Write Cve Rule
evdenis/cvehound
Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.
主机安全CVE漏洞修复验证引擎。从主机漏扫报告(Excel)或CVE编号自动提取漏洞,查询威胁情报(NVD/EPSS/MSRC/OVAL),生成修复脚本(fix.sh/fix.ps1),SSH验证脚本可执行性,产出修复验证报告。覆盖 Linux(centos/ubuntu/debian/suse/amazon/fedora/alpine/arch) + Windows + Web-CMS…
$ npx skills add infometa/workbuddyskills --skill host-cve-validator -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install infometa/workbuddyskills host-cve-validator --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/infometa/workbuddyskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validator .claude/skills/host-cve-validator && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "host-cve-validator" agent skill from https://github.com/infometa/workbuddyskills/tree/main/experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validator into .claude/skills/host-cve-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "host-cve-validator", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/infometa/workbuddyskills/tree/main/experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validatorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add infometa/workbuddyskills --skill host-cve-validator -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install infometa/workbuddyskills host-cve-validator --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/infometa/workbuddyskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validator .agents/skills/host-cve-validator && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "host-cve-validator" agent skill from https://github.com/infometa/workbuddyskills/tree/main/experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validator into .agents/skills/host-cve-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "host-cve-validator", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add infometa/workbuddyskills --skill host-cve-validator -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install infometa/workbuddyskills host-cve-validator --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/infometa/workbuddyskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validator .cursor/skills/host-cve-validator && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "host-cve-validator" agent skill from https://github.com/infometa/workbuddyskills/tree/main/experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validator into .cursor/skills/host-cve-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "host-cve-validator", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/infometa/workbuddyskills.git --path experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validator--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add infometa/workbuddyskills --skill host-cve-validator -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install infometa/workbuddyskills host-cve-validator --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/infometa/workbuddyskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validator .gemini/skills/host-cve-validator && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "host-cve-validator" agent skill from https://github.com/infometa/workbuddyskills/tree/main/experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validator into .gemini/skills/host-cve-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "host-cve-validator", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install infometa/workbuddyskills host-cve-validatorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add infometa/workbuddyskills --skill host-cve-validator -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/infometa/workbuddyskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validator .github/skills/host-cve-validator && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "host-cve-validator" agent skill from https://github.com/infometa/workbuddyskills/tree/main/experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validator into .github/skills/host-cve-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "host-cve-validator", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add infometa/workbuddyskills --skill host-cve-validator -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install infometa/workbuddyskills host-cve-validator --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/infometa/workbuddyskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validator .opencode/skills/host-cve-validator && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "host-cve-validator" agent skill from https://github.com/infometa/workbuddyskills/tree/main/experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validator into .opencode/skills/host-cve-validator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "host-cve-validator", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
host-cve-validator主机安全CVE漏洞修复验证引擎。从主机漏扫报告(Excel)或CVE编号自动提取漏洞,查询威胁情报(NVD/EPSS/MSRC/OVAL),生成修复脚本(fix.sh/fix.ps1),SSH验证脚本可执行性,产出修复验证报告。覆盖 Linux(centos/ubuntu/debian/suse/amazon/fedora/alpine/arch) + Windows + Web-CMS…
Host Cve Validator is an agent skill from infometa/workbuddyskills. 主机安全CVE漏洞修复验证引擎。从主机漏扫报告(Excel)或CVE编号自动提取漏洞,查询威胁情报(NVD/EPSS/MSRC/OVAL),生成修复脚本(fix.sh/fix.ps1),SSH验证脚本可执行性,产出修复验证报告。覆盖 Linux(centos/ubuntu/debian/suse/amazon/fedora/alpine/arch) + Windows + Web-CMS 三类。触发关键词:主机漏扫、CVE验证、漏洞修复验证、host CVE、fix validation。
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 61 other files, including scripts, reference files and assets (for example `README.md`, `assets/PLAN.template.md` and `references/demo-mode.md`).
It sits in Security, covering Vulnerability scanning and Excel spreadsheets. It works with Linux and Microsoft Excel. The repository describes itself as: WorkBuddy skills / connectors / experts archive for offline study.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 75a5ad9. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadFrom allowed-tools in the SKILL.md frontmatter.
Ships 6 files in scripts/ (Python, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
python3jqFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Host Cve Validator loads about 1.8k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 67 tokens; SKILL.md has 315 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, ReadAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
Its licence (Proprietary) doesn't allow us to republish the file, so here is its outline and opening line. It has 315 words (~1,788 tokens).
SKILL.md and 58 other files (scripts, references, assets) in experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validator of infometa/workbuddyskills.
Open the folder on GitHubat commit 75a5ad9
Host Cve Validator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Host Cve Validator this skillinfometa/workbuddyskills | 344 | — | ~1.8k | Automated safety check: Notes | Proprietary | |
| Write Cve Ruleevdenis/cvehound | 138 | — | ~2.5k | Automated safety check: Pass | GPL-3.0 | |
| Security Auditmarketcalls/openalgo | 2.8k | — | ~1.9k | Automated safety check: Pass | AGPL-3.0 | |
| Editaplotliushunqi8-hash/editaplot2026 | 125 | — | ~5.8k | Automated safety check: Pass | Apache-2.0 | |
| Performing Agentless Vulnerability Scanningmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | |
| Performing Authenticated Scan With Openvasmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.3k | Automated safety check: Warn | Apache-2.0 |
evdenis/cvehound
Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.
marketcalls/openalgo
Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report.
liushunqi8-hash/editaplot2026
Analyze local scientific CSV, TXT, XLS, or XLSX data; recommend publication-informed charts and Chinese scientific palettes; freeze a reproducible plan; and automate editable figures through a…
mukul975/Anthropic-Cybersecurity-Skills
Configure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and API-based discovery to assess systems without installing endpoint agents.
mukul975/Anthropic-Cybersecurity-Skills
Configure and execute authenticated (credentialed) vulnerability scans using OpenVAS/Greenbone Vulnerability Management (GVM) with SSH, SMB, or ESXi credentials to detect local vulnerabilities…
LeoYeAI/openclaw-master-skills
Natural language search for local files (100G-1T). An agent skill from LeoYeAI/openclaw-master-skills.
infometa/workbuddyskills
This skill should be used when planning, coordinating, running, or reviewing student-led campus events, including club recruitment, freshman mixers, welcome activities, small talks, competitions…
infometa/workbuddyskills
K-12 interactive courseware creation. An agent skill from infometa/workbuddyskills.
infometa/workbuddyskills
A skill your agent uses when the adult weight-management MCP needs to be installed/set up in WorkBuddy (connector) or its result must be rendered as a standalone Chinese HTML plan.
infometa/workbuddyskills
A skill your agent uses when the user needs browser automation, including opening web pages, taking screenshots, extracting page content, clicking elements, filling forms, or testing web flows.
infometa/workbuddyskills
定时任务:每日研究简报。漏掉重要论文和行业报告?每天帮你盯着,关键信息一条不漏 This skill should be used when the user asks about 定时任务:每日研究简报.
infometa/workbuddyskills
Investment banking presentation quality checker. An agent skill from infometa/workbuddyskills.
Works with
Categories
主机安全CVE漏洞修复验证引擎。从主机漏扫报告(Excel)或CVE编号自动提取漏洞,查询威胁情报(NVD/EPSS/MSRC/OVAL),生成修复脚本(fix.sh/fix.ps1),SSH验证脚本可执行性,产出修复验证报告。覆盖 Linux(centos/ubuntu/debian/suse/amazon/fedora/alpine/arch) + Windows + Web-CMS…. Host Cve Validator is an agent skill from infometa/workbuddyskills.
Host Cve Validator fits situations like: tasks that involve Vulnerability scanning; tasks that involve Excel spreadsheets.
Run `npx skills add infometa/workbuddyskills --skill host-cve-validator -a claude-code`. Or copy the skill folder (experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validator in infometa/workbuddyskills) into .claude/skills/host-cve-validator in your project. Claude Code loads it when a task matches its description.
Run `npx skills add infometa/workbuddyskills --skill host-cve-validator -a codex`. Or copy the skill folder (experts/soe/skills/soe/references/vulnerability-analysis/host-cve-validator in infometa/workbuddyskills) into .agents/skills/host-cve-validator in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add infometa/workbuddyskills --skill host-cve-validator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/host-cve-validator, .gemini/skills/host-cve-validator, .github/skills/host-cve-validator and .opencode/skills/host-cve-validator in your project.
Going by SKILL.md and its folder, Host Cve Validator needs Python for the scripts in its folder and the command-line tools its instructions call (python3 and jq). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Bash, Read.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Host Cve Validator carries a proprietary licence (from the LICENSE file in the skill folder). It is published on GitHub, but it is not open source: read the licence file before using or sharing it.
About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Host Cve Validator: Write Cve Rule (evdenis/cvehound, 138 stars), Security Audit (marketcalls/openalgo, 2.8k stars), Editaplot (liushunqi8-hash/editaplot2026, 125 stars) and Performing Agentless Vulnerability Scanning (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
infometa (a GitHub user) maintains it in infometa/workbuddyskills, which has 344 GitHub stars. The repository holds 212 skills in this directory. The repository was last updated on October 7, 2026.
Source: infometa/workbuddyskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.