Agent skill

Vulnerability Management

by Hack23 in Hack23/cia

Systematic vulnerability lifecycle management with SLAs: Critical 7d, High 30d, Medium 90d, Low 180d aligned with OWASP, NIST, CIS Controls

Apache-2.0Auto-check passedSecurity

Install Vulnerability Management

skills CLI
$ npx skills add Hack23/cia --skill vulnerability-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia vulnerability-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/vulnerability-management .claude/skills/vulnerability-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vulnerability-management
GitHub stars
239
Token cost
~6.2k tokens
SKILL.md length
634 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Systematic vulnerability lifecycle management with SLAs: Critical 7d, High 30d, Medium 90d, Low 180d aligned with OWASP, NIST, CIS Controls

  • Works in 5 steps: Discovery → Assessment → Remediation → …
  • Tasks that involve Vulnerability scanning
  • SKILL.md covers Purpose, When to Use This Skill, Decision Tree and CVSS v3.1 Severity…, plus 7 more sections
  • Calls mvn, git and gh; reaches github.com and nvd.nist.gov; needs NVD_API_KEY

What it does

Vulnerability Management is an agent skill from Hack23/cia. Systematic vulnerability lifecycle management with SLAs: Critical 7d, High 30d, Medium 90d, Low 180d aligned with OWASP, NIST, CIS Controls

Its SKILL.md is about 6.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning and Web application vulnerabilities. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Vulnerability scanning
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/vulnerability-management”

Requirements

  • Python 3
  • Docker

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Discovery
  2. Assessment
  3. Remediation
  4. Verification
  5. Closure

What it can do on your machine

Read from SKILL.md and the folder at commit bbed538. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • mvn
    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • nvd.nist.gov
    • spring.io

    Also links to:

    • owasp.org
    • docs.github.com
    • cwe.mitre.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NVD_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vulnerability Management loads about 6.2k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 634 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit bbed538, republished under its Apache-2.0 licence (© Hack23). 634 words, ~6,236 tokens.

Download SKILL.mdSave it as .claude/skills/vulnerability-management/SKILL.md (or your agent's skills folder).
name
vulnerability-management
description
Systematic vulnerability lifecycle management with SLAs: Critical 7d, High 30d, Medium 90d, Low 180d aligned with OWASP, NIST, CIS Controls
license
Apache-2.0

Vulnerability Management Skill

Purpose

This skill provides systematic procedures for proactive vulnerability discovery, intelligent remediation, and transparent security communication across the CIA platform. It implements Hack23's bleeding-edge dependency management strategy with automated testing, security validation, and measurable outcomes aligned with business impact.

When to Use This Skill

Apply this skill when:

  • ✅ Analyzing Dependabot pull requests for dependency updates
  • ✅ Responding to GitHub Security Advisories or CodeQL alerts
  • ✅ Triaging OWASP Dependency Check findings
  • ✅ Prioritizing vulnerability remediation across repositories
  • ✅ Managing SLA compliance for vulnerability fixes
  • ✅ Conducting security audits or compliance assessments
  • ✅ Implementing security patches for critical vulnerabilities
  • ✅ Tracking end-of-life (EOL) dependencies and runtimes

Do NOT use for:

  • ❌ General code quality issues (use code-quality-checks skill)
  • ❌ Feature development (different concern)
  • ❌ Performance optimization (use performance-engineer agent)

Decision Tree

mermaid
%%{
  init: {
    'theme': 'base',
    'themeVariables': {
      'primaryColor': '#D32F2F',
      'primaryTextColor': '#fff',
      'lineColor': '#D32F2F',
      'secondaryColor': '#FF9800',
      'tertiaryColor': '#4CAF50'
    }
  }
}%%
flowchart TD
    START["🔍 Vulnerability Detected"] --> SOURCE{"📊 Detection Source?"}
    
    SOURCE -->|Dependabot| DEPEND["📦 Dependency Vulnerability"]
    SOURCE -->|CodeQL| CODE["💻 Code Vulnerability"]
    SOURCE -->|OWASP| OWASP["🔍 Dependency Check Finding"]
    SOURCE -->|Security Advisory| ADVISORY["🚨 GitHub Advisory"]
    
    DEPEND --> CVSS{"🎯 CVSS Score?"}
    CODE --> CVSS
    OWASP --> CVSS
    ADVISORY --> CVSS
    
    CVSS -->|9.0-10.0| CRITICAL["🔴 Critical<br/>SLA: 7 days"]
    CVSS -->|7.0-8.9| HIGH["🟠 High<br/>SLA: 30 days"]
    CVSS -->|4.0-6.9| MEDIUM["🟡 Medium<br/>SLA: 90 days"]
    CVSS -->|0.1-3.9| LOW["🟢 Low<br/>SLA: 180 days"]
    
    CRITICAL --> EXPLOIT{"🎯 Exploited in Wild?"}
    HIGH --> IMPACT{"💼 Business Impact?"}
    MEDIUM --> CONTEXT{"🔍 Contextual Risk?"}
    LOW --> SCHEDULE["📅 Schedule Remediation"]
    
    EXPLOIT -->|YES| IMMEDIATE["⚡ Immediate Action<br/>4 hours target"]
    EXPLOIT -->|NO| VERIFY["✅ Verify Exploitability"]
    
    IMPACT -->|Significant| PRIORITY["🔴 High Priority"]
    IMPACT -->|Limited| STANDARD["🟡 Standard Priority"]
    
    CONTEXT -->|Reachable| ASSESS["🔍 Risk Assessment"]
    CONTEXT -->|Unreachable| BACKLOG["📋 Backlog"]
    
    IMMEDIATE --> REMEDIATE["🔧 Apply Remediation"]
    VERIFY --> REMEDIATE
    PRIORITY --> REMEDIATE
    STANDARD --> REMEDIATE
    ASSESS --> REMEDIATE
    SCHEDULE --> REMEDIATE
    BACKLOG --> MONITOR["👁️ Monitor for Changes"]
    
    REMEDIATE --> TEST["🧪 Test & Validate"]
    TEST --> DOCUMENT["📝 Document Resolution"]
    DOCUMENT --> CLOSE["✅ Close Vulnerability"]
    
    style START fill:#2196F3,color:#fff
    style CRITICAL fill:#D32F2F,color:#fff
    style HIGH fill:#FF9800,color:#fff
    style MEDIUM fill:#FFC107,color:#000
    style LOW fill:#4CAF50,color:#fff
    style IMMEDIATE fill:#D32F2F,color:#fff
    style REMEDIATE fill:#1565C0,color:#fff
    style CLOSE fill:#4CAF50,color:#fff

CVSS v3.1 Severity Classification

Severity Scoring Matrix

CVSS v3.1 Base Score Calculation:

SeverityCVSS ScoreBusiness ImpactSLAEscalation
🔴 Critical9.0 - 10.0€10K+ daily loss7 daysCEO immediate
🟠 High7.0 - 8.9€5-10K daily loss30 daysCEO within 1 day
🟡 Medium4.0 - 6.9€1-5K daily loss90 daysWeekly review
🟢 Low0.1 - 3.9<€1K daily loss180 daysMonthly review
CVSS Vector Analysis

Key CVSS Metrics to Evaluate:

yaml
Attack_Vector (AV):
  - Network (N): Remotely exploitable = Higher severity
  - Adjacent (A): Local network required = Medium severity
  - Local (L): Local access required = Lower severity
  - Physical (P): Physical access required = Lowest severity

Attack_Complexity (AC):
  - Low (L): Easy to exploit = Higher severity
  - High (H): Difficult to exploit = Lower severity

Privileges_Required (PR):
  - None (N): No authentication = Highest severity
  - Low (L): Basic user privileges = Medium severity
  - High (H): Admin privileges = Lower severity

User_Interaction (UI):
  - None (N): No user action required = Higher severity
  - Required (R): User must take action = Lower severity

Scope (S):
  - Changed (C): Impacts beyond vulnerable component = Higher severity
  - Unchanged (U): Impact limited to component = Lower severity

Confidentiality_Impact (C):
  - High (H): Total information disclosure = Highest severity
  - Low (L): Limited disclosure = Medium severity
  - None (N): No confidentiality impact = Lowest severity

Integrity_Impact (I):
  - High (H): Complete data modification = Highest severity
  - Low (L): Limited modification = Medium severity
  - None (N): No integrity impact = Lowest severity

Availability_Impact (A):
  - High (H): Complete system unavailability = Highest severity
  - Low (L): Reduced performance = Medium severity
  - None (N): No availability impact = Lowest severity

Example CVSS Vector:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score: 10.0 (Critical)
Interpretation: Remotely exploitable, easy to exploit, no authentication,
               scope change, high impact to confidentiality/integrity/availability

Vulnerability Lifecycle Management

Phase 1: Discovery

Automated Detection Sources:

yaml
GitHub_Dependabot:
  - Frequency: Real-time alerts
  - Coverage: npm, Maven, pip, Docker, GitHub Actions
  - Action: Auto-creates PR with fix
  - Integration: .github/dependabot.yml

GitHub_CodeQL:
  - Frequency: On push, PR, scheduled scan
  - Coverage: Java, JavaScript, Python code vulnerabilities
  - Action: Creates security alert
  - Integration: .github/workflows/codeql.yml

OWASP_Dependency_Check:
  - Frequency: Daily via CI/CD
  - Coverage: All Maven dependencies
  - Action: Fails build if critical found
  - Integration: pom.xml plugin configuration

GitHub_Security_Advisories:
  - Frequency: Real-time notifications
  - Coverage: All dependencies and platforms
  - Action: Email + dashboard alert
  - Integration: Repository settings

SonarCloud:
  - Frequency: On push, PR
  - Coverage: Code quality + security hotspots
  - Action: Quality gate failure
  - Integration: .github/workflows/verify-release.yml

Manual Discovery Methods:

  • Security researcher disclosure (SECURITY.md)
  • Penetration testing findings
  • Third-party security audit
  • Customer vulnerability report
Phase 2: Assessment

Contextual Risk Evaluation:

mermaid
flowchart LR
    VULN["🔍 Vulnerability"] --> CVSS["📊 CVSS Score"]
    VULN --> EXPLOIT["💣 Exploitability"]
    VULN --> ATTACK["🎯 Attack Surface"]
    VULN --> DATA["🔐 Data Exposure"]
    
    CVSS --> RISK["⚖️ Risk Score"]
    EXPLOIT --> RISK
    ATTACK --> RISK
    DATA --> RISK
    
    RISK --> CRITICAL{"🔴 Critical Risk?"}
    RISK --> HIGH{"🟠 High Risk?"}
    RISK --> MEDIUM{"🟡 Medium Risk?"}
    RISK --> LOW{"🟢 Low Risk?"}
    
    CRITICAL --> IMMEDIATE["⚡ Immediate Action"]
    HIGH --> URGENT["🔴 Urgent Action"]
    MEDIUM --> SCHEDULED["📅 Scheduled Action"]
    LOW --> BACKLOG["📋 Backlog"]
    
    style VULN fill:#2196F3,color:#fff
    style RISK fill:#FF9800,color:#fff
    style CRITICAL fill:#D32F2F,color:#fff
    style IMMEDIATE fill:#D32F2F,color:#fff

Assessment Checklist:

  • CVSS Score: Base score from NVD or GitHub Advisory
  • Exploitability: POC available? Exploited in wild?
  • Attack Surface: Is vulnerable component reachable?
  • Data Classification: What data class does component handle?
  • Business Impact: Revenue/operations/reputation impact?
  • Fix Availability: Patch available? Workaround possible?
  • Blast Radius: How many systems affected?
  • Regulatory Impact: GDPR/NIS2/SOC2 implications?
Phase 3: Remediation

Remediation Strategies:

yaml
Patch_Update:
  - Action: Apply vendor security patch
  - Priority: Preferred solution
  - Risk: Low (tested by vendor)
  - Example: "Update Spring Boot 2.7.5 → 2.7.18"

Version_Upgrade:
  - Action: Upgrade to non-vulnerable version
  - Priority: Standard approach
  - Risk: Medium (breaking changes possible)
  - Example: "Upgrade Vaadin 14.x → 23.x"

Configuration_Change:
  - Action: Disable vulnerable feature
  - Priority: Quick mitigation
  - Risk: Low (functionality may be reduced)
  - Example: "Disable XML external entity processing"

Virtual_Patch:
  - Action: WAF rule or network control
  - Priority: Temporary mitigation
  - Risk: Medium (bypass possible)
  - Example: "Block exploit pattern in AWS WAF"

Replace_Component:
  - Action: Switch to alternative library
  - Priority: Last resort
  - Risk: High (significant refactoring)
  - Example: "Replace Log4j with Logback"

Accept_Risk:
  - Action: Document risk acceptance
  - Priority: Only with CEO approval
  - Risk: Varies (requires monitoring)
  - Example: "Low CVSS + unreachable code + no fix available"

Remediation Workflow:

bash
# 1. Create remediation branch
git checkout -b security/CVE-2024-XXXXX-remediation
git pull origin main

# 2. Apply fix (example: dependency update)
# Edit pom.xml or use Maven versions plugin
mvn versions:use-latest-versions -Dincludes=org.springframework:spring-core

# 3. Build and test
mvn clean install
mvn test
mvn verify

# 4. Security validation
mvn dependency-check:check
# Review report: target/dependency-check-report.html

# 5. Commit with security context
git add pom.xml
git commit -m "security: fix CVE-2024-XXXXX in Spring Core

- Update Spring Core 5.3.20 → 5.3.30
- CVSS Score: 9.8 (Critical)
- Vulnerability: Remote Code Execution
- Fixes: https://github.com/advisories/GHSA-xxxx-xxxx-xxxx
- Tested: All unit tests pass, security scan clean

Refs: #1234"

# 6. Push and create PR
git push origin security/CVE-2024-XXXXX-remediation
gh pr create --title "Security: Fix CVE-2024-XXXXX" \
  --body "Fixes critical vulnerability in Spring Core" \
  --label "security,priority:critical"
Phase 4: Verification

Verification Checklist:

markdown
## Security Fix Verification

- [ ] **Vulnerability Resolved:** Confirmed by security scanner
- [ ] **No New Vulnerabilities:** Dependency check clean
- [ ] **Unit Tests Pass:** `mvn test` successful
- [ ] **Integration Tests Pass:** `mvn verify` successful
- [ ] **Security Tests Pass:** CodeQL analysis clean
- [ ] **Performance Impact:** No degradation observed
- [ ] **Compatibility Check:** No breaking changes introduced
- [ ] **Documentation Updated:** CHANGELOG.md updated
- [ ] **Security Advisory Reviewed:** GitHub advisory closed

**Evidence:**
- Dependency Check Report: target/dependency-check-report.html
- CodeQL Scan: Clean (0 alerts)
- Test Coverage: 82% (maintained)
- Build Status: ✅ Success

Automated Verification:

yaml
# .github/workflows/security-verification.yml
name: Security Verification

on:
  pull_request:
    branches: [ main ]
    labels: [ security ]

jobs:
  verify-security-fix:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
      
      - name: Set up JDK 21
        uses: actions/setup-java@8df1039502a15bceb9433410b1a100fbe190c53b # v4.5.0
        with:
          java-version: '21'
          distribution: 'temurin'
      
      - name: Run OWASP Dependency Check
        run: mvn dependency-check:check -P dependency-check
      
      - name: Check for vulnerabilities
        run: |
          if grep -q "Critical" target/dependency-check-report.html; then
            echo "❌ Critical vulnerabilities still present"
            exit 1
          fi
          echo "✅ No critical vulnerabilities detected"
      
      - name: Run security tests
        run: mvn test -Dsecurity.test=true
      
      - name: Upload verification report
        uses: actions/upload-artifact@ea165860e890e4c0d99e2a7e241d52ce9fdf0b90 # v4.5.0
        with:
          name: security-verification-report
          path: target/dependency-check-report.html
Phase 5: Closure

Closure Criteria:

  1. ✅ Fix deployed to production
  2. ✅ Vulnerability scanner confirms resolution
  3. ✅ GitHub Security Advisory dismissed or closed
  4. ✅ Documentation updated (CHANGELOG.md)
  5. ✅ Stakeholders notified
  6. ✅ Lessons learned documented

Closure Documentation:

markdown
# Vulnerability CVE-2024-XXXXX - Closure Report

## Summary
- **Vulnerability ID:** CVE-2024-XXXXX
- **Severity:** Critical (CVSS 9.8)
- **Component:** Spring Core 5.3.20
- **Detected:** 2024-01-15
- **Resolved:** 2024-01-16
- **SLA:** 7 days (Met: 1 day)

## Resolution
- **Action:** Version upgrade
- **Fix:** Spring Core 5.3.20 → 5.3.30
- **PR:** #1234
- **Deployment:** 2024-01-16 14:30 UTC

## Verification
- ✅ OWASP Dependency Check: Clean
- ✅ CodeQL Scan: No alerts
- ✅ Unit Tests: 100% pass
- ✅ Integration Tests: 100% pass
- ✅ Security Regression Tests: Pass

## Lessons Learned
- **Detection:** Dependabot alert received within 2 hours
- **Triage:** Severity confirmed in 30 minutes
- **Fix:** Patch applied in 4 hours
- **Deployment:** Production rollout in 24 hours
- **Improvement:** Consider auto-merge for patch-level security updates

## References
- GitHub Advisory: https://github.com/advisories/GHSA-xxxx-xxxx-xxxx
- NVD Entry: https://nvd.nist.gov/vuln/detail/CVE-2024-XXXXX
- Spring Security Advisory: https://spring.io/security/cve-2024-xxxxx

SLA Tracking and Escalation

SLA Monitoring

Automated SLA Tracking:

yaml
# .github/workflows/vulnerability-sla-monitoring.yml
name: Vulnerability SLA Monitoring

on:
  schedule:
    - cron: '0 9 * * *' # Daily at 9 AM UTC
  workflow_dispatch:

jobs:
  check-sla:
    runs-on: ubuntu-latest
    steps:
      - name: Check Dependabot Alerts
        uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
        with:
          script: |
            const { data: alerts } = await github.rest.dependabot.listAlertsForRepo({
              owner: context.repo.owner,
              repo: context.repo.repo,
              state: 'open'
            });
            
            const now = new Date();
            const criticalSLA = 7 * 24 * 60 * 60 * 1000; // 7 days
            const highSLA = 30 * 24 * 60 * 60 * 1000; // 30 days
            
            let breaches = [];
            
            for (const alert of alerts) {
              const createdAt = new Date(alert.created_at);
              const age = now - createdAt;
              const severity = alert.security_advisory.severity;
              
              if (severity === 'critical' && age > criticalSLA) {
                breaches.push(`CRITICAL SLA BREACH: ${alert.security_advisory.cve_id}`);
              } else if (severity === 'high' && age > highSLA) {
                breaches.push(`HIGH SLA BREACH: ${alert.security_advisory.cve_id}`);
              }
            }
            
            if (breaches.length > 0) {
              core.setFailed(`SLA Breaches Detected:\n${breaches.join('\n')}`);
              // Trigger notification (Slack, email, etc.)
            }
Escalation Procedures

Escalation Matrix:

SeverityAge ThresholdEscalation LevelAction
Critical3 days (42% of SLA)Level 1: Development TeamDaily standup review
Critical5 days (71% of SLA)Level 2: Team LeadRisk assessment required
Critical7 days (100% of SLA)Level 3: CEOException approval needed
High15 days (50% of SLA)Level 1: Development TeamWeekly review
High25 days (83% of SLA)Level 2: Team LeadRemediation plan required
High30 days (100% of SLA)Level 3: CEOException approval needed

Escalation Template:

markdown
# SLA Escalation Notice

**To:** CEO / Security Team Lead
**From:** Automated SLA Monitor
**Date:** 2024-01-15
**Priority:** 🔴 URGENT

## SLA Breach Alert

**Vulnerability:** CVE-2024-XXXXX
**Severity:** Critical (CVSS 9.8)
**Component:** Spring Core 5.3.20
**Age:** 6 days (86% of 7-day SLA)
**Status:** In Progress

## Current Status
- PR #1234 created for remediation
- Blocked on: Integration test failures
- Estimated Resolution: 2024-01-16

## Required Action
- [ ] CEO acknowledgment
- [ ] Risk acceptance or remediation prioritization
- [ ] Resource allocation if needed

## Impact Assessment
- **Exploitability:** High (POC available)
- **Attack Surface:** Internet-facing API
- **Data at Risk:** Customer PII
- **Business Impact:** €15K/day potential loss

## Escalation History
- Day 3: Development team notified
- Day 5: Team lead engaged
- Day 6: CEO escalation (this notice)
Show full SKILL.md (213 more words)Show less

Exception Handling

Risk Acceptance Process

When to Accept Risk:

  • Fix not available from vendor
  • Fix introduces breaking changes requiring major refactoring
  • Vulnerable code path is unreachable
  • Compensating controls adequately mitigate risk
  • Business justification outweighs risk

Risk Acceptance Template:

markdown
# Vulnerability Risk Acceptance

**Date:** 2024-01-15
**Valid Until:** 2024-04-15 (90 days max)
**Approved By:** CEO

## Vulnerability Details
- **CVE ID:** CVE-2024-XXXXX
- **Severity:** Medium (CVSS 5.5)
- **Component:** Apache Commons Text 1.9
- **Description:** Regular expression denial of service

## Risk Assessment
- **Exploitability:** Low (requires specific input pattern)
- **Attack Surface:** Internal admin API only (not public)
- **Data Impact:** None (no data exposure)
- **Business Impact:** Minimal (temporary performance degradation)

## Justification
- Vendor fix not yet available
- Component used only in internal admin tools
- Compensating controls: Input validation + rate limiting
- Monitoring: CloudWatch alarms on API latency

## Compensating Controls
1. ✅ Input validation regex pattern: `^[a-zA-Z0-9_-]{1,50}$`
2. ✅ API rate limiting: 10 requests/minute
3. ✅ Monitoring: CloudWatch alarm on p99 latency >500ms
4. ✅ WAF rule: Block suspicious patterns

## Review Schedule
- **Next Review:** 2024-02-15 (30 days)
- **Re-evaluation Trigger:** Vendor patch release
- **Maximum Duration:** 90 days from approval

## Approval
- **Approver:** James Pether Sörling, CEO
- **Date:** 2024-01-15
- **Signature:** [Digital signature or commit SHA]

**Tracking:** Documented in Risk Register, monitored monthly

Integration with CIA Platform

Dependabot Configuration
yaml
# .github/dependabot.yml
version: 2
updates:
  - package-ecosystem: "maven"
    directory: "/"
    schedule:
      interval: "daily"
    open-pull-requests-limit: 10
    labels:
      - "dependencies"
      - "security"
    reviewers:
      - "hack23"
    commit-message:
      prefix: "security"
      include: "scope"
    
  - package-ecosystem: "github-actions"
    directory: "/"
    schedule:
      interval: "weekly"
    labels:
      - "github-actions"
      - "security"
    commit-message:
      prefix: "ci"
OWASP Dependency Check Configuration
xml
<!-- pom.xml -->
<plugin>
  <groupId>org.owasp</groupId>
  <artifactId>dependency-check-maven</artifactId>
  <version>10.0.4</version>
  <configuration>
    <failBuildOnCVSS>7</failBuildOnCVSS>
    <suppressionFiles>
      <suppressionFile>owasp-suppressions.xml</suppressionFile>
    </suppressionFiles>
    <nvdApiKey>${env.NVD_API_KEY}</nvdApiKey>
  </configuration>
  <executions>
    <execution>
      <goals>
        <goal>check</goal>
      </goals>
    </execution>
  </executions>
</plugin>
CodeQL Configuration
yaml
# .github/workflows/codeql.yml
name: "CodeQL"

on:
  push:
    branches: [ main ]
  pull_request:
    branches: [ main ]
  schedule:
    - cron: '0 6 * * 1' # Weekly Monday 6 AM

jobs:
  analyze:
    name: Analyze
    runs-on: ubuntu-latest
    permissions:
      security-events: write
      actions: read
      contents: read

    steps:
      - name: Checkout repository
        uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

      - name: Initialize CodeQL
        uses: github/codeql-action/init@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # v3.28.0
        with:
          languages: java
          queries: security-extended

      - name: Build
        run: mvn clean compile -DskipTests

      - name: Perform CodeQL Analysis
        uses: github/codeql-action/analyze@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 # v3.28.0

Compliance Mapping

ISO 27001:2022
  • A.8.8 - Management of Technical Vulnerabilities
  • A.5.7 - Threat Intelligence
  • A.8.16 - Monitoring Activities
NIST CSF 2.0
  • DE.CM-8 - Vulnerability scans are performed
  • RS.MA-1 - Incidents are contained
  • PR.DS-6 - Integrity checking mechanisms verify software integrity
CIS Controls v8
  • Control 7 - Continuous Vulnerability Management
  • Control 7.1 - Establish and Maintain Vulnerability Management Process
  • Control 7.2 - Establish and Maintain Remediation Process
  • Control 7.3 - Perform Automated Operating System Patch Management
  • Control 7.4 - Perform Automated Application Patch Management
  • Control 7.5 - Perform Automated Vulnerability Scans
OWASP Top 10 2021
  • A06:2021 - Vulnerable and Outdated Components
  • A08:2021 - Software and Data Integrity Failures

References

Examples from CIA Platform

Successful Vulnerability Remediation

CVE-2023-20863 - Spring Expression DoS (CVSS 7.5)

bash
# 1. Detected by Dependabot
# Alert: https://github.com/Hack23/cia/security/dependabot/123

# 2. Assessment (30 minutes)
# Severity: High
# Component: spring-expression 5.3.25
# Impact: DoS possible via crafted SpEL expression
# Exploitability: Low (requires admin privileges)
# SLA: 30 days

# 3. Remediation (4 hours)
git checkout -b security/spring-expression-dos
mvn versions:set-property -Dproperty=spring.version -DnewVersion=5.3.27
mvn clean install
git commit -m "security: fix CVE-2023-20863 Spring Expression DoS"
git push origin security/spring-expression-dos

# 4. Verification
# - OWASP Dependency Check: Clean
# - All tests pass: 2,847 tests
# - CodeQL: No new alerts

# 5. Deployment
# Merged to main, deployed to production
# Total time: 1 day (well within 30-day SLA)

Appendix: Tools and Resources

Security Scanning Tools
yaml
Tools_Used:
  Dependabot:
    Purpose: Automated dependency updates
    Coverage: Maven, npm, GitHub Actions
    Integration: GitHub native
    Cost: Free for public repos

  OWASP_Dependency_Check:
    Purpose: Known vulnerability detection
    Coverage: Maven dependencies
    Integration: Maven plugin
    Cost: Free

  CodeQL:
    Purpose: Code vulnerability scanning
    Coverage: Java, JavaScript, Python
    Integration: GitHub Actions
    Cost: Free for public repos

  SonarCloud:
    Purpose: Code quality + security hotspots
    Coverage: All source code
    Integration: GitHub Actions
    Cost: Free for public repos

  GitHub_Security_Advisories:
    Purpose: Vulnerability notifications
    Coverage: All dependencies
    Integration: GitHub native
    Cost: Free
Useful Commands
bash
# Check for vulnerabilities in Maven project
mvn dependency-check:check

# Update all dependencies to latest versions
mvn versions:use-latest-versions

# List outdated dependencies
mvn versions:display-dependency-updates

# Generate dependency tree
mvn dependency:tree

# Check for dependency conflicts
mvn dependency:analyze

# Run security-focused tests
mvn test -Dsecurity.test=true

# Generate SBOM (Software Bill of Materials)
mvn cyclonedx:makeAggregateBom

Document Maintenance:

  • Review Frequency: Quarterly
  • Last Updated: 2024-01-15
  • Next Review: 2024-04-15
  • Owner: Security Team / CIA Project Maintainers

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/vulnerability-management of Hack23/cia.

Open the folder on GitHubat commit bbed538

Compare with similar skills

Vulnerability Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vulnerability Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vulnerability Management this skillHack23/cia239—~6.2kAutomated safety check: PassApache-2.0
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Octopus Security Auditnyldn/claude-octopus4.2k1 repos~2.3kAutomated safety check: PassMIT
Security Verification Gatefengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT

Similar skills

  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Octopus Security Audit

    nyldn/claude-octopus

    OWASP compliance, vulnerability scanning, and adversarial red team testing — use for security reviews

    4.2k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check passed
  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 22 days ago
    SecurityAuto-check: notes
  • Secknowledge Skill

    Pa55w0rd/secknowledge-skill

    Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

    423 GitHub stars~2.7k tokensUpdated 3 mo ago
    SecurityAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Categories

Questions about Vulnerability Management

What does Vulnerability Management do?

Systematic vulnerability lifecycle management with SLAs: Critical 7d, High 30d, Medium 90d, Low 180d aligned with OWASP, NIST, CIS Controls. Vulnerability Management is an agent skill from Hack23/cia.

When should I use Vulnerability Management?

Vulnerability Management fits situations like: tasks that involve Vulnerability scanning; tasks that involve Web application vulnerabilities.

How do I install Vulnerability Management in Claude Code?

Run `npx skills add Hack23/cia --skill vulnerability-management -a claude-code`. Or copy the skill folder (.github/skills/vulnerability-management in Hack23/cia) into .claude/skills/vulnerability-management in your project. Claude Code loads it when a task matches its description.

How do I install Vulnerability Management in Codex?

Run `npx skills add Hack23/cia --skill vulnerability-management -a codex`. Or copy the skill folder (.github/skills/vulnerability-management in Hack23/cia) into .agents/skills/vulnerability-management in your project. Codex loads it when a task matches its description.

Can I use Vulnerability Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill vulnerability-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vulnerability-management, .gemini/skills/vulnerability-management, .github/skills/vulnerability-management and .opencode/skills/vulnerability-management in your project.

What does Vulnerability Management need to run?

Going by SKILL.md and its folder, Vulnerability Management needs the command-line tools its instructions call (mvn, git and gh) and credentials named NVD_API_KEY. Our summary lists: Python 3; Docker.

Does Vulnerability Management access the network?

SKILL.md names 6 domains. In commands or code: github.com, nvd.nist.gov and spring.io; the agent is likely to contact these when it follows the instructions. As links in the text: owasp.org, docs.github.com and cwe.mitre.org. This is read from the text; nothing was executed.

Is Vulnerability Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vulnerability Management use?

Vulnerability Management is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vulnerability Management use?

About 6.2k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vulnerability Management?

Skills that share tags, products or a category with Vulnerability Management: Security Auditor (eigent-ai/eigent, 15k stars), Code Audit (3stoneBrother/code-audit, 893 stars), Security Audit Scanner (ruvnet/ruflo, 74k stars) and Octopus Security Audit (nyldn/claude-octopus, 4.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vulnerability Management?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 7, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.