Agent skill

Cvss Score Extraction

by benchflow-ai in benchflow-ai/skillsbench

Extract CVSS (Common Vulnerability Scoring System) scores from vulnerability data sources with proper fallback handling.

Apache-2.0Auto-check passed

Install Cvss Score Extraction

skills CLI
$ npx skills add benchflow-ai/skillsbench --skill cvss-score-extraction -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install benchflow-ai/skillsbench cvss-score-extraction --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/benchflow-ai/skillsbench.git skills-src && mkdir -p .claude/skills && cp -r skills-src/tasks/software-dependency-audit/environment/skills/cvss-score-extraction .claude/skills/cvss-score-extraction && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cvss-score-extraction
GitHub stars
1.8k
Token cost
~2.3k tokens
SKILL.md length
389 words
Files
1
Skills in repo
189
Repo updated
First seen
Licence
Apache-2.0

At a glance

Extract CVSS (Common Vulnerability Scoring System) scores from vulnerability data sources with proper fallback handling.

  • Works in 3 steps: NVD (National Vulnerability Database) → GHSA (GitHub Security Advisory) → RedHat Security Data
  • SKILL.md covers Overview, What is CVSS?, Multiple Vulnerability Data… and Source Priority Strategy, plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cvss Score Extraction is an agent skill from benchflow-ai/skillsbench. Extract CVSS (Common Vulnerability Scoring System) scores from vulnerability data sources with proper fallback handling. This skill covers understanding CVSS v3, handling multiple score sources (NVD, GHSA, RedHat), implementing source priority logic, and dealing with missing scores in security reporting.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: SkillsBench evaluates how well skills work and how effective agents are at using them. The licence is Apache-2.0.

Example prompts

  • “/cvss-score-extraction”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. NVD (National Vulnerability Database)
  2. GHSA (GitHub Security Advisory)
  3. RedHat Security Data

What it can do on your machine

Read from SKILL.md and the folder at commit 9a1f4dd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python and json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • first.org
    • nvd.nist.gov
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cvss Score Extraction loads about 2.3k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 389 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from benchflow-ai/skillsbench at commit 9a1f4dd, republished under its Apache-2.0 licence (© benchflow-ai). 389 words, ~2,289 tokens.

Download SKILL.mdSave it as .claude/skills/cvss-score-extraction/SKILL.md (or your agent's skills folder).
name
cvss-score-extraction
description
Extract CVSS (Common Vulnerability Scoring System) scores from vulnerability data sources with proper fallback handling. This skill covers understanding CVSS v3, handling multiple score sources (NVD, GHSA, RedHat), implementing source priority logic, and dealing with missing scores in security reporting.

CVSS Score Extraction from Vulnerability Data

This skill provides guidance on extracting CVSS scores from vulnerability data—a critical component of security report generation.

Overview

CVSS (Common Vulnerability Scoring System) provides a standardized way to assess the severity of security vulnerabilities. When generating security reports, extracting the correct CVSS score from multiple data sources is essential for accurate risk assessment.

What is CVSS?

CVSS Scoring System

CVSS assigns a numerical score (0.0-10.0) representing vulnerability severity:

Score RangeSeverity LevelDescription
0.0NoneNo impact
0.1-3.9LowMinimal impact
4.0-6.9MediumModerate impact
7.0-8.9HighSignificant impact
9.0-10.0CriticalSevere impact
CVSS Versions
  • CVSS v2: Legacy scoring system (0-10 scale)
  • CVSS v3: Current standard with refined metrics
  • CVSS v3.1: Minor refinement of v3

Best Practice: Prefer CVSS v3/v3.1 scores when available.

Multiple Vulnerability Data Sources

Vulnerability scanners often aggregate data from multiple sources, each providing their own CVSS assessment:

Common Sources
  1. NVD (National Vulnerability Database)

    • Maintained by NIST (U.S. government)
    • Most authoritative source
    • Priority: Highest
  2. GHSA (GitHub Security Advisory)

    • Community-driven vulnerability database
    • Strong for open-source packages
    • Priority: Medium
  3. RedHat Security Data

    • RedHat's security team assessments
    • Focused on enterprise Linux ecosystem
    • Priority: Lower
Why Multiple Sources?
  • Not all sources have scores for every CVE
  • Scores may differ based on interpretation
  • Need fallback logic when primary source unavailable

Source Priority Strategy

When multiple sources provide scores, use a priority cascade:

NVD → GHSA → RedHat → N/A

Rationale: NVD is the most comprehensive and authoritative, followed by community sources, then vendor-specific databases.

Show full SKILL.md (145 more words)Show less

Data Structure

Trivy (and similar tools) return CVSS data in nested format:

json
{
  "VulnerabilityID": "CVE-2021-44906",
  "PkgName": "minimist",
  "Severity": "CRITICAL",
  "CVSS": {
    "nvd": {
      "V2Vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
      "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "V2Score": 7.5,
      "V3Score": 9.8
    },
    "ghsa": {
      "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "V3Score": 9.8
    }
  }
}

Python Implementation

Basic Score Extraction
python
def get_cvss_score(vuln_data):
    """
    Extract CVSS v3 score from vulnerability data.
    Uses priority: NVD > GHSA > RedHat
    
    Args:
        vuln_data: Dictionary containing vulnerability information
        
    Returns:
        CVSS v3 score as float, or 'N/A' if not available
    """
    cvss = vuln_data.get('CVSS', {})
    
    # Priority 1: NVD (National Vulnerability Database)
    if 'nvd' in cvss:
        score = cvss['nvd'].get('V3Score')
        if score is not None:
            return score
    
    # Priority 2: GHSA (GitHub Security Advisory)
    if 'ghsa' in cvss:
        score = cvss['ghsa'].get('V3Score')
        if score is not None:
            return score
    
    # Priority 3: RedHat
    if 'redhat' in cvss:
        score = cvss['redhat'].get('V3Score')
        if score is not None:
            return score
    
    # No score available
    return 'N/A'
Enhanced Version with V2 Fallback
python
def get_cvss_score_with_fallback(vuln_data):
    """
    Extract CVSS score with v2 fallback.
    Priority: NVD v3 > GHSA v3 > RedHat v3 > NVD v2 > N/A
    """
    cvss = vuln_data.get('CVSS', {})
    
    # Try v3 scores first
    for source in ['nvd', 'ghsa', 'redhat']:
        if source in cvss:
            v3_score = cvss[source].get('V3Score')
            if v3_score is not None:
                return {'score': v3_score, 'version': 'v3', 'source': source}
    
    # Fallback to v2 if v3 not available
    if 'nvd' in cvss:
        v2_score = cvss['nvd'].get('V2Score')
        if v2_score is not None:
            return {'score': v2_score, 'version': 'v2', 'source': 'nvd'}
    
    return {'score': 'N/A', 'version': None, 'source': None}

Usage in Report Generation

Integrating CVSS Extraction
python
import json

def parse_vulnerabilities(json_file):
    """Parse Trivy JSON and extract vulnerabilities with CVSS scores."""
    with open(json_file, 'r') as f:
        data = json.load(f)
    
    vulnerabilities = []
    
    if 'Results' in data:
        for result in data['Results']:
            for vuln in result.get('Vulnerabilities', []):
                # Extract basic fields
                record = {
                    'Package': vuln.get('PkgName'),
                    'Version': vuln.get('InstalledVersion'),
                    'CVE_ID': vuln.get('VulnerabilityID'),
                    'Severity': vuln.get('Severity'),
                    'CVSS_Score': get_cvss_score(vuln),  # Use extraction function
                    'Fixed_Version': vuln.get('FixedVersion', 'N/A'),
                    'Title': vuln.get('Title', 'No description')
                }
                vulnerabilities.append(record)
    
    return vulnerabilities

Common Patterns

Pattern 1: Numeric Score or 'N/A'
python
cvss_score = get_cvss_score(vuln)
# Returns: 9.8 or 'N/A'

Use case: Simple reports where missing scores are acceptable

Pattern 2: Score with Metadata
python
cvss_info = get_cvss_score_with_fallback(vuln)
# Returns: {'score': 9.8, 'version': 'v3', 'source': 'nvd'}

Use case: Detailed reports showing data provenance

Pattern 3: Filtering by Score Threshold
python
def is_high_severity(vuln_data, threshold=7.0):
    """Check if vulnerability meets severity threshold."""
    score = get_cvss_score(vuln_data)
    if score == 'N/A':
        # If no score, use severity label
        return vuln_data.get('Severity') in ['HIGH', 'CRITICAL']
    return score >= threshold

Error Handling

Handling Missing Data
python
def safe_get_cvss_score(vuln_data):
    """Safely extract CVSS score with comprehensive error handling."""
    try:
        cvss = vuln_data.get('CVSS', {})
        
        # Validate cvss is a dictionary
        if not isinstance(cvss, dict):
            return 'N/A'
        
        for source in ['nvd', 'ghsa', 'redhat']:
            if source in cvss and isinstance(cvss[source], dict):
                score = cvss[source].get('V3Score')
                # Validate score is numeric
                if score is not None and isinstance(score, (int, float)):
                    return score
        
        return 'N/A'
    except (AttributeError, TypeError):
        return 'N/A'

Best Practices

  1. Always provide fallback: Use 'N/A' when scores unavailable
  2. Prefer newer versions: V3 > V2
  3. Respect source hierarchy: NVD is most authoritative
  4. Validate data types: Ensure scores are numeric before using
  5. Document source: In detailed reports, note which source provided the score

Complete Example

python
import json

def get_cvss_score(vuln_data):
    """Extract CVSS v3 score with source priority."""
    cvss = vuln_data.get('CVSS', {})
    
    for source in ['nvd', 'ghsa', 'redhat']:
        if source in cvss:
            score = cvss[source].get('V3Score')
            if score is not None:
                return score
    
    return 'N/A'

def generate_report_with_cvss(json_file):
    """Generate vulnerability report with CVSS scores."""
    with open(json_file, 'r') as f:
        data = json.load(f)
    
    print(f"{'Package':<20} {'CVE ID':<20} {'CVSS':<8} {'Severity':<10}")
    print("-" * 60)
    
    if 'Results' in data:
        for result in data['Results']:
            for vuln in result.get('Vulnerabilities', []):
                pkg = vuln.get('PkgName', 'Unknown')
                cve = vuln.get('VulnerabilityID', 'N/A')
                cvss = get_cvss_score(vuln)
                severity = vuln.get('Severity', 'UNKNOWN')
                
                print(f"{pkg:<20} {cve:<20} {cvss:<8} {severity:<10}")

# Usage
generate_report_with_cvss('trivy_report.json')

Dependencies

Python Modules
  • json (standard library)
Data Format
  • Expects Trivy JSON format or similar structured vulnerability data

References

© benchflow-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in tasks/software-dependency-audit/environment/skills/cvss-score-extraction of benchflow-ai/skillsbench.

Open the folder on GitHubat commit 9a1f4dd

Compare with similar skills

Cvss Score Extraction next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cvss Score Extraction compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cvss Score Extraction this skillbenchflow-ai/skillsbench1.8k—~2.3kAutomated safety check: PassApache-2.0
Prioritizing Vulnerabilities With Cvss Scoringmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0
Vulnerability Scanningsickn33/agentic-awesome-skills47k1 repos~2.8kAutomated safety check: PassMIT
Extractalirezarezvani/claude-skills28k—~1.4kAutomated safety check: PassMIT
Claw Scoreopenclaw/openclaw392k—~2.5kAutomated safety check: PassMIT
Performing Ot Vulnerability Assessment With Clarotymukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • Prioritizing Vulnerabilities With Cvss Scoring

    mukul975/Anthropic-Cybersecurity-Skills

    The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum of Incident Response and Security Teams) for assessing vulnerability severity.

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Vulnerability Scanning

    sickn33/agentic-awesome-skills

    Scan systems and dependencies for CVEs and security vulnerabilities.

    47k GitHub starsUsed in 1 repo~2.8k tokens
    SecurityAuto-check passed
  • Extract

    alirezarezvani/claude-skills

    Turn a proven pattern or debugging solution into a standalone reusable skill with SKILL.md, reference docs, and examples.

    28k GitHub stars~1.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Claw Score

    openclaw/openclaw

    Audit or refresh OpenClaw maturity scorecard docs from root taxonomy, maturity scores, and QA evidence artifacts without using maintainer discrawl data or committed inventory reports.

    392k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Performing Ot Vulnerability Assessment With Claroty

    mukul975/Anthropic-Cybersecurity-Skills

    Perform OT vulnerability assessments using the Claroty xDome platform for asset discovery, risk scoring, and vulnerability correlation, combining passive traffic-based identification and active safe…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Endpoint Vulnerability Remediation

    mukul975/Anthropic-Cybersecurity-Skills

    Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes.

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from benchflow-ai/skillsbench

All 189 skills in this repo
  • Lean4 Memories

    benchflow-ai/skillsbench

    This skill should be used when working on Lean 4 formalization projects to maintain persistent memory of successful proof patterns, failed approaches, project conventions, and user preferences…

    1.8k GitHub stars~3.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Senior Data Engineer

    benchflow-ai/skillsbench

    World-class data engineering skill for building scalable data pipelines, ETL/ELT systems, real-time streaming, and data infrastructure.

    1.8k GitHub stars~5.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Ac Branch Pi Model

    benchflow-ai/skillsbench

    AC branch pi-model power flow equations (P/Q and |S|) with transformer tap ratio and phase shift, matching acopf-math-model.md and MATPOWER branch fields.

    1.8k GitHub stars~1.1k tokensUpdated 2 mo ago
    Auto-check passed
  • Civ6lib

    benchflow-ai/skillsbench

    Civilization 6 district mechanics library. An agent skill from benchflow-ai/skillsbench.

    1.8k GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed
  • D3 Visualization

    benchflow-ai/skillsbench

    Build deterministic, verifiable data visualizations with D3.js (v6).

    1.8k GitHub stars~1.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Dc Power Flow

    benchflow-ai/skillsbench

    DC power flow analysis for power systems. An agent skill from benchflow-ai/skillsbench.

    1.8k GitHub stars~717 tokensUpdated 2 mo ago
    Auto-check passed

Questions about Cvss Score Extraction

What does Cvss Score Extraction do?

Extract CVSS (Common Vulnerability Scoring System) scores from vulnerability data sources with proper fallback handling. Cvss Score Extraction is an agent skill from benchflow-ai/skillsbench. Extract CVSS (Common Vulnerability Scoring System) scores from vulnerability data sources with proper fallback handling.

How do I install Cvss Score Extraction in Claude Code?

Run `npx skills add benchflow-ai/skillsbench --skill cvss-score-extraction -a claude-code`. Or copy the skill folder (tasks/software-dependency-audit/environment/skills/cvss-score-extraction in benchflow-ai/skillsbench) into .claude/skills/cvss-score-extraction in your project. Claude Code loads it when a task matches its description.

How do I install Cvss Score Extraction in Codex?

Run `npx skills add benchflow-ai/skillsbench --skill cvss-score-extraction -a codex`. Or copy the skill folder (tasks/software-dependency-audit/environment/skills/cvss-score-extraction in benchflow-ai/skillsbench) into .agents/skills/cvss-score-extraction in your project. Codex loads it when a task matches its description.

Can I use Cvss Score Extraction in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add benchflow-ai/skillsbench --skill cvss-score-extraction -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cvss-score-extraction, .gemini/skills/cvss-score-extraction, .github/skills/cvss-score-extraction and .opencode/skills/cvss-score-extraction in your project.

What does Cvss Score Extraction need to run?

SKILL.md names no scripts, command-line tools or credentials: Cvss Score Extraction is instructions for the agent only. Our summary lists: Python 3.

Does Cvss Score Extraction access the network?

SKILL.md names 3 domains. As links in the text: first.org, nvd.nist.gov and github.com. This is read from the text; nothing was executed.

Is Cvss Score Extraction safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cvss Score Extraction use?

Cvss Score Extraction is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cvss Score Extraction use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cvss Score Extraction?

Skills that share tags, products or a category with Cvss Score Extraction: Prioritizing Vulnerabilities With Cvss Scoring (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Vulnerability Scanning (sickn33/agentic-awesome-skills, 47k stars), Extract (alirezarezvani/claude-skills, 28k stars) and Claw Score (openclaw/openclaw, 392k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cvss Score Extraction?

benchflow-ai (a GitHub organization) maintains it in benchflow-ai/skillsbench, which has 1,834 GitHub stars. The repository holds 189 skills in this directory. The repository was last updated on July 23, 2026.

Source: benchflow-ai/skillsbench on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.