Install the "vulnerability-csv-reporting" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/vulnerability-csv-reporting into .claude/skills/vulnerability-csv-reporting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-csv-reporting", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add benchflow-ai/skillsbench --skill vulnerability-csv-reporting -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "vulnerability-csv-reporting" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/vulnerability-csv-reporting into .agents/skills/vulnerability-csv-reporting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-csv-reporting", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add benchflow-ai/skillsbench --skill vulnerability-csv-reporting -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "vulnerability-csv-reporting" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/vulnerability-csv-reporting into .cursor/skills/vulnerability-csv-reporting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-csv-reporting", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add benchflow-ai/skillsbench --skill vulnerability-csv-reporting -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "vulnerability-csv-reporting" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/vulnerability-csv-reporting into .gemini/skills/vulnerability-csv-reporting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-csv-reporting", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add benchflow-ai/skillsbench --skill vulnerability-csv-reporting -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "vulnerability-csv-reporting" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/vulnerability-csv-reporting into .github/skills/vulnerability-csv-reporting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-csv-reporting", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add benchflow-ai/skillsbench --skill vulnerability-csv-reporting -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "vulnerability-csv-reporting" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/vulnerability-csv-reporting into .opencode/skills/vulnerability-csv-reporting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-csv-reporting", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
vulnerability-csv-reporting
GitHub stars
1.8k
Token cost
~3k tokens
SKILL.md length
464 words
Files
1
Skills in repo
178
Repo updated
First seen
Licence
Apache-2.0
At a glance
Generate structured CSV security audit reports from vulnerability data with proper filtering and formatting.
Works in 4 steps: Use descriptive column names: Package… → Handle missing data: Use N/A for… → Consistent data types: Ensure all rows… → …
Tasks that involve CSV and tabular files
SKILL.md covers Overview, When to Use CSV Reports, CSV Schema Design for Security… and Python CSV Generation with…, plus 8 more sections
Reaches nvd.nist.gov and avd.aquasec.com
What it does
Vulnerability CSV Reporting is an agent skill from benchflow-ai/skillsbench. Generate structured CSV security audit reports from vulnerability data with proper filtering and formatting. This skill covers CSV schema design for security reports, using Python csv.DictWriter, severity-based filtering, and field mapping from JSON to tabular format.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Documents & Office, covering CSV and tabular files, Database schema design and Security review. It works with Python. The repository describes itself as: SkillsBench evaluates how well skills work and how effective agents are at using them. The licence is Apache-2.0.
When your agent uses it
Tasks that involve CSV and tabular files
Tasks that involve Database schema design
Tasks that involve Security review
Example prompts
“/vulnerability-csv-reporting”
Requirements
Python 3
Workflow steps
4 steps, taken from the first numbered list in SKILL.md.
1Use descriptive column names: Package not pkg, CVE_ID not id
2Handle missing data: Use N/A for unavailable fields, not empty strings
3Consistent data types: Ensure all rows have same format
4Include metadata: Consider adding scan date, target, tool version
What it can do on your machine
Read from SKILL.md and the folder at commit 9a1f4dd. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
nvd.nist.gov
avd.aquasec.com
Also links to:
docs.python.org
tools.ietf.org
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Vulnerability CSV Reporting loads about 3k tokens when it runs. Until then it costs about 74 tokens; SKILL.md has 464 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~74
When it runs· the whole SKILL.md, loaded when a task matches
~3k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/vulnerability-csv-reporting/SKILL.md (or your agent's skills folder).
name
vulnerability-csv-reporting
description
Generate structured CSV security audit reports from vulnerability data with proper filtering and formatting. This skill covers CSV schema design for security reports, using Python csv.DictWriter, severity-based filtering, and field mapping from JSON to tabular format.
Vulnerability CSV Report Generation
This skill provides guidance on generating structured CSV reports from vulnerability scan data—a common format for security audits and compliance reporting.
Overview
CSV (Comma-Separated Values) is a widely-used format for security reports because it's:
Human-readable: Can be opened in Excel, Google Sheets
Machine-parseable: Easy to process programmatically
Universal: Supported by all data analysis tools
Lightweight: Smaller than JSON/XML formats
When to Use CSV Reports
Ideal Use Cases
Compliance audits requiring tabular data
Executive summaries for non-technical stakeholders
Integration with ticketing systems (Jira, ServiceNow)
Automated vulnerability tracking pipelines
Data analysis in spreadsheet tools
Limitations
No hierarchical data (flat structure only)
Limited support for nested information
No standard for binary data
Alternative formats: JSON (for APIs), PDF (for formal reports), HTML (for dashboards)
CSV Schema Design for Security Reports
Essential Fields
A well-designed vulnerability report CSV should include:
Field
Type
Description
Example
Package
String
Vulnerable package name
express
Version
String
Installed version
4.17.1
CVE_ID
String
Vulnerability identifier
CVE-2022-24999
Severity
Enum
Risk level
CRITICAL, HIGH
CVSS_Score
Float/String
Numeric severity score
9.8 or N/A
Fixed_Version
String
Patched version
4.18.0 or N/A
Title
String
Brief description
XSS in Express.js
Url
String
Reference link
https://nvd.nist.gov/...
Design Principles
Use descriptive column names: Package not pkg, CVE_ID not id
Handle missing data: Use N/A for unavailable fields, not empty strings
Consistent data types: Ensure all rows have same format
Include metadata: Consider adding scan date, target, tool version
Python CSV Generation with DictWriter
Why DictWriter?
Python's csv.DictWriter is ideal for structured reports:
Type-safe: Column names defined upfront
Readable: Use dictionary keys instead of indices
Maintainable: Easy to add/remove columns
Automatic header generation: No manual header writing
encoding='utf-8': Handles special characters in descriptions
Severity-Based Filtering
Why Filter by Severity?
Security teams prioritize based on risk. Filtering ensures reports focus on critical issues:
Severity
Action Required
Typical SLA
CRITICAL
Immediate patch
24 hours
HIGH
Urgent patch
7 days
MEDIUM
Scheduled patch
30 days
LOW
Optional patch
90 days
Implementation
python
def filter_high_severity(vulnerabilities, min_severity=['HIGH', 'CRITICAL']):
"""
Filter vulnerabilities by severity level.
Args:
vulnerabilities: List of vulnerability dictionaries
min_severity: List of severity levels to include
Returns:
Filtered list containing only specified severity levels
"""
filtered = []
for vuln in vulnerabilities:
if vuln.get('Severity') in min_severity:
filtered.append(vuln)
return filtered
# Usage
all_vulns = [...] # From scanner
critical_vulns = filter_high_severity(all_vulns, ['CRITICAL', 'HIGH'])
Field Mapping from JSON to CSV
Extracting Fields from Scanner Output
python
import json
def parse_trivy_json_to_csv_records(json_file):
"""
Parse Trivy JSON output and extract CSV-ready records.
Returns list of dictionaries, one per vulnerability.
"""
with open(json_file, 'r', encoding='utf-8') as f:
data = json.load(f)
records = []
if 'Results' in data:
for result in data['Results']:
target = result.get('Target', 'Unknown')
for vuln in result.get('Vulnerabilities', []):
# Map JSON fields to CSV fields
record = {
"Package": vuln.get('PkgName'),
"Version": vuln.get('InstalledVersion'),
"CVE_ID": vuln.get('VulnerabilityID'),
"Severity": vuln.get('Severity', 'UNKNOWN'),
"CVSS_Score": extract_cvss_score(vuln),
"Fixed_Version": vuln.get('FixedVersion', 'N/A'),
"Title": vuln.get('Title', 'No description'),
"Url": vuln.get('PrimaryURL', '')
}
records.append(record)
return records
def extract_cvss_score(vuln):
"""Extract CVSS score (from cvss-score-extraction skill)."""
cvss = vuln.get('CVSS', {})
for source in ['nvd', 'ghsa', 'redhat']:
if source in cvss:
score = cvss[source].get('V3Score')
if score is not None:
return score
return 'N/A'
Complete Vulnerability CSV Report Generator
python
import json
import csv
import sys
def generate_vulnerability_csv_report(
json_input,
csv_output,
severity_filter=['HIGH', 'CRITICAL']
):
"""
Generate filtered CSV security report from Trivy JSON output.
Args:
json_input: Path to Trivy JSON report
csv_output: Path for output CSV file
severity_filter: List of severity levels to include
"""
# Read JSON
try:
with open(json_input, 'r', encoding='utf-8') as f:
data = json.load(f)
except FileNotFoundError:
print(f"[!] Error: Could not find {json_input}")
sys.exit(1)
# Extract and filter vulnerabilities
vulnerabilities = []
if 'Results' in data:
for result in data['Results']:
for vuln in result.get('Vulnerabilities', []):
severity = vuln.get('Severity', 'UNKNOWN')
# Apply severity filter
if severity in severity_filter:
vulnerabilities.append({
"Package": vuln.get('PkgName'),
"Version": vuln.get('InstalledVersion'),
"CVE_ID": vuln.get('VulnerabilityID'),
"Severity": severity,
"CVSS_Score": get_cvss_score(vuln),
"Fixed_Version": vuln.get('FixedVersion', 'N/A'),
"Title": vuln.get('Title', 'No description'),
"Url": vuln.get('PrimaryURL', '')
})
# Write CSV
if vulnerabilities:
headers = ["Package", "Version", "CVE_ID", "Severity",
"CVSS_Score", "Fixed_Version", "Title", "Url"]
with open(csv_output, 'w', newline='', encoding='utf-8') as f:
writer = csv.DictWriter(f, fieldnames=headers)
writer.writeheader()
writer.writerows(vulnerabilities)
print(f"\n[SUCCESS] Found {len(vulnerabilities)} "
f"{'/'.join(severity_filter)} vulnerabilities")
print(f"[SUCCESS] Report saved to: {csv_output}")
else:
print(f"\n[SUCCESS] No {'/'.join(severity_filter)} vulnerabilities found")
def get_cvss_score(vuln_data):
"""Extract CVSS score with source priority."""
cvss = vuln_data.get('CVSS', {})
for source in ['nvd', 'ghsa', 'redhat']:
if source in cvss:
score = cvss[source].get('V3Score')
if score is not None:
return score
return 'N/A'
# Usage
if __name__ == "__main__":
generate_vulnerability_csv_report(
json_input='trivy_report.json',
csv_output='security_audit.csv',
severity_filter=['CRITICAL', 'HIGH']
)
Advanced Patterns
Pattern 1: Adding Metadata Row
python
import csv
from datetime import datetime
# Add metadata as first row
metadata = {
"Package": f"Scan Date: {datetime.now().isoformat()}",
"Version": "Tool: Trivy v0.40.0",
"CVE_ID": "Target: package-lock.json",
"Severity": "", "CVSS_Score": "", "Fixed_Version": "",
"Title": "", "Url": ""
}
with open('report.csv', 'w', newline='') as f:
writer = csv.DictWriter(f, fieldnames=headers)
writer.writeheader()
writer.writerow(metadata) # Metadata row
writer.writerow({}) # Blank separator
writer.writerows(vulnerabilities) # Actual data
Pattern 2: Multi-Target Reports
python
def generate_multi_target_report(json_input, csv_output):
"""Include target/file name in each row."""
with open(json_input, 'r') as f:
data = json.load(f)
vulnerabilities = []
for result in data.get('Results', []):
target = result.get('Target', 'Unknown')
for vuln in result.get('Vulnerabilities', []):
record = {
"Target": target, # Add target column
"Package": vuln.get('PkgName'),
# ... other fields
}
vulnerabilities.append(record)
headers = ["Target", "Package", "Version", ...] # Target first
# Write CSV as before
Pattern 3: Summary Statistics
python
def print_report_summary(vulnerabilities):
"""Print summary before writing CSV."""
from collections import Counter
severity_counts = Counter(v['Severity'] for v in vulnerabilities)
print("\nVulnerability Summary:")
print(f" CRITICAL: {severity_counts.get('CRITICAL', 0)}")
print(f" HIGH: {severity_counts.get('HIGH', 0)}")
print(f" Total: {len(vulnerabilities)}")
Error Handling
Handling Missing or Malformed Data
python
def safe_get_field(vuln, field, default='N/A'):
"""Safely extract field with default fallback."""
value = vuln.get(field, default)
# Ensure value is not None
return value if value is not None else default
# Usage in field mapping
record = {
"Package": safe_get_field(vuln, 'PkgName', 'Unknown'),
"Fixed_Version": safe_get_field(vuln, 'FixedVersion', 'N/A'),
# ...
}
Best Practices
Always write headers: Makes CSV self-documenting
Use UTF-8 encoding: Handles international characters
Set newline='': Prevents blank lines on Windows
Validate data: Check for None/null values before writing
Add timestamp: Include scan date for tracking
Document schema: Maintain a data dictionary
Test with edge cases: Empty results, missing fields
Dependencies
Python Modules
csv (standard library)
json (standard library)
Input Format
Requires structured vulnerability data (typically JSON from scanners)
Vulnerability CSV Reporting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Vulnerability CSV Reporting compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Vulnerability CSV Reporting this skillbenchflow-ai/skillsbench
Run a full 6-phase autonomous replication of a biomedical/epidemiology paper against UK Biobank or similar cohort data, producing Python and R scripts plus a validated replication report.
This skill should be used when working on Lean 4 formalization projects to maintain persistent memory of successful proof patterns, failed approaches, project conventions, and user preferences…
AC branch pi-model power flow equations (P/Q and |S|) with transformer tap ratio and phase shift, matching acopf-math-model.md and MATPOWER branch fields.
Generate structured CSV security audit reports from vulnerability data with proper filtering and formatting. Vulnerability CSV Reporting is an agent skill from benchflow-ai/skillsbench. Generate structured CSV security audit reports from vulnerability data with proper filtering and formatting.
When should I use Vulnerability CSV Reporting?
Vulnerability CSV Reporting fits situations like: tasks that involve CSV and tabular files; tasks that involve Database schema design; tasks that involve Security review.
How do I install Vulnerability CSV Reporting in Claude Code?
Run `npx skills add benchflow-ai/skillsbench --skill vulnerability-csv-reporting -a claude-code`. Or copy the skill folder (tasks/software-dependency-audit/environment/skills/vulnerability-csv-reporting in benchflow-ai/skillsbench) into .claude/skills/vulnerability-csv-reporting in your project. Claude Code loads it when a task matches its description.
How do I install Vulnerability CSV Reporting in Codex?
Run `npx skills add benchflow-ai/skillsbench --skill vulnerability-csv-reporting -a codex`. Or copy the skill folder (tasks/software-dependency-audit/environment/skills/vulnerability-csv-reporting in benchflow-ai/skillsbench) into .agents/skills/vulnerability-csv-reporting in your project. Codex loads it when a task matches its description.
Can I use Vulnerability CSV Reporting in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add benchflow-ai/skillsbench --skill vulnerability-csv-reporting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vulnerability-csv-reporting, .gemini/skills/vulnerability-csv-reporting, .github/skills/vulnerability-csv-reporting and .opencode/skills/vulnerability-csv-reporting in your project.
What does Vulnerability CSV Reporting need to run?
SKILL.md names no scripts, command-line tools or credentials: Vulnerability CSV Reporting is instructions for the agent only. Our summary lists: Python 3.
Does Vulnerability CSV Reporting access the network?
SKILL.md names 4 domains. In commands or code: nvd.nist.gov and avd.aquasec.com; the agent is likely to contact these when it follows the instructions. As links in the text: docs.python.org and tools.ietf.org. This is read from the text; nothing was executed.
Is Vulnerability CSV Reporting safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Vulnerability CSV Reporting use?
Vulnerability CSV Reporting is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Vulnerability CSV Reporting use?
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Vulnerability CSV Reporting?
Skills that share tags, products or a category with Vulnerability CSV Reporting: Replicate Paper (brycewang-stanford/Auto-Empirical-Research-Skills, 4.5k stars), Instrument Data To Allotrope (aws-samples/amazon-bedrock-agents-healthcare-lifesciences, 274 stars), Sap Rpt1 (secondsky/sap-skills, 462 stars) and Histolab (K-Dense-AI/scientific-agent-skills, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Vulnerability CSV Reporting?
benchflow-ai (a GitHub organization) maintains it in benchflow-ai/skillsbench, which has 1,832 GitHub stars. The repository holds 178 skills in this directory. The repository was last updated on July 23, 2026.
Source: benchflow-ai/skillsbench on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.