Install the "remediation" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/remediation into .claude/skills/remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remediation", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add davepoon/buildwithclaude --skill remediation -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "remediation" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/remediation into .agents/skills/remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remediation", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add davepoon/buildwithclaude --skill remediation -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "remediation" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/remediation into .cursor/skills/remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remediation", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add davepoon/buildwithclaude --skill remediation -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "remediation" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/remediation into .gemini/skills/remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remediation", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add davepoon/buildwithclaude --skill remediation -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "remediation" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/remediation into .github/skills/remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remediation", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add davepoon/buildwithclaude --skill remediation -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "remediation" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/remediation into .opencode/skills/remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remediation", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
remediation
GitHub stars
3.6k
Token cost
~3.8k tokens
SKILL.md length
1,568 words
Files
1
Skills in repo
246
Repo updated
First seen
Licence
MIT
At a glance
Get a context-aware remediation plan for a vulnerability with fix verification steps
Works in 7 steps: Load Memory and Detect Repository Context → Auto-Populate Context Flags → Execute Remediation Plan Query → …
SKILL.md covers Vulnerability Memory…, Dependabot Integration, Workflow and Error Handling, plus 1 more section
Calls apt-get, jq and gh
What it does
Remediation is an agent skill from davepoon/buildwithclaude. Get a context-aware remediation plan for a vulnerability with fix verification steps
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw. The licence is MIT.
Read from SKILL.md and the folder at commit 616deb5. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves these tools, so the agent can use them without asking each time:
Bash
Read
Glob
Grep
Edit
Write
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
apt-get
jq
gh
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Remediation loads about 3.8k tokens when it runs. Until then it costs about 24 tokens; SKILL.md has 1,568 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~24
When it runs· the whole SKILL.md, loaded when a task matches
~3.8k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check: notes
The automated check noted patterns worth knowing about, such as sudo or a known installer.
NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/remediation/SKILL.md (or your agent's skills folder).
name
remediation
description
Get a context-aware remediation plan for a vulnerability with fix verification steps
allowed-tools
Bash, Read, Glob, Grep, Edit, Write
argument-hint
<vuln-id>
user-invocable
true
model
sonnet
Vulnetix Remediation Plan Skill
This skill generates a comprehensive, context-aware remediation plan for a specific vulnerability using the VDB V2 remediation API. It auto-detects your repository's ecosystem, package manager, installed versions, container images, and OS to provide targeted fix guidance including registry upgrades, source patches, distribution advisories, workarounds, CWE-specific remediation strategies, and verification commands.
How this differs from /vulnetix:fix: The existing /vulnetix:fix skill fetches V1 fix data and proposes manual manifest edits. This skill uses the V2 remediation plan endpoint which provides context-aware guidance (ecosystem, version, OS, container), CWE remediation strategies, CrowdSec threat intelligence (live exploitation data), workaround effectiveness scoring, SSVC decision support, and verification commands per package manager.
Vulnerability Memory (.vulnetix/memory.yaml)
This skill reads and updates the .vulnetix/memory.yaml file in the repository root. This file is shared with /vulnetix:fix, /vulnetix:exploits, /vulnetix:package-search, /vulnetix:vuln, and /vulnetix:exploits-search.
Schema
The canonical schema is defined in /vulnetix:fix. This skill updates base fields and appends remediation plan events to the history log.
Reading Prior State
At the start of every invocation:
Use Glob to check if .vulnetix/memory.yaml exists in the repo root
If it exists, use Read to load it and check for the vuln ID or aliases
Use Glob for .vulnetix/scans/*.cdx.json -- cross-reference for component data
If a prior entry exists, display:
Previously seen: <vulnId> -- <developer-friendly status> (as of <date>)
Priority: <P1/P2/P3/P4> (<score>) (if cwss data exists)
Last decision: <developer-friendly decision> -- "<reason>"
Writing Updated State
After completing the remediation plan (Step 7):
If no entry exists, create one with status: under_investigation, discovery.source: user
If an entry exists, update severity, safe_harbour, and versions.fixed_in from the remediation plan data. Merge aliases.
Do NOT change status or decision unless the user explicitly makes a decision during the conversation
Append to history: event: remediation-plan, detail: summary of fix options found (registry fixes, source fixes, workarounds, distribution patches)
Confirm to the user
VEX Status Mapping
not_affected --> "Not affected"
affected --> "Vulnerable"
fixed --> "Fixed"
under_investigation --> "Investigating"
Dependabot Integration
When gh CLI is available (check with gh auth status 2>/dev/null), query Dependabot alerts for the vuln ID to cross-reference with the remediation plan.
Query alerts matching this vuln ID
If a Dependabot PR exists, note it in the output: "Dependabot PR #N proposes this upgrade -- consider reviewing and merging it"
If the vuln ID is already in memory with a package field, use that package name
If not, run a quick lookup to get affected products:bash
vulnetix vdb vuln "$ARGUMENTS" -o json
Extract affected package names and ecosystems from the response.
For each affected package found in the repo, detect the installed version using the priority chain: lockfile --> manifest --> installed artifacts --> unknown
Step 2: Auto-Populate Context Flags
Build the CLI flags automatically from repository state:
Flag
Source
How to detect
--ecosystem
Manifest files
From Step 1 ecosystem detection
--package-name
VDB response or memory
Affected package name matching repo
--current-version
Lockfile/manifest
Installed version from Step 1
--package-manager
Manifest file type
package-lock.json --> npm, yarn.lock --> yarn, poetry.lock --> pip/poetry, etc.
--purl
Constructed
If ecosystem + name + version are known, construct pkg:<eco>/<name>@<version>
--container-image
Containerfile/Dockerfile
Use Glob for Containerfile, Dockerfile, *.dockerfile. If found, Read and extract FROM image reference (e.g., node:18-alpine)
--os
OS detection
Check for /etc/os-release or infer from container base image
--vendor
VDB response
From affected products vendor field
--product
VDB response
From affected products product field
Always set:
--include-guidance -- includes CWE-specific remediation strategies
--include-verification-steps -- includes per-package-manager verification commands
If no package context can be determined (no manifests, no memory), run the command without package-specific flags -- the API will still return general remediation guidance.
CWE-<id>: <title>
Remediation strategy:
<markdown guidance from API>
Verification guidance:
<markdown from API>
Verification Steps (per package manager):
Verify the fix:
npm: npm audit --json | jq '.vulnerabilities["<package>"]'
maven: mvn dependency:tree | grep <package>
pip: pip show <package> | grep Version
Show full SKILL.md (639 more words)Show less
Step 5: Cross-Reference with Dependabot and Memory
If Dependabot PR exists for this upgrade, note: "Dependabot PR #N already proposes this upgrade -- consider reviewing and merging"
If a prior /vulnetix:exploits analysis exists in memory (threat_model, cwss), surface the priority: "Prior exploit analysis: P1 (87.5) -- Act now"
If a prior /vulnetix:fix analysis exists, note what was previously proposed
Step 6: Present Actionable Next Steps
Based on the remediation plan, present concrete actions:
If registry fix available: Show exact manifest edit (same diff format as /vulnetix:fix) with the fix version from the remediation plan. Offer to apply it.
If source fix only (no registry release): Note that the fix requires building from source or waiting for a release. Link to the commit/PR.
If workaround only: Present the workaround steps with effectiveness score. Note: "No patch available yet -- workaround is interim mitigation."
If distribution patch: Provide the package manager command (e.g., apt-get update && apt-get install --only-upgrade <package>)
Test commands: Suggest running tests after applying the fix
Re-scan: Suggest vulnetix vdb vuln <vuln-id> to verify the fix resolved the vulnerability
Rollback guidance: If the fix introduces breaking changes, note the backup/rollback approach
Cross-references:
"Run /vulnetix:exploits $ARGUMENTS for exploit intelligence and threat modeling"
"Run /vulnetix:vuln $ARGUMENTS for full vulnerability details"
"Run /vulnetix:exploits-search --ecosystem <eco> to discover related exploited vulnerabilities"
Step 7: Update Vulnerability Memory
Use Read to load the current memory file
Create or update the entry:
versions.fixed_in -- from the registry fix data
versions.fix_source -- registry name and version
severity -- from CVSS data
safe_harbour -- computed from fix confidence
aliases -- merge any newly discovered aliases
dependabot -- if gathered in Step 5
Append to history: event: remediation-plan, detail: summary of fix options (e.g., "Registry fix: 2.17.1 (Maven Central, High confidence). 2 workarounds available. CWE-502 guidance provided.")
Use Write to save
Confirm to the user
If the user applies a fix or makes a decision:
Record using the risk treatment categories from /vulnetix:exploits
Set status: fixed and decision.choice: fix-applied if they apply the fix
Append event: fix-applied with detail including the version change
Error Handling
If vulnetix vdb remediation plan returns an error, fall back to vulnetix vdb fixes "$ARGUMENTS" -o json (V1 endpoint) and present basic fix data. Note that V2 enrichment (workarounds, CWE guidance, verification steps) is unavailable.
If the vuln ID is not found, suggest checking the format and provide examples
If no package context can be determined from the repo, run without context flags and note that guidance is generic rather than repo-specific
If no fixes, workarounds, or patches are available, state clearly: "No remediation options are currently available for this vulnerability. Consider risk acceptance or component removal."
If .vulnetix/memory.yaml cannot be written, warn but do not block
Important Reminders
This skill proposes code changes (manifest edits) but always asks before applying -- same guardrail as /vulnetix:fix
Auto-populate context flags from the repo -- the V2 API returns better results with more context. Always detect ecosystem, package name, current version, and package manager.
Container detection is important -- if a Containerfile/Dockerfile exists, extract the base image for OS-specific distribution patches
Safe Harbour scores: compute from fix confidence tiers, display as 0.00-1.00
Version source transparency is mandatory -- always disclose how the current version was determined
CrowdSec data is live threat intelligence -- if sightings are active, flag prominently
The agent_prompt field in the response contains AI-optimized context -- use it to inform your analysis but do not display it raw to the user
Always update .vulnetix/memory.yaml after generating the plan
If Dependabot already has a PR for this fix, prefer merging that PR over manual edits
The V2 remediation endpoint is the most comprehensive single endpoint -- it aggregates data from registry fixes, source fixes, distribution patches, workarounds, CWE guidance, and KEV data into one response
Remediation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes.
Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure.
Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.
Deploy DefectDojo as a centralized vulnerability management dashboard that ingests findings from 200+ security scanners, deduplicates results, tracks remediation metrics, and integrates with CI/CD…
A skill your agent uses when the user asks to "analyze video", "watch this video", "what happens in this video", "describe this clip", "review this footage", "classify these videos", "compare…
Toolkit for creating animated GIFs optimized for Slack, with validators for size constraints and composable animation primitives.
3.6k GitHub starsUsed in 12 repos~4.3k tokens
Auto-check passed
Questions about Remediation
What does Remediation do?
Get a context-aware remediation plan for a vulnerability with fix verification steps. Remediation is an agent skill from davepoon/buildwithclaude.
How do I install Remediation in Claude Code?
Run `npx skills add davepoon/buildwithclaude --skill remediation -a claude-code`. Or copy the skill folder (plugins/vulnetix/skills/remediation in davepoon/buildwithclaude) into .claude/skills/remediation in your project. Claude Code loads it when a task matches its description.
How do I install Remediation in Codex?
Run `npx skills add davepoon/buildwithclaude --skill remediation -a codex`. Or copy the skill folder (plugins/vulnetix/skills/remediation in davepoon/buildwithclaude) into .agents/skills/remediation in your project. Codex loads it when a task matches its description.
Can I use Remediation in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davepoon/buildwithclaude --skill remediation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/remediation, .gemini/skills/remediation, .github/skills/remediation and .opencode/skills/remediation in your project.
What does Remediation need to run?
Going by SKILL.md and its folder, Remediation needs the command-line tools its instructions call (apt-get, jq and gh). Its frontmatter pre-approves these tools: Bash, Read, Glob, Grep, Edit, Write.
Does Remediation access the network?
SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Is Remediation safe to install?
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
What licence does Remediation use?
Remediation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Remediation use?
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Remediation?
Skills that share tags, products or a category with Remediation: Performing Endpoint Vulnerability Remediation (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Vulnerability Remediation Sla (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Building Vulnerability Scanning Workflow (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Vulnerability Scanning (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Remediation?
davepoon (a GitHub user) maintains it in davepoon/buildwithclaude, which has 3,605 GitHub stars. The repository holds 246 skills in this directory. The repository was last updated on October 9, 2026.
Source: davepoon/buildwithclaude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.