Official agent skill

Ingest Cwe Taxonomies

by microsoft in microsoft/PromptKit

Ingest the official MITRE CWE database and generate per-domain security audit taxonomies for PromptKit.

OfficialMITAuto-check passedSecurity

Install Ingest Cwe Taxonomies

skills CLI
$ npx skills add microsoft/PromptKit --skill ingest-cwe-taxonomies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/PromptKit ingest-cwe-taxonomies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/PromptKit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/ingest-cwe-taxonomies .claude/skills/ingest-cwe-taxonomies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ingest-cwe-taxonomies
GitHub stars
111
Token cost
~356 tokens
SKILL.md length
135 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Ingest the official MITRE CWE database and generate per-domain security audit taxonomies for PromptKit.

  • Works in 4 steps: Read… → Ask the user for the CWE source (path or… → Follow all six phases defined in the… → …
  • The user wants to update CWE taxonomies
  • SKILL.md covers Inputs, Output and Workflow
  • Reaches cwe.mitre.org

What it does

Ingest Cwe Taxonomies is an agent skill from microsoft/PromptKit, published by the product's own GitHub organization. Ingest the official MITRE CWE database and generate per-domain security audit taxonomies for PromptKit. Use this skill when the user wants to update CWE taxonomies, ingest a new CWE version, or regenerate domain mappings from the CWE corpus.

Its SKILL.md is about 360 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review and Prompt engineering. The repository describes itself as: Agentic prompts are the most important code you're not engineering. PromptKit fixes that — composable, version-controlled prompt components (personas, protocols, formats… The licence is MIT.

When your agent uses it

  • The user wants to update CWE taxonomies
  • Ingest a new CWE version
  • Regenerate domain mappings from the CWE corpus

Example prompts

  • “/ingest-cwe-taxonomies”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Read .github/prompts/ingest-cwe-taxonomies.prompt.md before doing
  2. Ask the user for the CWE source (path or latest).
  3. Follow all six phases defined in the prompt file: Acquisition,
  4. Do NOT skip the sanity checks in Phase 6.

What it can do on your machine

Read from SKILL.md and the folder at commit 074dc8d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • cwe.mitre.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ingest Cwe Taxonomies loads about 356 tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 135 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~356

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/PromptKit at commit 074dc8d, republished under its MIT licence (© microsoft). 135 words, ~356 tokens.

Download SKILL.mdSave it as .claude/skills/ingest-cwe-taxonomies/SKILL.md (or your agent's skills folder).
name
ingest-cwe-taxonomies
description
Ingest the official MITRE CWE database and generate per-domain security audit taxonomies for PromptKit. Use this skill when the user wants to update CWE taxonomies, ingest a new CWE version, or regenerate domain mappings from the CWE corpus.
<!-- Generated by PromptKit — edit with care -->

You must read and execute the prompt file at .github/prompts/ingest-cwe-taxonomies.prompt.md. Treat it as the complete, self-contained instruction set for the CWE ingestion pipeline.

Inputs

  • CWE source: A local path to a CWE XML file, or latest to download the current release from https://cwe.mitre.org/data/xml/cwec_latest.xml.zip.
  • Any overrides to the domain registry or mapping rules the user specifies.

Output

  • Per-domain taxonomy files at taxonomies/cwe-<domain>.md (13 domains)
  • Normalized CWE data at data/cwe/<version>/
  • Updated manifest.yaml with new taxonomy entries
  • Reusable ingestion script at scripts/ingest-cwe.py
  • Diff report if a previous CWE version exists

Workflow

  1. Read .github/prompts/ingest-cwe-taxonomies.prompt.md before doing anything else.
  2. Ask the user for the CWE source (path or latest).
  3. Follow all six phases defined in the prompt file: Acquisition, Normalization, Domain Mapping, Taxonomy Generation, Integration, and Verification.
  4. Do NOT skip the sanity checks in Phase 6.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/ingest-cwe-taxonomies of microsoft/PromptKit.

Open the folder on GitHubat commit 074dc8d

Compare with similar skills

Ingest Cwe Taxonomies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ingest Cwe Taxonomies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ingest Cwe Taxonomies this skillmicrosoft/PromptKit111—~356Automated safety check: PassMIT
LLM Securitysickn33/agentic-awesome-skills47k1 repos~1.2kAutomated safety check: WarnMIT
Common LLM SecurityHoangNguyen0403/agent-skills-standard572—~921Automated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT

Similar skills

  • LLM Security

    sickn33/agentic-awesome-skills

    Authorized security assessment of LLM applications and AI agents: prompt injection, tool abuse, RAG exposure, memory poisoning, system-prompt extraction, and agent-compliance engineering per OWASP…

    47k GitHub starsUsed in 1 repo~1.2k tokens
    SecurityAuto-check: warnings
  • Common LLM Security

    HoangNguyen0403/agent-skills-standard

    OWASP LLM Top 10 (2025) audit checklist for AI applications, agent tools, RAG pipelines, and prompt construction.

    572 GitHub stars~921 tokensUpdated yesterday
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.5k GitHub stars~3.7k tokensUpdated yesterday
    SecurityAuto-check: notes

More from microsoft/PromptKit

  • Respond To PR Comments

    microsoft/PromptKit

    Official

    Respond to pull request review comments on GitHub or Azure DevOps Services.

    111 GitHub stars~4.2k tokensUpdated 22 days ago
    Auto-check passed
  • Promptkit

    microsoft/PromptKit

    Official

    PromptKit composition engine. An agent skill from microsoft/PromptKit.

    111 GitHub stars~420 tokensUpdated 22 days ago
    Auto-check passed

Categories

Questions about Ingest Cwe Taxonomies

What does Ingest Cwe Taxonomies do?

Ingest the official MITRE CWE database and generate per-domain security audit taxonomies for PromptKit. Ingest Cwe Taxonomies is an agent skill from microsoft/PromptKit, published by the product's own GitHub organization. Ingest the official MITRE CWE database and generate per-domain security audit taxonomies for PromptKit.

When should I use Ingest Cwe Taxonomies?

Ingest Cwe Taxonomies fits situations like: the user wants to update CWE taxonomies; ingest a new CWE version; regenerate domain mappings from the CWE corpus.

How do I install Ingest Cwe Taxonomies in Claude Code?

Run `npx skills add microsoft/PromptKit --skill ingest-cwe-taxonomies -a claude-code`. Or copy the skill folder (.github/skills/ingest-cwe-taxonomies in microsoft/PromptKit) into .claude/skills/ingest-cwe-taxonomies in your project. Claude Code loads it when a task matches its description.

How do I install Ingest Cwe Taxonomies in Codex?

Run `npx skills add microsoft/PromptKit --skill ingest-cwe-taxonomies -a codex`. Or copy the skill folder (.github/skills/ingest-cwe-taxonomies in microsoft/PromptKit) into .agents/skills/ingest-cwe-taxonomies in your project. Codex loads it when a task matches its description.

Can I use Ingest Cwe Taxonomies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/PromptKit --skill ingest-cwe-taxonomies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ingest-cwe-taxonomies, .gemini/skills/ingest-cwe-taxonomies, .github/skills/ingest-cwe-taxonomies and .opencode/skills/ingest-cwe-taxonomies in your project.

What does Ingest Cwe Taxonomies need to run?

SKILL.md names no scripts, command-line tools or credentials: Ingest Cwe Taxonomies is instructions for the agent only.

Does Ingest Cwe Taxonomies access the network?

SKILL.md names 1 domain. In commands or code: cwe.mitre.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Ingest Cwe Taxonomies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ingest Cwe Taxonomies use?

Ingest Cwe Taxonomies is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ingest Cwe Taxonomies use?

About 356 tokens (SKILL.md is roughly 1.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ingest Cwe Taxonomies?

Skills that share tags, products or a category with Ingest Cwe Taxonomies: LLM Security (sickn33/agentic-awesome-skills, 47k stars), Common LLM Security (HoangNguyen0403/agent-skills-standard, 572 stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars) and Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ingest Cwe Taxonomies?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/PromptKit, which has 111 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on September 18, 2026.

Source: microsoft/PromptKit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.