Agent skill

Building Vulnerability Scanning Workflow

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure.

Apache-2.0Auto-check passedSecurity

Install Building Vulnerability Scanning Workflow

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-vulnerability-scanning-workflow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills building-vulnerability-scanning-workflow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/building-vulnerability-scanning-workflow .claude/skills/building-vulnerability-scanning-workflow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
building-vulnerability-scanning-workflow
GitHub stars
34k
Token cost
~3.2k tokens
SKILL.md length
503 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure.

  • Works in 6 steps: Define Scan Scope and Scheduling → Process and Prioritize Scan Results → Define Remediation SLAs → …
  • SOC teams need to establish recurring vulnerability assessment processes
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; reaches cisa.gov; needs SCAN_SERVICE_PASSWORD and API_PASSWORD

What it does

Building Vulnerability Scanning Workflow is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure. Use when SOC teams need to establish recurring vulnerability assessment processes, integrate scan results with SIEM alerting, and build remediation tracking dashboards.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Vulnerability scanning and Security operations. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • SOC teams need to establish recurring vulnerability assessment processes
  • Integrate scan results with SIEM alerting
  • Build remediation tracking dashboards

Example prompts

  • “Use the building-vulnerability-scanning-workflow skill to build a structured vulnerability scanning workflow using tools like Nessus, Qualys, and…”
  • “/building-vulnerability-scanning-workflow”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Define Scan Scope and Scheduling
  2. Process and Prioritize Scan Results
  3. Define Remediation SLAs
  4. Integrate with SIEM for Exploitation Detection
  5. Build Remediation Tracking Dashboard
  6. Automate Remediation Ticketing

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • cisa.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SCAN_SERVICE_PASSWORD
    • API_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Building Vulnerability Scanning Workflow loads about 3.2k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 101 tokens; SKILL.md has 503 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~101
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 503 words, ~3,170 tokens.

Download SKILL.mdSave it as .claude/skills/building-vulnerability-scanning-workflow/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
building-vulnerability-scanning-workflow
description
Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure. Use when SOC teams need to establish recurring vulnerability assessment processes, integrate scan results with SIEM alerting, and build remediation tracking dashboards.
domain
cybersecurity
subdomain
soc-operations
tags
soc, vulnerability-scanning, nessus, qualys, openvas, cvss, remediation, patch-management
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
DE.CM-01, DE.AE-02, RS.MA-01, DE.AE-06
mitre_attack
T1595.002, T1190, T1046

Building Vulnerability Scanning Workflow

When to Use

Use this skill when:

  • SOC teams need to establish or improve recurring vulnerability scanning programs
  • Scan results require prioritization beyond raw CVSS scores using asset context and threat intelligence
  • Vulnerability data must be integrated into SIEM for correlation with exploitation attempts
  • Remediation tracking needs formalization with SLA-based dashboards and reporting

Do not use for penetration testing or active exploitation — vulnerability scanning identifies weaknesses, penetration testing validates exploitability.

Prerequisites

  • Vulnerability scanner (Tenable Nessus Professional, Qualys VMDR, or OpenVAS/Greenbone)
  • Asset inventory with criticality classifications (business-critical, standard, development)
  • Network access from scanner to all target segments (agent-based or network scan)
  • SIEM integration for scan result ingestion and correlation
  • Patch management system (WSUS, SCCM, Intune) for remediation tracking

Workflow

Step 1: Define Scan Scope and Scheduling

Create scan policies covering all asset types:

Nessus Scan Configuration (API):

python
import requests

nessus_url = "https://nessus.company.com:8834"
headers = {"X-ApiKeys": f"accessKey={access_key};secretKey={secret_key}"}

# Create scan policy
policy = {
    "uuid": "advanced",
    "settings": {
        "name": "SOC Weekly Infrastructure Scan",
        "description": "Weekly credentialed scan of all server and workstation segments",
        "scanner_id": 1,
        "policy_id": 0,
        "text_targets": "10.0.0.0/16, 172.16.0.0/12",
        "launch": "WEEKLY",
        "starttime": "20240315T020000",
        "rrules": "FREQ=WEEKLY;INTERVAL=1;BYDAY=SA",
        "enabled": True
    },
    "credentials": {
        "add": {
            "Host": {
                "Windows": [{
                    "domain": "company.local",
                    "username": "nessus_svc",
                    "password": "SCAN_SERVICE_PASSWORD",
                    "auth_method": "Password"
                }],
                "SSH": [{
                    "username": "nessus_svc",
                    "private_key": "/path/to/nessus_key",
                    "auth_method": "public key"
                }]
            }
        }
    }
}

response = requests.post(f"{nessus_url}/scans", headers=headers, json=policy,
                         verify=not os.environ.get("SKIP_TLS_VERIFY", "").lower() == "true")  # Set SKIP_TLS_VERIFY=true for self-signed certs in lab environments
scan_id = response.json()["scan"]["id"]
print(f"Scan created: ID {scan_id}")

Qualys VMDR Scan via API:

python
import qualysapi

conn = qualysapi.connect(
    hostname="qualysapi.qualys.com",
    username="api_user",
    password="API_PASSWORD"
)

# Launch vulnerability scan
params = {
    "action": "launch",
    "scan_title": "Weekly_Infrastructure_Scan",
    "ip": "10.0.0.0/16",
    "option_id": "123456",  # Scan profile ID
    "iscanner_name": "Internal_Scanner_01",
    "priority": "0"
}

response = conn.request("/api/2.0/fo/scan/", params)
print(f"Scan launched: {response}")
Step 2: Process and Prioritize Scan Results

Download results and apply risk-based prioritization:

python
import requests
import csv

# Export Nessus results
response = requests.get(
    f"{nessus_url}/scans/{scan_id}/export",
    headers=headers,
    params={"format": "csv"},
    verify=not os.environ.get("SKIP_TLS_VERIFY", "").lower() == "true",  # Set SKIP_TLS_VERIFY=true for self-signed certs in lab environments
)

# Parse and prioritize
vulns = []
reader = csv.DictReader(response.text.splitlines())
for row in reader:
    cvss = float(row.get("CVSS v3.0 Base Score", 0))
    asset_criticality = get_asset_criticality(row["Host"])  # From asset inventory

    # Risk-based priority calculation
    risk_score = cvss * asset_criticality_multiplier(asset_criticality)

    # Boost score if actively exploited (check CISA KEV)
    if row.get("CVE") in cisa_kev_list:
        risk_score *= 1.5

    vulns.append({
        "host": row["Host"],
        "plugin_name": row["Name"],
        "severity": row["Risk"],
        "cvss": cvss,
        "cve": row.get("CVE", "N/A"),
        "risk_score": round(risk_score, 1),
        "asset_criticality": asset_criticality,
        "kev": row.get("CVE") in cisa_kev_list
    })

# Sort by risk score
vulns.sort(key=lambda x: x["risk_score"], reverse=True)

CISA KEV (Known Exploited Vulnerabilities) Check:

python
import requests

kev_response = requests.get(
    "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
)
kev_data = kev_response.json()
cisa_kev_list = {v["cveID"] for v in kev_data["vulnerabilities"]}

# Check if vulnerability is actively exploited
def is_actively_exploited(cve_id):
    return cve_id in cisa_kev_list
Step 3: Define Remediation SLAs

Apply SLA-based remediation timelines:

PriorityCVSS RangeAsset TypeSLAExamples
P1 Critical9.0-10.0 + KEVAll assets24 hoursLog4Shell, EternalBlue on prod servers
P2 High7.0-8.9 or 9.0+ non-KEVBusiness-critical7 daysRCE without known exploit
P3 Medium4.0-6.9Business-critical30 daysAuthenticated privilege escalation
P4 Low0.1-3.9Standard90 daysInformation disclosure, low-impact DoS
P5 Informational0.0DevelopmentNext cycleBest practice findings, config hardening
Step 4: Integrate with SIEM for Exploitation Detection

Correlate vulnerability scan data with SIEM alerts to detect active exploitation:

spl
index=vulnerability sourcetype="nessus:scan"
| eval vuln_key = Host.":".CVE
| join vuln_key type=left [
    search index=ids_ips sourcetype="snort" OR sourcetype="suricata"
    | eval vuln_key = dest_ip.":".cve_id
    | stats count AS exploit_attempts, latest(_time) AS last_exploit_attempt by vuln_key
  ]
| where isnotnull(exploit_attempts)
| eval risk = "CRITICAL — Vulnerability being actively exploited"
| sort - exploit_attempts
| table Host, CVE, plugin_name, cvss_score, exploit_attempts, last_exploit_attempt, risk

Alert when KEV vulnerabilities are detected on critical assets:

spl
index=vulnerability sourcetype="nessus:scan" severity="Critical"
| lookup cisa_kev_lookup.csv cve_id AS CVE OUTPUT kev_status, due_date
| where kev_status="active"
| lookup asset_criticality_lookup.csv ip AS Host OUTPUT criticality
| where criticality IN ("business-critical", "mission-critical")
| table Host, CVE, plugin_name, cvss_score, kev_status, due_date, criticality
Step 5: Build Remediation Tracking Dashboard

Splunk Dashboard for Vulnerability Metrics:

spl
-- Open vulnerabilities by severity
index=vulnerability sourcetype="nessus:scan" status="open"
| stats count by severity
| eval order = case(severity="Critical", 1, severity="High", 2, severity="Medium", 3,
                    severity="Low", 4, 1=1, 5)
| sort order

-- SLA compliance tracking
index=vulnerability sourcetype="nessus:scan" status="open"
| eval sla_days = case(
    severity="Critical", 1,
    severity="High", 7,
    severity="Medium", 30,
    severity="Low", 90
  )
| eval days_open = round((now() - first_detected) / 86400)
| eval sla_status = if(days_open > sla_days, "OVERDUE", "Within SLA")
| stats count by severity, sla_status

-- Remediation trend over 90 days
index=vulnerability sourcetype="nessus:scan"
| eval is_open = if(status="open", 1, 0)
| eval is_closed = if(status="fixed", 1, 0)
| timechart span=1w sum(is_open) AS opened, sum(is_closed) AS remediated
Step 6: Automate Remediation Ticketing

Create tickets automatically for high-priority findings:

python
import requests

servicenow_url = "https://company.service-now.com/api/now/table/incident"
headers = {
    "Content-Type": "application/json",
    "Authorization": f"Bearer {snow_token}"
}

for vuln in vulns:
    if vuln["risk_score"] >= 8.0:
        ticket = {
            "short_description": f"[VULN] {vuln['cve']} — {vuln['plugin_name']} on {vuln['host']}",
            "description": (
                f"Vulnerability: {vuln['plugin_name']}\n"
                f"CVE: {vuln['cve']}\n"
                f"CVSS: {vuln['cvss']}\n"
                f"Host: {vuln['host']}\n"
                f"Asset Criticality: {vuln['asset_criticality']}\n"
                f"CISA KEV: {'YES' if vuln['kev'] else 'NO'}\n"
                f"Risk Score: {vuln['risk_score']}\n"
                f"Remediation SLA: {'24 hours' if vuln['kev'] else '7 days'}"
            ),
            "urgency": "1" if vuln["kev"] else "2",
            "impact": "1" if vuln["asset_criticality"] == "business-critical" else "2",
            "assignment_group": "IT Infrastructure",
            "category": "Vulnerability"
        }
        response = requests.post(servicenow_url, headers=headers, json=ticket)
        print(f"Ticket created: {response.json()['result']['number']}")
Show full SKILL.md (217 more words)Show less

Key Concepts

TermDefinition
CVSSCommon Vulnerability Scoring System — standardized severity rating (0-10) for vulnerabilities
CISA KEVKnown Exploited Vulnerabilities catalog — CISA-maintained list of vulnerabilities with confirmed active exploitation
Credentialed ScanVulnerability scan using authenticated access for deeper detection than network-only scanning
Asset CriticalityBusiness impact classification determining remediation priority (mission-critical, business-critical, standard)
Remediation SLAService Level Agreement defining maximum time allowed to patch vulnerabilities by severity
EPSSExploit Prediction Scoring System — ML-based probability score predicting likelihood of exploitation

Tools & Systems

  • Tenable Nessus / Tenable.io: Enterprise vulnerability scanner with 200,000+ plugin checks and compliance auditing
  • Qualys VMDR: Cloud-based vulnerability management with asset discovery, prioritization, and patching integration
  • OpenVAS (Greenbone): Open-source vulnerability scanner with community-maintained vulnerability feed
  • CISA KEV Catalog: US government maintained list of actively exploited vulnerabilities requiring mandatory remediation
  • Rapid7 InsightVM: Vulnerability management platform with live dashboards and remediation project tracking

Common Scenarios

  • Zero-Day Response: New CVE published — run targeted scan for affected software, cross-reference with KEV and exploit databases
  • Compliance Audit Prep: Generate PCI DSS or HIPAA vulnerability report showing scan coverage and remediation status
  • Post-Patch Verification: Rescan patched systems to confirm vulnerability closure and update tracking dashboard
  • Network Expansion: New subnet added to infrastructure — onboard to scan scope with appropriate policy
  • Third-Party Risk: Scan externally-facing assets to validate vendor patch compliance before integration

Output Format

VULNERABILITY SCAN REPORT — Weekly Summary
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Scan Date:    2024-03-16 02:00 UTC
Scan Scope:   10.0.0.0/16 (1,247 hosts scanned)
Duration:     4h 23m
Coverage:     98.7% (16 hosts unreachable)

Findings:
  Severity     Count    New    CISA KEV
  Critical     23       5      3
  High         187      34     12
  Medium       892      78     0
  Low          1,456    112    0
  Info         3,891    201    0

Top Priority (P1 — 24hr SLA):
  CVE-2024-21762  FortiOS RCE           3 hosts   KEV: YES
  CVE-2024-1709   ConnectWise RCE       1 host    KEV: YES
  CVE-2024-3400   Palo Alto PAN-OS RCE  2 hosts   KEV: YES

SLA Compliance:
  Critical: 82% within SLA (4 overdue)
  High:     91% within SLA (17 overdue)
  Medium:   88% within SLA (107 overdue)

Tickets Created: 39 (ServiceNow)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/building-vulnerability-scanning-workflow of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Building Vulnerability Scanning Workflow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Building Vulnerability Scanning Workflow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Building Vulnerability Scanning Workflow this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Chaitin CLIchaitin/chaitin-cli114—~15kAutomated safety check: NotesGPL-3.0
DefectDojo Vulnerability ManagementAgentSecOps/SecOpsAgentKit220—~2.3kAutomated safety check: PassCustom licence
Soeinfometa/workbuddyskills346—~2.3kAutomated safety check: NotesNone
Cybersecurityohmyjahh/xquads-squads277—~895Automated safety check: PassMIT
Defending Applicationstelagod/code-abyss243—~777Automated safety check: PassMIT

Similar skills

  • Chaitin CLI

    chaitin/chaitin-cli

    A skill your agent uses when running chaitin-cli commands to manage Chaitin security products: SafeLine WAF (site management, IP blocking, ACL, policy rules, attack logs), X-Ray vulnerability…

    114 GitHub stars~15k tokensUpdated 10 days ago
    SecurityAuto-check: notes
  • DefectDojo Vulnerability Management

    AgentSecOps/SecOpsAgentKit

    Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

    220 GitHub stars~2.3k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Soe

    infometa/workbuddyskills

    This skill should be used when the user asks to "analyze security alerts", "parse vulnerability scan report", "analyze vulnerability scan report", "verify CVE fix", "analyze WAF attack log"…

    346 GitHub stars~2.3k tokensUpdated today
    SecurityAuto-check: notes
  • Cybersecurity

    ohmyjahh/xquads-squads

    Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

    277 GitHub stars~895 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Defending Applications

    telagod/code-abyss

    Application security defense knowledge for builders. An agent skill from telagod/code-abyss.

    243 GitHub stars~777 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Official

    Author, validate, test, and deploy YARA-L 2.0 detection rules and evaluate end-to-end detection coverage gaps in Google SecOps.

    21k GitHub stars~4.8k tokensUpdated today
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Building Vulnerability Scanning Workflow

What does Building Vulnerability Scanning Workflow do?

Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure. Building Vulnerability Scanning Workflow is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure.

When should I use Building Vulnerability Scanning Workflow?

Building Vulnerability Scanning Workflow fits situations like: SOC teams need to establish recurring vulnerability assessment processes; integrate scan results with SIEM alerting; build remediation tracking dashboards.

How do I install Building Vulnerability Scanning Workflow in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-vulnerability-scanning-workflow -a claude-code`. Or copy the skill folder (skills/building-vulnerability-scanning-workflow in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/building-vulnerability-scanning-workflow in your project. Claude Code loads it when a task matches its description.

How do I install Building Vulnerability Scanning Workflow in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-vulnerability-scanning-workflow -a codex`. Or copy the skill folder (skills/building-vulnerability-scanning-workflow in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/building-vulnerability-scanning-workflow in your project. Codex loads it when a task matches its description.

Can I use Building Vulnerability Scanning Workflow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-vulnerability-scanning-workflow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/building-vulnerability-scanning-workflow, .gemini/skills/building-vulnerability-scanning-workflow, .github/skills/building-vulnerability-scanning-workflow and .opencode/skills/building-vulnerability-scanning-workflow in your project.

What does Building Vulnerability Scanning Workflow need to run?

Going by SKILL.md and its folder, Building Vulnerability Scanning Workflow needs Python for the scripts in its folder and credentials named SCAN_SERVICE_PASSWORD and API_PASSWORD. Our summary lists: Python 3.

Does Building Vulnerability Scanning Workflow access the network?

SKILL.md names 1 domain. In commands or code: cisa.gov; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Building Vulnerability Scanning Workflow safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Building Vulnerability Scanning Workflow use?

Building Vulnerability Scanning Workflow is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Building Vulnerability Scanning Workflow use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 445 tokens, read only when the agent opens those files.

What are the alternatives to Building Vulnerability Scanning Workflow?

Skills that share tags, products or a category with Building Vulnerability Scanning Workflow: Chaitin CLI (chaitin/chaitin-cli, 114 stars), DefectDojo Vulnerability Management (AgentSecOps/SecOpsAgentKit, 220 stars), Soe (infometa/workbuddyskills, 346 stars) and Cybersecurity (ohmyjahh/xquads-squads, 277 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Building Vulnerability Scanning Workflow?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.