (P/Q and |S|) with transformer tap ratio and phase shift, matching acopf-math-model.md and MATPOWER branch fields.
DC power flow analysis for power systems. An agent skill from benchflow-ai/skillsbench.
1.8k GitHub stars~717 tokensUpdated 2 mo ago
Auto-check passed
Questions about Cvss Score Extraction
What does Cvss Score Extraction do?
Extract CVSS (Common Vulnerability Scoring System) scores from vulnerability data sources with proper fallback handling. Cvss Score Extraction is an agent skill from benchflow-ai/skillsbench. Extract CVSS (Common Vulnerability Scoring System) scores from vulnerability data sources with proper fallback handling.
How do I install Cvss Score Extraction in Claude Code?
Run `npx skills add benchflow-ai/skillsbench --skill cvss-score-extraction -a claude-code`. Or copy the skill folder (tasks/software-dependency-audit/environment/skills/cvss-score-extraction in benchflow-ai/skillsbench) into .claude/skills/cvss-score-extraction in your project. Claude Code loads it when a task matches its description.
How do I install Cvss Score Extraction in Codex?
Run `npx skills add benchflow-ai/skillsbench --skill cvss-score-extraction -a codex`. Or copy the skill folder (tasks/software-dependency-audit/environment/skills/cvss-score-extraction in benchflow-ai/skillsbench) into .agents/skills/cvss-score-extraction in your project. Codex loads it when a task matches its description.
Can I use Cvss Score Extraction in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add benchflow-ai/skillsbench --skill cvss-score-extraction -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cvss-score-extraction, .gemini/skills/cvss-score-extraction, .github/skills/cvss-score-extraction and .opencode/skills/cvss-score-extraction in your project.
What does Cvss Score Extraction need to run?
SKILL.md names no scripts, command-line tools or credentials: Cvss Score Extraction is instructions for the agent only. Our summary lists: Python 3.
Does Cvss Score Extraction access the network?
SKILL.md names 3 domains. As links in the text: first.org, nvd.nist.gov and github.com. This is read from the text; nothing was executed.
Is Cvss Score Extraction safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Cvss Score Extraction use?
Cvss Score Extraction is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Cvss Score Extraction use?
About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Cvss Score Extraction?
Skills that share tags, products or a category with Cvss Score Extraction: Prioritizing Vulnerabilities With Cvss Scoring (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Vulnerability Scanning (sickn33/agentic-awesome-skills, 47k stars), Extract (alirezarezvani/claude-skills, 28k stars) and Claw Score (openclaw/openclaw, 392k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Cvss Score Extraction?
benchflow-ai (a GitHub organization) maintains it in benchflow-ai/skillsbench, which has 1,834 GitHub stars. The repository holds 189 skills in this directory. The repository was last updated on July 23, 2026.
Source: benchflow-ai/skillsbench on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.