Agent skill

Cve Doctor

by getlago in getlago/lago-front

Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix.

MITAuto-check passedSecurity

Install Cve Doctor

skills CLI
$ npx skills add getlago/lago-front --skill cve-doctor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install getlago/lago-front cve-doctor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/getlago/lago-front.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/cve-doctor .claude/skills/cve-doctor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cve-doctor
GitHub stars
163
Token cost
~2.9k tokens
SKILL.md length
1,479 words
Files
3
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix.

  • Works in 7 steps: Collect input → Detect the package manager → Is this a direct dependency? → …
  • The user asks to fix a CVE
  • SKILL.md covers Guiding principles, Phase 0 — Collect input, Phase 1 — Detect the package… and Phase 2 — Is this a direct…, plus 6 more sections
  • Calls yarn, gh and npm; reaches github.com

What it does

Cve Doctor is an agent skill from getlago/lago-front. Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix. Walks the dependency chain, identifies the parent that blocks the patch, flags unmaintained packages, and only suggests a package-manager override as a last resort with explicit user confirmation. TRIGGER when the user asks to "fix a CVE", references a Dependabot alert URL (github.com//security/dependabot/), mentions a CVE-YYYY-NNNN or GHSA- identifier, or asks how to resolve a vulnerable transitive dependency.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `README.md`).

It sits in Security, covering Vulnerability scanning and Dependency management. It works with GitHub. The repository describes itself as: Open Source Metering and Usage Based Billing. The licence is MIT.

When your agent uses it

  • The user asks to fix a CVE
  • References a Dependabot alert URL (github.com//security/dependabot/)
  • Mentions a CVE-YYYY-NNNN
  • GHSA- identifier

Example prompts

  • “fix a CVE”
  • “/cve-doctor”

Requirements

  • Node.js

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Collect input
  2. Detect the package manager
  3. Is this a direct dependency?
  4. Walk the dependency chain
  5. Investigate hard-blocking parents
  6. Present ranked options
  7. Apply the chosen option

What it can do on your machine

Read from SKILL.md and the folder at commit c3f9715. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • yarn
    • gh
    • npm
    • pnpm
    • bun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cve Doctor loads about 2.9k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 1,479 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from getlago/lago-front at commit c3f9715, republished under its MIT licence (© getlago). 1,479 words, ~2,857 tokens.

Download SKILL.mdSave it as .claude/skills/cve-doctor/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
cve-doctor
description
Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix. Walks the dependency chain, identifies the parent that blocks the patch, flags unmaintained packages, and only suggests a package-manager override as a last resort with explicit user confirmation. TRIGGER when the user asks to "fix a CVE", references a Dependabot alert URL (github.com/*/security/dependabot/*), mentions a CVE-YYYY-NNNN or GHSA-* identifier, or asks how to resolve a vulnerable transitive dependency.

cve-doctor

You are helping the user triage a single CVE / security advisory in a JavaScript or TypeScript project. The goal is to resolve it with the least-invasive change possible, preserving the project's semver intent and Dependabot/Renovate visibility. A package-manager override is the absolute last resort.

Guiding principles

  1. Investigate before acting. Do not install packages, edit package.json, or run update until you have walked the full chain and presented options.
  2. User decides at every branch. When there are multiple viable fix paths, list them ranked least → most invasive and wait for the user to pick. Never silently pick the "easiest" option for them.
  3. Overrides are a last resort. A pnpm.overrides / npm.overrides / yarn.resolutions entry hides the problem from future automated scans and creates a drift-debt. Only suggest it after every upstream path has been exhausted, and only with explicit "yes, do it" from the user.
  4. Unmaintained upstream is information, not a verdict. If a blocking parent looks abandoned, report the specific signals (archived flag, last commit date, last release date) and let the user decide whether to fork, switch packages, or override.

Phase 0 — Collect input

  1. Read $ARGUMENTS from the invocation.
  2. Parse it:
    • Dependabot alert URL of the form https://github.com/<owner>/<repo>/security/dependabot/<n>: run gh api repos/<owner>/<repo>/dependabot/alerts/<n> to fetch the alert JSON.
    • CVE ID (CVE-YYYY-NNNN) or GHSA ID (GHSA-*): run gh api /advisories/<id> to fetch the advisory. If the advisory has multiple vulnerabilities[], ask the user which package+ecosystem applies in this project.
    • Empty: ask the user for a Dependabot alert URL or CVE/GHSA ID. Do not proceed without one.
  3. From the fetched data, extract and display to the user:
    • Package name + ecosystem
    • Severity (CVSS score if available)
    • Short summary
    • vulnerable_version_range[] and first_patched_version for each range
    • Alert state (if applicable): open, fixed, dismissed, auto_dismissed
  4. Short-circuit: if the alert state is fixed or auto_dismissed, report that the alert is already resolved and stop. Do not continue to Phase 1.

Phase 1 — Detect the package manager

Check the project root for lockfiles (in this priority order when multiple exist — but ask the user if ambiguous):

LockfilePM
pnpm-lock.yamlpnpm
yarn.lockyarn (check package.json → packageManager for classic vs berry)
package-lock.jsonnpm
bun.lock or bun.lockbbun

Record the detected PM. All commands below branch on this value — use the matrix at the bottom of this file.

Phase 2 — Is this a direct dependency?

  1. Grep the vulnerable package name in package.json (dependencies, devDependencies, peerDependencies, and any workspace package.jsons).
  2. If it's a direct dep:
    • Check whether the latest version on the registry (<pm> view <pkg> version) is outside all vulnerable ranges.
    • Check whether our declared semver range admits a patched version.
    • If yes to both → this is a one-shot fix. Propose the single targeted update command (see matrix) and ask: "Want me to run this?" Then stop here.
    • If no (declared range pins to an unpatched major) → also ask the user whether they want to bump the major, and outline the risks. Stop here; it's not a transitive-chain problem.
  3. If it's not direct → continue to Phase 3.

Phase 3 — Walk the dependency chain

  1. Run the PM-specific "why" command and capture the full output.

  2. Parse it into a flat list of (parent-package@parent-version, declared-range-for-vuln-pkg) tuples. Include every path, not just the first.

  3. Identify every distinct installed version of the vulnerable package in the lockfile (grep the lockfile for ^\s+<pkg>: or equivalent). For each version, check it against every vulnerable_version_range from Phase 0.

  4. For each vulnerable installed version, and for each immediate parent:

    • Look up the parent's latest published version and its declared range for the vulnerable package: <pm> view <parent>@latest dependencies.<vuln-pkg>.
    • Look up the parent's currently-installed version's declared range.
    • Classify the parent:
      • Auto-resolves on refresh: the installed parent's declared range already admits a patched version (the lockfile is simply stale).
      • Fixed in newer parent version: current parent blocks, but latest parent admits a patch.
      • Blocks even at latest: current AND latest parent versions both pin to a vulnerable range. This is a hard blocker — continue to Phase 4 for this parent.
  5. Print a compact summary table:

    Vulnerable version  | Parent                  | Status
    <pkg>@<v>           | <parent>@<v>            | Auto-resolves / Needs parent bump to <v'> / Hard blocker

Phase 4 — Investigate hard-blocking parents

For each parent in the "hard blocker" category, gather (all read-only):

  1. Latest release metadata — <pm> view <parent> version repository time.modified.
  2. Repository signals — from the repository URL, run:
    • gh api repos/<owner>/<repo> → capture archived, pushed_at, updated_at, open_issues_count.
    • gh search issues "<CVE-ID>" repo:<owner>/<repo> --state=all → any existing discussion?
    • gh search issues "<vuln-pkg>" repo:<owner>/<repo> --state=open → any open issue mentioning the vulnerable dep?
    • gh pr list --repo <owner>/<repo> --search "<vuln-pkg>" --state=all → any open or merged PR bumping it?
  3. Classify the blocker and report to the user:
    • (a) Upstream PR exists — link the PR and its state. Suggest: wait for merge, or (if urgent) pin to a git-URL fork of the merged branch.
    • (b) Upstream issue exists, no PR — link the issue and its age. Suggest: +1 the issue, or contribute a PR.
    • (c) No discussion upstream, repo actively maintained — propose opening an issue. Pre-fill a suggested title/body citing the CVE ID, vulnerable range, and patched version.
    • (d) Unmaintained signals — report each of the following that applies, verbatim, and let the user judge:
      • Repo archived: true
      • pushed_at older than 12 months
      • Latest npm release older than 12 months
      • No open-issues response from maintainers in the last 6 months Do not pronounce a package "abandoned" — state the facts and let the user decide.
    • (d-alt) Known alternative package exists — if the blocker is in a narrow category (e.g. request → undici/node-fetch, node-sass → sass), mention the alternative as context but do not recommend migrating without explicit user interest.
Show full SKILL.md (556 more words)Show less

Phase 5 — Present ranked options

Produce a single summary to the user with the applicable options only, in this order (skip any that don't apply to this CVE):

  1. Lockfile refresh — if Phase 3 found at least one chain that auto-resolves.
    • Command: see matrix.
    • Side effects: lockfile only; no package.json change; full Dependabot visibility preserved.
  2. Bump a maintained intermediate parent — if Phase 4 classified any blocker as (a) or found a newer parent version that admits the patch.
    • Command: bump the declared range of whatever pins that parent (often the user's own package.json).
    • Side effects: package.json minor diff; may need to review the parent's changelog.
  3. Switch to an alternative package — only if the blocker is (d) + a well-known drop-in exists. Phrase as a significant codebase change; do not propose command-level automation for this.
  4. Package-manager override (last resort) — only if all chains have hard blockers and none of options 1–3 apply or are acceptable.
    • Command: see matrix.
    • Ask explicitly: "This will add an override that hides the issue from Dependabot/Renovate on future scans. Upstream blocker: <link>. Do you want to proceed? (yes/no)"
    • Do not proceed without an explicit affirmative.

After presenting, ask: "Which option do you want to apply?" and wait.

Phase 6 — Apply the chosen option

  1. Run the PM-specific command(s) for the chosen option.
  2. Verify the fix: re-grep the lockfile for every installed version of the vulnerable package, and assert each is outside every vulnerable_version_range from Phase 0.
  3. Print a before/after table.
  4. Suggest a commit message following conventional commits:
    • Option 1 (lockfile only): fix(deps): bump <pkg> to patched versions (<CVE-ID>)
    • Option 2 (parent bump): fix(deps): bump <parent> to pick up patched <pkg> (<CVE-ID>)
    • Option 4 (override): fix(deps): override <pkg> to patched versions (<CVE-ID>)
  5. Do not create the branch, commit, or push. Leave that to the user.

Package-manager command matrix

All commands assume the CWD is the project root.

Conceptpnpmnpmyarn (classic)yarn (berry)bun
Why is <pkg> installedpnpm why <pkg>npm ls <pkg> --allyarn why <pkg>yarn why <pkg>bun pm why <pkg>
Update <pkg> within rangespnpm update --depth Infinity <pkg> (add -r for workspaces)npm update <pkg>yarn upgrade <pkg>yarn up <pkg>bun update <pkg>
Package metadatapnpm view <pkg>npm view <pkg>yarn info <pkg>yarn npm info <pkg>bun pm view <pkg> (fallback: npm view <pkg>)
Latest versionpnpm view <pkg> versionnpm view <pkg> versionyarn info <pkg> versionyarn npm info <pkg> --jsonbun pm view <pkg> version
Override block in package.json"pnpm": { "overrides": { "<pkg>": "<range>" } }"overrides": { "<pkg>": "<range>" }"resolutions": { "<pkg>": "<range>" }"resolutions": { "<pkg>": "<range>" }"overrides": { "<pkg>": "<range>" }
Apply overridepnpm installnpm installyarn installyarn installbun install
Override syntax notes
  • pnpm supports per-major overrides via "<pkg>@<major>": "<range>" (e.g. "lodash@4": ">=4.17.21"). Use this when multiple majors are installed and only some are vulnerable.
  • npm supports nested overrides ("<parent>": { "<pkg>": "<range>" }). Prefer the flat form unless you need surgical scope.
  • yarn resolutions support glob patterns ("**/<pkg>": "<range>") — useful for workspace-wide application.

Final checklist

Before reporting success:

  • Every installed version of the vulnerable package is outside every vulnerable_version_range.
  • If an override was used, the override is scoped to the minimum range required (not a global pin).
  • A commit message is suggested but not executed.
  • The Dependabot alert URL is referenced in the suggested commit body for traceability.

© getlago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in .agents/skills/cve-doctor of getlago/lago-front.

  • SKILL.md
  • LICENSE
  • README.md

Open the folder on GitHubat commit c3f9715

Compare with similar skills

Cve Doctor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cve Doctor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cve Doctor this skillgetlago/lago-front163—~2.9kAutomated safety check: PassMIT
Warp Vulnerability Triagewarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0
Security Vulnerabilities Patcheraxelixlabs/axelix148—~4.2kAutomated safety check: PassLGPL-3.0
Clawsec ScannerLeoYeAI/openclaw-master-skills2.2k—~4.1kAutomated safety check: PassMIT
Fix Dependabotowid/etl159—~2.8kAutomated safety check: PassMIT
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT

Similar skills

  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed
  • Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…

    148 GitHub stars~4.2k tokensUpdated today
    SecurityAuto-check passed
  • Clawsec Scanner

    LeoYeAI/openclaw-master-skills

    Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~4.1k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Resolve Dependabot security alerts on owid/etl by upgrading vulnerable dependencies.

    159 GitHub stars~2.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated today
    SecurityAuto-check passed

More from getlago/lago-front

All 17 skills in this repo
  • Babysit

    getlago/lago-front

    A skill your agent uses when asked to babysit, monitor, shepherd, or keep working on a GitHub pull request until it is green, review-ready, approved, mergeable, or ready to merge.

    163 GitHub stars~5.2k tokensUpdated today
    Auto-check passed
  • Extract Section To Drawer

    getlago/lago-front

    Extract a Formik form section into a TanStack Form drawer with Zod validation, following the plan form migration pattern.

    163 GitHub stars~4k tokensUpdated today
    Auto-check: notes
  • Loop Build

    getlago/lago-front

    Phase 2 of the loop pipeline for lago-front. An agent skill from getlago/lago-front.

    163 GitHub stars~3.5k tokensUpdated today
    Auto-check: notes
  • Loop Clean

    getlago/lago-front

    Cleanup phase of the loop pipeline for lago-front, for the worktree layout only.

    163 GitHub stars~816 tokensUpdated today
    Auto-check passed
  • Docker Expert

    getlago/lago-front

    You are an advanced Docker containerization expert with comprehensive, practical knowledge of container optimization, security hardening, multi-stage builds, orchestration patterns, and production…

    163 GitHub starsUsed in 10 repos~3.6k tokens
    Auto-check passed
  • Loop Flywheel

    getlago/lago-front

    Harvest phase of the loop pipeline for lago-front. An agent skill from getlago/lago-front.

    163 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Cve Doctor

What does Cve Doctor do?

Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix. Cve Doctor is an agent skill from getlago/lago-front. Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix.

When should I use Cve Doctor?

Cve Doctor fits situations like: the user asks to fix a CVE; references a Dependabot alert URL (github.com//security/dependabot/); mentions a CVE-YYYY-NNNN; GHSA- identifier.

How do I install Cve Doctor in Claude Code?

Run `npx skills add getlago/lago-front --skill cve-doctor -a claude-code`. Or copy the skill folder (.agents/skills/cve-doctor in getlago/lago-front) into .claude/skills/cve-doctor in your project. Claude Code loads it when a task matches its description.

How do I install Cve Doctor in Codex?

Run `npx skills add getlago/lago-front --skill cve-doctor -a codex`. Or copy the skill folder (.agents/skills/cve-doctor in getlago/lago-front) into .agents/skills/cve-doctor in your project. Codex loads it when a task matches its description.

Can I use Cve Doctor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add getlago/lago-front --skill cve-doctor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cve-doctor, .gemini/skills/cve-doctor, .github/skills/cve-doctor and .opencode/skills/cve-doctor in your project.

What does Cve Doctor need to run?

Going by SKILL.md and its folder, Cve Doctor needs the command-line tools its instructions call (yarn, gh, npm, pnpm and bun). Our summary lists: Node.js.

Does Cve Doctor access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Cve Doctor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cve Doctor use?

Cve Doctor is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cve Doctor use?

About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cve Doctor?

Skills that share tags, products or a category with Cve Doctor: Warp Vulnerability Triage (warpdotdev/warp, 65k stars), Security Vulnerabilities Patcher (axelixlabs/axelix, 148 stars), Clawsec Scanner (LeoYeAI/openclaw-master-skills, 2.2k stars) and Fix Dependabot (owid/etl, 159 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cve Doctor?

getlago (a GitHub organization) maintains it in getlago/lago-front, which has 163 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 11, 2026.

Source: getlago/lago-front on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.