Agent skill

Dashboard

by davepoon in davepoon/buildwithclaude

View all tracked vulnerabilities and their current status. An agent skill from davepoon/buildwithclaude.

MITAuto-check passed

Install Dashboard

skills CLI
$ npx skills add davepoon/buildwithclaude --skill dashboard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install davepoon/buildwithclaude dashboard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/vulnetix/skills/dashboard .claude/skills/dashboard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dashboard
GitHub stars
3.6k
Token cost
~930 tokens
SKILL.md length
308 words
Files
1
Skills in repo
245
Repo updated
First seen
Licence
MIT

At a glance

View all tracked vulnerabilities and their current status. An agent skill from davepoon/buildwithclaude.

  • Works in 7 steps: Load Memory → Parse and Categorize → Display Summary Header → …
  • Calls npm and go

What it does

Dashboard is an agent skill from davepoon/buildwithclaude. View all tracked vulnerabilities and their current status

Its SKILL.md is about 930 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw. The licence is MIT.

Example prompts

  • “/dashboard”

Requirements

  • Pre-approved tools (allowed-tools): Read, Glob, Grep

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Load Memory
  2. Parse and Categorize
  3. Display Summary Header
  4. Open Vulnerabilities Table
  5. Resolved Vulnerabilities Table
  6. Manifest Tracking
  7. Suggested Actions

What it can do on your machine

Read from SKILL.md and the folder at commit 10bfc43. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dashboard loads about 930 tokens when it runs. Until then it costs about 17 tokens; SKILL.md has 308 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~17
When it runs · the whole SKILL.md, loaded when a task matches
~930

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from davepoon/buildwithclaude at commit 10bfc43, republished under its MIT licence (© davepoon). 308 words, ~930 tokens.

Download SKILL.mdSave it as .claude/skills/dashboard/SKILL.md (or your agent's skills folder).
name
dashboard
description
View all tracked vulnerabilities and their current status
allowed-tools
Read, Glob, Grep
user-invocable
true
model
haiku

Vulnetix Vulnerability Dashboard

This skill reads .vulnetix/memory.yaml and displays a comprehensive vulnerability status report. It is read-only and does not modify any files.

Workflow

Step 1: Load Memory
  1. Use Glob to check if .vulnetix/memory.yaml exists in the repo root
  2. If it does not exist, display: "No vulnerability data found. Run /vulnetix:vuln <package> or /vulnetix:exploits-search to start tracking." and stop.
  3. Use Read to load the full contents of .vulnetix/memory.yaml
Step 2: Parse and Categorize

From the vulnerabilities: section, categorize each entry:

Open (unresolved):

  • status: affected -- "Vulnerable"
  • status: under_investigation -- "Investigating"

Resolved:

  • status: fixed -- "Fixed"
  • status: not_affected -- "Not affected"
  • Entries with decision.choice: risk-accepted -- "Risk accepted"
  • Entries with decision.choice: deferred -- "Deferred"

From the manifests: section, collect manifest tracking info.

Step 3: Display Summary Header
Vulnetix Security Dashboard
============================
Open: <N> (<X> vulnerable, <Y> investigating)
Resolved: <N> (<X> fixed, <Y> not affected, <Z> risk-accepted, <W> deferred)
Manifests tracked: <N> (last scan: <timestamp>)

If there are zero vulnerabilities and zero manifests, display: "Clean slate -- no vulnerabilities tracked yet."

Step 4: Open Vulnerabilities Table

If there are open vulnerabilities, display them sorted by CWSS priority (P1 first), then by severity:

Open Vulnerabilities
--------------------
| ID | Package | Severity | Status | Priority | Decision |
|----|---------|----------|--------|----------|----------|
| CVE-2021-44228 | log4j-core | critical | Vulnerable | P1 (87.5) | investigating |
| GHSA-xxxx-yyyy | express | high | Investigating | P2 (62.0) | investigating |

For each column:

  • ID: Primary vulnerability key
  • Package: package field
  • Severity: severity field
  • Status: Developer-friendly status (see VEX mapping above)
  • Priority: cwss.priority and cwss.score if available, otherwise "--"
  • Decision: decision.choice if available, otherwise "--"
Step 5: Resolved Vulnerabilities Table

If there are resolved vulnerabilities, display them:

Resolved Vulnerabilities
------------------------
| ID | Package | Severity | Resolution | Decision | Date |
|----|---------|----------|------------|----------|------|
| CVE-2023-1234 | lodash | high | Fixed | fix-applied | 2024-01-15 |

For the Date column, use the most recent history entry timestamp, or discovery.date as fallback.

Step 6: Manifest Tracking

If manifests are tracked, display:

Tracked Manifests
-----------------
| Manifest | Ecosystem | Last Scanned | Vulns Found |
|----------|-----------|--------------|-------------|
| package.json | npm | 2024-01-15T10:30:00Z | 3 |
| go.mod | go | 2024-01-15T10:31:00Z | 0 |
Step 7: Suggested Actions

For each open vulnerability (up to 5), suggest a next action based on its state:

  • Has no threat_model or cwss: "/vulnetix:exploits <id>" -- get exploit analysis and priority scoring
  • Has cwss but no fix applied: "/vulnetix:fix <id>" -- get fix intelligence
  • General: "/vulnetix:remediation <id>" -- get a full remediation plan

If there are more than 5 open vulns, add: "Use /vulnetix:exploits-search to find exploited vulnerabilities across your ecosystem."

Always end with: "Use /vulnetix:vuln <id> for detailed info on any vulnerability."

© davepoon, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/vulnetix/skills/dashboard of davepoon/buildwithclaude.

Open the folder on GitHubat commit 10bfc43

Compare with similar skills

Dashboard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dashboard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dashboard this skilldavepoon/buildwithclaude3.6k—~930Automated safety check: PassMIT
Building Vulnerability Dashboard With Defectdojomukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
Building Vulnerability Aging And Sla Trackingmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Building Vulnerability Exception Tracking Systemmukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.0
DashboardInsForge/InsForge13k—~2.3kAutomated safety check: PassApache-2.0
Building Vulnerability Scanning Workflowmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Building Vulnerability Dashboard With Defectdojo

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy DefectDojo as a centralized vulnerability management dashboard that ingests findings from 200+ security scanners, deduplicates results, tracks remediation metrics, and integrates with CI/CD…

    34k GitHub stars~2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Building Vulnerability Aging And Sla Tracking

    mukul975/Anthropic-Cybersecurity-Skills

    Implement a vulnerability aging dashboard and SLA tracking system that measures time-to-remediation against severity-based deadlines (e.g.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Building Vulnerability Exception Tracking System

    mukul975/Anthropic-Cybersecurity-Skills

    Build a vulnerability exception and risk acceptance tracking system covering approval workflows, compensating controls documentation, and automatic expiration for vulnerabilities that miss SLA…

    34k GitHub stars~1.7k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Dashboard

    InsForge/InsForge

    A skill your agent uses when contributing to InsForge's shared dashboard package.

    13k GitHub stars~2.3k tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Building Vulnerability Scanning Workflow

    mukul975/Anthropic-Cybersecurity-Skills

    Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure.

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Vulnerability Scanning

    sickn33/agentic-awesome-skills

    Scan systems and dependencies for CVEs and security vulnerabilities.

    47k GitHub starsUsed in 1 repo~2.8k tokens
    SecurityAuto-check passed

More from davepoon/buildwithclaude

All 245 skills in this repo
  • Qwen Vision

    davepoon/buildwithclaude

    A skill your agent uses when the user asks to "analyze video", "watch this video", "what happens in this video", "describe this clip", "review this footage", "classify these videos", "compare…

    3.6k GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed
  • Hard Predict Future

    davepoon/buildwithclaude

    Activate this agent for any future-oriented question that requires deep quantitative analysis, historical precedents, and structured scenario planning.

    3.6k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • iOS Hig Design Guide

    davepoon/buildwithclaude

    Build, update, and apply iOS design specifications using Apple Human Interface Guidelines (HIG) source data.

    3.6k GitHub stars~735 tokensUpdated yesterday
    Auto-check passed
  • Video Downloader

    davepoon/buildwithclaude

    Download YouTube videos with customizable quality and format options.

    3.6k GitHub starsUsed in 1 repo~871 tokens
    Auto-check passed
  • Atlas Cloud Media

    davepoon/buildwithclaude

    Discover Atlas Cloud image and video models, inspect their live schemas, and submit one confirmed media generation request with bounded GET polling.

    3.6k GitHub stars~852 tokensUpdated yesterday
    Auto-check passed
  • Slack Gif Creator

    davepoon/buildwithclaude

    Toolkit for creating animated GIFs optimized for Slack, with validators for size constraints and composable animation primitives.

    3.6k GitHub starsUsed in 12 repos~4.3k tokens
    Auto-check passed

Questions about Dashboard

What does Dashboard do?

View all tracked vulnerabilities and their current status. An agent skill from davepoon/buildwithclaude. Dashboard is an agent skill from davepoon/buildwithclaude.

How do I install Dashboard in Claude Code?

Run `npx skills add davepoon/buildwithclaude --skill dashboard -a claude-code`. Or copy the skill folder (plugins/vulnetix/skills/dashboard in davepoon/buildwithclaude) into .claude/skills/dashboard in your project. Claude Code loads it when a task matches its description.

How do I install Dashboard in Codex?

Run `npx skills add davepoon/buildwithclaude --skill dashboard -a codex`. Or copy the skill folder (plugins/vulnetix/skills/dashboard in davepoon/buildwithclaude) into .agents/skills/dashboard in your project. Codex loads it when a task matches its description.

Can I use Dashboard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davepoon/buildwithclaude --skill dashboard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dashboard, .gemini/skills/dashboard, .github/skills/dashboard and .opencode/skills/dashboard in your project.

What does Dashboard need to run?

Going by SKILL.md and its folder, Dashboard needs the command-line tools its instructions call (npm and go). Its frontmatter pre-approves these tools: Read, Glob, Grep.

Does Dashboard access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dashboard safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dashboard use?

Dashboard is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dashboard use?

About 930 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dashboard?

Skills that share tags, products or a category with Dashboard: Building Vulnerability Dashboard With Defectdojo (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Building Vulnerability Aging And Sla Tracking (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Building Vulnerability Exception Tracking System (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Dashboard (InsForge/InsForge, 13k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dashboard?

davepoon (a GitHub user) maintains it in davepoon/buildwithclaude, which has 3,604 GitHub stars. The repository holds 245 skills in this directory. The repository was last updated on October 6, 2026.

Source: davepoon/buildwithclaude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.