Agent skill

Vuln

by davepoon in davepoon/buildwithclaude

Look up a vulnerability by ID or list all vulnerabilities for a package

MITAuto-check: notesSecurity

Install Vuln

skills CLI
$ npx skills add davepoon/buildwithclaude --skill vuln -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install davepoon/buildwithclaude vuln --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/vulnetix/skills/vuln .claude/skills/vuln && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vuln
GitHub stars
3.6k
Token cost
~3.6k tokens
SKILL.md length
1,509 words
Files
1
Skills in repo
245
Repo updated
First seen
Licence
MIT

At a glance

Look up a vulnerability by ID or list all vulnerabilities for a package

  • Works in 5 steps: Use Glob to check if… → If it exists, use Read to load it → Use Glob for .vulnetix/scans/*.cdx.json… → …
  • Security work in your project
  • SKILL.md covers Argument Detection, Vulnerability Memory…, Dependabot Integration and Vuln Lookup Mode Workflow, plus 3 more sections
  • Calls gh and pip

What it does

Vuln is an agent skill from davepoon/buildwithclaude. Look up a vulnerability by ID or list all vulnerabilities for a package

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw. The licence is MIT.

When your agent uses it

  • Security work in your project

Example prompts

  • “/vuln”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, Glob, Grep, Edit, Write

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Use Glob to check if .vulnetix/memory.yaml exists in the repo root
  2. If it exists, use Read to load it
  3. Use Glob for .vulnetix/scans/*.cdx.json -- if CycloneDX SBOMs exist from prior scans, cross-reference for additional context
  4. Vuln lookup mode: check for the vuln ID or any aliases in memory. If found
  5. Package vulns mode: find all entries referencing the queried package name. If found

What it can do on your machine

Read from SKILL.md and the folder at commit 10bfc43. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Glob
    • Grep
    • Edit
    • Write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vuln loads about 3.6k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 1,509 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Glob, Grep, Edit, Write

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from davepoon/buildwithclaude at commit 10bfc43, republished under its MIT licence (© davepoon). 1,509 words, ~3,601 tokens.

Download SKILL.mdSave it as .claude/skills/vuln/SKILL.md (or your agent's skills folder).
name
vuln
description
Look up a vulnerability by ID or list all vulnerabilities for a package
allowed-tools
Bash, Read, Glob, Grep, Edit, Write
argument-hint
<vuln-id or package-name>
user-invocable
true
model
sonnet

Vulnetix Vulnerability Lookup Skill

This skill serves two purposes based on the argument provided:

  • Vuln ID argument (CVE-, GHSA-, PYSEC-*, etc.) --> retrieves detailed vulnerability intelligence and assesses its impact against the current repository
  • Package name argument (express, lodash, log4j-core, etc.) --> lists all known vulnerabilities for that package and identifies which ones affect your installed version

This skill does not modify application code -- it only updates .vulnetix/memory.yaml to track findings. Use /vulnetix:fix for remediation, /vulnetix:exploits for exploit analysis, or /vulnetix:remediation for a context-aware remediation plan.

Argument Detection

Determine the mode from the argument:

Vuln lookup mode -- argument matches any known vulnerability identifier pattern:

  • CVE-* (e.g., CVE-2021-44228)
  • GHSA-* (e.g., GHSA-jfh8-3a1q-hjz9)
  • PYSEC-*, GO-*, RUSTSEC-*, EUVD-*, OSV-*, GSD-*, VDB-*, GCVE-*
  • SNYK-*, ZDI-*, MSCVE-*, MSRC-*, RHSA-*, TALOS-*, EDB-*
  • WORDFENCE-*, PATCHSTACK-*, MFSA*, JVNDB-*, CNVD-*, BDU:*, HUNTR-*
  • DSA-*, DLA-*, USN-*, ALSA-*, RLSA-*, MGASA-*, OPENSUSE-*, FreeBSD-*, BIT-*

The VDB accepts 78+ identifier formats in total.

Package vulns mode -- argument does not match any vuln-id pattern. Treat it as a package name.

If ambiguous, prefer vuln lookup mode (vuln IDs are more structured). If the vuln lookup returns an error or empty response, fall back to package vulns mode automatically.

Vulnerability Memory (.vulnetix/memory.yaml)

This skill reads and updates the .vulnetix/memory.yaml file in the repository root. This file is shared with /vulnetix:fix, /vulnetix:exploits, /vulnetix:package-search, /vulnetix:exploits-search, and /vulnetix:remediation.

Schema

The canonical schema is defined in /vulnetix:fix. This skill creates or updates base vulnerability fields: aliases, package, ecosystem, discovery, versions, severity, safe_harbour, and status. It does not modify threat_model or cwss (owned by /vulnetix:exploits).

Reading Prior State and SBOMs

At the start of every invocation:

  1. Use Glob to check if .vulnetix/memory.yaml exists in the repo root
  2. If it exists, use Read to load it
  3. Use Glob for .vulnetix/scans/*.cdx.json -- if CycloneDX SBOMs exist from prior scans, cross-reference for additional context
  4. Vuln lookup mode: check for the vuln ID or any aliases in memory. If found:
    Previously seen: <vulnId> -- <developer-friendly status> (as of <date>)
    Priority: <P1/P2/P3/P4> (<score>) -- "<priority description>" (if cwss data exists)
    Last decision: <developer-friendly decision> -- "<reason>"
    Dependabot: <alert state, PR state if available>
  5. Package vulns mode: find all entries referencing the queried package name. If found:
    Known history for <package>:
    - CVE-2021-44228 -- Fixed (2024-01-15), P1 (87.5)
    - CVE-2023-1234 -- Investigating (2024-03-01)
Writing Updated State

Vuln lookup mode (after Step L6):

  1. If no entry exists, create one with status: under_investigation, decision.choice: investigating, discovery.source: user
  2. If an entry exists, merge aliases, update severity and safe_harbour if newer. Do NOT change status or decision.
  3. Append to history: event: lookup

Package vulns mode (after Step P7):

For each vulnerability that affects the installed version and is not already tracked:

  1. Create a minimal stub entry with status: under_investigation, decision.choice: investigating, discovery.source: scan, decision.reason: "Discovered via /vulnetix:vuln <package>"
  2. Append to history: event: discovered

For existing entries, do not change status or decision -- only update severity if newer.

VEX Status Mapping

Use developer-friendly language when surfacing status:

  • not_affected --> "Not affected"
  • affected --> "Vulnerable"
  • fixed --> "Fixed"
  • under_investigation --> "Investigating"

Dependabot Integration

When gh CLI is available (check with gh auth status 2>/dev/null), query Dependabot alerts to enrich the output.

Vuln lookup mode: Query alerts matching the vuln ID:

bash
gh api repos/{owner}/{repo}/dependabot/alerts --jq '[.[] | select(.security_advisory.cve_id == "'"$ARGUMENTS"'" or .security_advisory.ghsa_id == "'"$ARGUMENTS"'")] | first'

Package vulns mode: Query alerts for the package:

bash
gh api repos/{owner}/{repo}/dependabot/alerts?state=open --jq '[.[] | select(.dependency.package.name == "'"$PACKAGE_NAME"'")] | length'

Vuln Lookup Mode Workflow

Use this workflow when the argument matches a vulnerability identifier pattern.

Step L1: Load Vulnerability Memory

Check for and load .vulnetix/memory.yaml as described in "Reading Prior State" above. Display any prior state before proceeding.

Step L2: Fetch Vulnerability Data
bash
vulnetix vdb vuln "$ARGUMENTS" -o json

CLI Reference (from vulnetix vdb vuln docs):

  • Accepts any of the 78+ identifier formats
  • -o json returns machine-readable output
  • Response includes: identifier and aliases, description, published/modified dates, CVSS scores (v2, v3, v4), references/advisories, affected products/versions, EPSS probability, KEV status

Extract: identity, aliases, description, dates, CVSS vectors/scores, EPSS, KEV status/deadline, CWE IDs, affected products with version ranges and fixed versions, reference URLs.

Step L3: Enrich with Metrics
bash
vulnetix vdb metrics "$ARGUMENTS" -o json

CLI Reference (from vulnetix vdb metrics docs):

  • Returns structured metric objects by type (CVSS v2, v3.1, v4, EPSS, etc.)
  • Each metric includes: source, type, score, vector string, timestamp

Merge with Step L2 data. If this call fails, continue with Step L2 data alone.

Step L4: Analyze Repository Impact

Use Glob and Grep to assess repo impact:

  1. Detect manifest files:

    • package.json, package-lock.json, yarn.lock, pnpm-lock.yaml --> npm
    • go.mod, go.sum --> go
    • Cargo.toml, Cargo.lock --> cargo
    • requirements.txt, pyproject.toml, Pipfile, poetry.lock, uv.lock --> pypi
    • Gemfile, Gemfile.lock --> rubygems
    • pom.xml, build.gradle, gradle.lockfile --> maven
    • composer.json, composer.lock --> packagist
  2. Search for affected packages from VDB response using Grep in manifests/lockfiles

  3. Determine installed version (lockfile --> manifest --> installed artifacts --> unknown). Report source transparently.

  4. Assess dependency relationship -- direct vs transitive, whether installed version is in vulnerable range

  5. Cross-reference CycloneDX SBOMs in .vulnetix/scans/*.cdx.json

Step L5: Present Structured Summary

Identity:

<Vuln ID> (<alias1>, <alias2>, ...)
<Description -- first 2-3 sentences>
Published: <date>  |  Modified: <date>

Severity Table:

MetricScoreVector
CVSS v3.110.0 (Critical)AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4.010.0 (Critical)...
EPSS0.97 (97% chance of exploitation within 30 days)--
CISA KEVListed (deadline: YYYY-MM-DD)--

Affected Packages:

PackageEcosystemVulnerable RangeFixed In
log4j-coremaven< 2.17.12.17.1

Repository Impact:

PackageInstalled VersionSourceAffected?Relationship
log4j-core2.14.1lockfile: pom.xmlYes (in range)Direct

If no affected packages found: "No affected packages detected in this repository."

References: List top advisory and reference URLs.

Next Steps:

  • "Run /vulnetix:exploits $ARGUMENTS for exploit intelligence and threat modeling"
  • "Run /vulnetix:fix $ARGUMENTS for fix intelligence and manifest edits"
  • "Run /vulnetix:remediation $ARGUMENTS for a context-aware remediation plan"
  • "Run /vulnetix:exploits-search --ecosystem <eco> to discover related exploited vulnerabilities"
Step L6: Update Vulnerability Memory

Update .vulnetix/memory.yaml as described in "Writing Updated State" above. If the user provides a decision during the conversation, record it using the risk treatment categories defined in /vulnetix:exploits.


Show full SKILL.md (628 more words)Show less

Package Vulns Mode Workflow

Use this workflow when the argument does not match a vulnerability identifier pattern.

Step P1: Load Vulnerability Memory

Check for and load .vulnetix/memory.yaml. Display any known history for the queried package before proceeding.

Step P2: Detect Repository Ecosystems

Use Glob to identify manifest files (same manifest list as Step L4 above). Determine which ecosystems the repository uses.

Step P3: Detect Installed Version

Determine if the queried package is installed. Resolve using the priority chain:

  1. User-supplied version -- explicitly stated in the user's message
  2. Lockfile -- most authoritative:
    • npm: package-lock.json, yarn.lock, pnpm-lock.yaml
    • pypi: poetry.lock, Pipfile.lock, uv.lock
    • go: go.sum
    • cargo: Cargo.lock
    • rubygems: Gemfile.lock
    • maven: gradle.lockfile
    • packagist: composer.lock
  3. Manifest file -- declared version constraint (less precise)
  4. Installed artifacts -- query installed state (e.g., node_modules/<pkg>/package.json, pip show <pkg>)

If not installed: "Not currently installed -- no existing version detected."

Version Source Label: 4.17.1 (from lockfile: package-lock.json), ^4.17.0 (from manifest: package.json -- constraint, not exact), Not installed

Step P4: Fetch Package Vulnerabilities
bash
vulnetix vdb vulns "$ARGUMENTS" -o json

CLI Reference (from vulnetix vdb vulns docs):

  • Retrieves all known vulnerabilities for a specific package
  • Flags:
    • --limit int -- Maximum results (default 100)
    • --offset int -- Results to skip for pagination (default 0)
    • -o, --output string -- Output format: json or pretty (default "pretty")
  • Response includes: total count, vulnerability identifiers, severity, CVSS, affected version ranges, fixed versions, descriptions, references, pagination info

Pagination modifiers -- parse user message:

  • "first 20" / "top 20" / "limit 20" --> --limit 20
  • "next page" / "more" / "page 2" --> --offset <previous_offset + limit>
  • "all" --> --limit 500
Step P5: Filter and Enrich
  1. Filter by repo ecosystems -- discard vulns from ecosystems not in the repo
  2. Cross-reference with memory -- note prior status, decision, CWSS priority, PoC count for each
  3. Determine "Affects You?" -- compare installed version against each vuln's affected range:
    • Yes -- installed version in vulnerable range
    • No -- installed version outside range
    • Unknown -- version undetermined or range data incomplete
Step P6: Present Vulnerability List
Vulnerabilities for <package>@<version> (<version source>)
Total: N known vulnerabilities (M affect your version)

| # | ID              | Severity | Affects You? | Fixed In | Status       | EPSS  |
|---|-----------------|----------|-------------|----------|--------------|-------|
| 1 | CVE-2024-XXXXX  | critical | Yes         | 4.18.3   | --           | 0.45  |
| 2 | CVE-2023-YYYYY  | high     | Yes         | 4.17.3   | Fixed        | 0.12  |
| 3 | CVE-2022-ZZZZZ  | medium   | No (>=4.17) | 4.17.0   | --           | 0.03  |

Summary: M of N affect your version -- X critical, Y high, Z medium

Pagination info (if truncated): Showing 1-20 of 47. Say "next page" or "page 3" for more.

Actionable recommendations:

  • Critical/high affecting installed version: "Run /vulnetix:fix <vuln-id> to remediate" or "Run /vulnetix:remediation <vuln-id> for a context-aware remediation plan"
  • Vulns with exploit signals: "Run /vulnetix:exploits <vuln-id> for exploit analysis"
  • Any vuln: "Run /vulnetix:vuln <vuln-id> for detailed vulnerability info"
  • Broad discovery: "Run /vulnetix:exploits-search --ecosystem <eco> to find exploited vulnerabilities in your ecosystem"
Step P7: Update Vulnerability Memory

Update .vulnetix/memory.yaml as described in "Writing Updated State" above. Only create stub entries for vulns that affect the installed version to prevent memory file bloat.


Error Handling

Vuln lookup mode:

  • If vdb vuln returns error/empty, try falling back to package vulns mode (the argument might be a package name)
  • If vdb metrics fails, continue with vdb vuln data alone
  • If no manifest files found, note repo impact analysis is inconclusive
  • If vuln ID not found, suggest alternative formats (GHSA if CVE fails, etc.)

Package vulns mode:

  • If vdb vulns returns error, suggest checking vulnetix vdb status
  • If no vulns found: "No known vulnerabilities found for <package>. This doesn't guarantee safety -- the package may not be indexed yet."
  • If package not found in repo ecosystems, suggest /vulnetix:package-search
  • If manifest files missing, "Affects You?" shows "Unknown"

Both modes:

  • If .vulnetix/memory.yaml cannot be written, warn but do not block

Important Reminders

  1. This skill does not modify application code -- use /vulnetix:fix or /vulnetix:remediation for that
  2. This skill does not fetch or analyze exploits -- use /vulnetix:exploits for single-vuln analysis or /vulnetix:exploits-search for broad discovery
  3. EPSS display: "X% chance of exploitation within 30 days" in vuln mode, decimal (0.45) in table columns
  4. Safe Harbour scores: convert API integer (0-100) to decimal (0.00-1.00)
  5. Always update .vulnetix/memory.yaml after the lookup
  6. Version source transparency is mandatory
  7. Prior data serves as baseline on re-invocation -- update, don't restart

© davepoon, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/vulnetix/skills/vuln of davepoon/buildwithclaude.

Open the folder on GitHubat commit 10bfc43

Compare with similar skills

Vuln next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vuln compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vuln this skilldavepoon/buildwithclaude3.6k—~3.6kAutomated safety check: NotesMIT
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4801 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    480 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from davepoon/buildwithclaude

All 245 skills in this repo
  • Qwen Vision

    davepoon/buildwithclaude

    A skill your agent uses when the user asks to "analyze video", "watch this video", "what happens in this video", "describe this clip", "review this footage", "classify these videos", "compare…

    3.6k GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed
  • Hard Predict Future

    davepoon/buildwithclaude

    Activate this agent for any future-oriented question that requires deep quantitative analysis, historical precedents, and structured scenario planning.

    3.6k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • iOS Hig Design Guide

    davepoon/buildwithclaude

    Build, update, and apply iOS design specifications using Apple Human Interface Guidelines (HIG) source data.

    3.6k GitHub stars~735 tokensUpdated 2 days ago
    Auto-check passed
  • Video Downloader

    davepoon/buildwithclaude

    Download YouTube videos with customizable quality and format options.

    3.6k GitHub starsUsed in 1 repo~871 tokens
    Auto-check passed
  • Atlas Cloud Media

    davepoon/buildwithclaude

    Discover Atlas Cloud image and video models, inspect their live schemas, and submit one confirmed media generation request with bounded GET polling.

    3.6k GitHub stars~852 tokensUpdated 2 days ago
    Auto-check passed
  • Slack Gif Creator

    davepoon/buildwithclaude

    Toolkit for creating animated GIFs optimized for Slack, with validators for size constraints and composable animation primitives.

    3.6k GitHub starsUsed in 12 repos~4.3k tokens
    Auto-check passed

Categories

Questions about Vuln

What does Vuln do?

Look up a vulnerability by ID or list all vulnerabilities for a package. Vuln is an agent skill from davepoon/buildwithclaude.

When should I use Vuln?

Vuln fits situations like: security work in your project.

How do I install Vuln in Claude Code?

Run `npx skills add davepoon/buildwithclaude --skill vuln -a claude-code`. Or copy the skill folder (plugins/vulnetix/skills/vuln in davepoon/buildwithclaude) into .claude/skills/vuln in your project. Claude Code loads it when a task matches its description.

How do I install Vuln in Codex?

Run `npx skills add davepoon/buildwithclaude --skill vuln -a codex`. Or copy the skill folder (plugins/vulnetix/skills/vuln in davepoon/buildwithclaude) into .agents/skills/vuln in your project. Codex loads it when a task matches its description.

Can I use Vuln in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davepoon/buildwithclaude --skill vuln -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vuln, .gemini/skills/vuln, .github/skills/vuln and .opencode/skills/vuln in your project.

What does Vuln need to run?

Going by SKILL.md and its folder, Vuln needs the command-line tools its instructions call (gh and pip). Its frontmatter pre-approves these tools: Bash, Read, Glob, Grep, Edit, Write.

Does Vuln access the network?

SKILL.md contains no URLs. Its commands use gh and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Vuln safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Vuln use?

Vuln is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vuln use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vuln?

Skills that share tags, products or a category with Vuln: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 480 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vuln?

davepoon (a GitHub user) maintains it in davepoon/buildwithclaude, which has 3,604 GitHub stars. The repository holds 245 skills in this directory. The repository was last updated on October 6, 2026.

Source: davepoon/buildwithclaude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.