Agent skill

Performing Endpoint Vulnerability Remediation

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes.

Apache-2.0Auto-check passedSecurity

Install Performing Endpoint Vulnerability Remediation

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-endpoint-vulnerability-remediation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-endpoint-vulnerability-remediation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-endpoint-vulnerability-remediation .claude/skills/performing-endpoint-vulnerability-remediation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-endpoint-vulnerability-remediation
GitHub stars
34k
Token cost
~2.2k tokens
SKILL.md length
384 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes.

  • Works in 7 steps: Import and Prioritize Vulnerability… → Identify Remediation Actions → Deploy Patches via WSUS/SCCM → …
  • Remediating findings from vulnerability scans
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 2 more sections
  • Runs Python scripts from its folder; reaches msrc.microsoft.com and helpx.adobe.com

What it does

Performing Endpoint Vulnerability Remediation is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes. Use when remediating findings from vulnerability scans, responding to critical CVE advisories, or maintaining endpoint compliance with patch management SLAs. Activates for requests involving vulnerability remediation, CVE patching, endpoint vulnerability management, or security fix deployment.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Vulnerability scanning. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Remediating findings from vulnerability scans
  • Responding to critical CVE advisories
  • Maintaining endpoint compliance with patch management SLAs

Example prompts

  • “Use the performing-endpoint-vulnerability-remediation skill to perform vulnerability remediation on endpoints by prioritizing CVEs based on risk…”
  • “/performing-endpoint-vulnerability-remediation”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Import and Prioritize Vulnerability Findings
  2. Identify Remediation Actions
  3. Deploy Patches via WSUS/SCCM
  4. Apply Configuration-Based Remediations
  5. Handle Zero-Day Vulnerabilities (No Patch Available)
  6. Validate Remediation
  7. Report and Track

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • msrc.microsoft.com
    • helpx.adobe.com

    Also links to:

    • cisa.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Endpoint Vulnerability Remediation loads about 2.2k tokens when it runs, and up to ~4.8k if it reads all its reference files. Until then it costs about 126 tokens; SKILL.md has 384 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~126
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 384 words, ~2,174 tokens.

Download SKILL.mdSave it as .claude/skills/performing-endpoint-vulnerability-remediation/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
performing-endpoint-vulnerability-remediation
description
Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes. Use when remediating findings from vulnerability scans, responding to critical CVE advisories, or maintaining endpoint compliance with patch management SLAs. Activates for requests involving vulnerability remediation, CVE patching, endpoint vulnerability management, or security fix deployment.
domain
cybersecurity
subdomain
endpoint-security
tags
endpoint, vulnerability-management, patching, CVE, remediation, CVSS
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
PR.PS-01, PR.PS-02, DE.CM-01, PR.IR-01
mitre_attack
T1055, T1547, T1059, T1036

Performing Endpoint Vulnerability Remediation

When to Use

Use this skill when:

  • Remediating vulnerabilities identified by scanners (Nessus, Qualys, Rapid7)
  • Responding to zero-day CVE advisories requiring immediate patching
  • Maintaining compliance with patch management SLAs (critical within 14 days, high within 30 days)
  • Building a prioritized remediation plan from vulnerability scan results

Do not use this skill for vulnerability scanning itself (use scanning tools) or for application-layer vulnerability remediation (use DevSecOps processes).

Prerequisites

  • Vulnerability scan results (Nessus, Qualys, or Rapid7 export in CSV/XML format)
  • Patch management platform (WSUS, SCCM, Intune, or third-party like Automox)
  • Administrative access to target endpoints or deployment infrastructure
  • Change management process for production endpoint patching
  • Testing environment for patch validation before production rollout

Workflow

Step 1: Import and Prioritize Vulnerability Findings
Priority scoring combines:
1. CVSS Base Score (0-10)
2. EPSS (Exploit Prediction Scoring System) - probability of exploitation
3. CISA KEV (Known Exploited Vulnerabilities) catalog membership
4. Asset criticality (business impact of affected endpoint)
5. Network exposure (internet-facing vs. internal)

Priority Matrix:
  P1 (Critical - 14 days SLA):
    - CVSS >= 9.0 OR
    - Listed in CISA KEV OR
    - Active exploitation in the wild + CVSS >= 7.0

  P2 (High - 30 days SLA):
    - CVSS 7.0-8.9 AND
    - EPSS > 0.5 (50% probability of exploitation)

  P3 (Medium - 60 days SLA):
    - CVSS 4.0-6.9 OR
    - CVSS 7.0-8.9 with EPSS < 0.1

  P4 (Low - 90 days SLA):
    - CVSS < 4.0 AND
    - No known exploit
Step 2: Identify Remediation Actions

For each vulnerability, determine the appropriate remediation:

Remediation Types:
1. Patch: Apply vendor security update (most common)
2. Configuration change: Modify settings to mitigate (registry, GPO)
3. Upgrade: Update to newer software version
4. Workaround: Apply temporary mitigation when patch unavailable
5. Compensating control: Network segmentation, WAF rule, EDR rule
6. Accept risk: Document accepted risk with CISO sign-off
Step 3: Deploy Patches via WSUS/SCCM
powershell
# WSUS: Approve patches for deployment
# 1. Open WSUS Console
# 2. Navigate to Updates → Security Updates
# 3. Approve selected KBs for target computer groups

# SCCM: Create Software Update Group
# 1. Software Library → Software Updates → All Software Updates
# 2. Select required KBs → Create Software Update Group
# 3. Deploy to target collection with maintenance window

# Intune: Create Windows Update Ring
# Devices → Windows → Update rings
# Configure: Quality updates deferral = 0 days (for critical)
# Feature updates deferral = per policy

# PowerShell: Force Windows Update check
Install-Module PSWindowsUpdate -Force
Get-WindowsUpdate -KBArticleID "KB5034441" -Install -AcceptAll -AutoReboot

# Verify patch installation
Get-HotFix -Id "KB5034441"
systeminfo | findstr "KB5034441"
Step 4: Apply Configuration-Based Remediations
powershell
# Example: Disable SMBv1 (CVE-2017-0144 - EternalBlue)
Set-SmbServerConfiguration -EnableSMB1Protocol $false -Force
Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol -NoRestart

# Example: Disable Print Spooler on non-print servers (CVE-2021-34527 - PrintNightmare)
Stop-Service -Name Spooler -Force
Set-Service -Name Spooler -StartupType Disabled

# Example: Disable LLMNR (credential theft mitigation)
# Via GPO: Computer Configuration → Admin Templates → Network → DNS Client
# Turn off multicast name resolution: Enabled
New-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient" `
  -Name EnableMulticast -Value 0 -PropertyType DWORD -Force

# Example: Restrict NTLM authentication
# Via GPO: Security Settings → Local Policies → Security Options
# Network security: Restrict NTLM: Audit/Deny
Step 5: Handle Zero-Day Vulnerabilities (No Patch Available)
When vendor patch is not yet available:

1. Check vendor advisory for workarounds
   - Microsoft: https://msrc.microsoft.com/update-guide
   - Adobe: https://helpx.adobe.com/security.html
   - Linux: Distribution security trackers

2. Apply temporary mitigations:
   - Disable vulnerable feature/service
   - Deploy EDR detection rule for exploitation attempt
   - Apply network-level blocking (WAF/firewall rules)
   - Restrict access to vulnerable application

3. Monitor for patch release:
   - Subscribe to vendor security mailing list
   - Monitor CISA KEV additions
   - Set calendar reminder for next Patch Tuesday

4. Document workaround with expiration date
Step 6: Validate Remediation
powershell
# Re-scan remediated endpoints to confirm vulnerability closure
# Option 1: Targeted vulnerability scan
nessuscli scan --target 192.168.1.0/24 --plugin-id 12345

# Option 2: PowerShell verification
# Check specific KB is installed
$kb = Get-HotFix -Id "KB5034441" -ErrorAction SilentlyContinue
if ($kb) {
    Write-Host "PASS: KB5034441 installed on $(hostname)" -ForegroundColor Green
} else {
    Write-Host "FAIL: KB5034441 missing on $(hostname)" -ForegroundColor Red
}

# Check service is disabled
$svc = Get-Service -Name Spooler
if ($svc.StartType -eq 'Disabled') {
    Write-Host "PASS: Print Spooler disabled" -ForegroundColor Green
}

# Check registry configuration
$val = Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" `
  -Name SMB1 -ErrorAction SilentlyContinue
if ($val.SMB1 -eq 0) {
    Write-Host "PASS: SMBv1 disabled" -ForegroundColor Green
}
Step 7: Report and Track

Generate remediation status report:

Remediation Metrics:
  - Total vulnerabilities: X
  - Remediated: Y (Z%)
  - Pending (within SLA): A
  - Overdue (past SLA): B
  - Accepted risk: C
  - Mean time to remediate (MTTR): D days
  - SLA compliance rate: E%

Key Concepts

TermDefinition
CVSSCommon Vulnerability Scoring System; 0-10 severity scale for vulnerabilities
EPSSExploit Prediction Scoring System; probability (0-1) that a CVE will be exploited in the wild within 30 days
CISA KEVCISA Known Exploited Vulnerabilities catalog; federal mandate to patch these CVEs within specified timeframes
SLAService Level Agreement for remediation timelines based on vulnerability severity
MTTRMean Time To Remediate; average days from vulnerability discovery to confirmed fix
Compensating ControlAlternative security measure when direct remediation is not feasible
Show full SKILL.md (133 more words)Show less

Tools & Systems

  • Nessus/Tenable.io: Vulnerability scanning and remediation tracking
  • Qualys VMDR: Vulnerability management, detection, and response platform
  • Rapid7 InsightVM: Vulnerability assessment with live dashboards
  • WSUS/SCCM/Intune: Microsoft patch deployment infrastructure
  • Automox: Cloud-native patch management for Windows, macOS, Linux
  • CISA KEV Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Common Pitfalls

  • Patching without testing: Apply patches to a test group first. Some patches cause application compatibility issues or BSOD.
  • Ignoring EPSS scores: A CVSS 9.8 vulnerability with EPSS 0.01 may be less urgent than a CVSS 7.5 with EPSS 0.95 (actively exploited).
  • Not validating remediation: Deploying a patch does not guarantee installation. Always re-scan to confirm closure.
  • Excluding critical servers from patching: Servers that "cannot be rebooted" accumulate critical vulnerabilities. Schedule maintenance windows.
  • Treating all CVEs equally: Risk-based prioritization (CVSS + EPSS + asset criticality + exposure) is more effective than patching all criticals first.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/performing-endpoint-vulnerability-remediation of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Endpoint Vulnerability Remediation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Endpoint Vulnerability Remediation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Endpoint Vulnerability Remediation this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT
Cve Remediationrundeck/rundeck6.3k—~2.9kAutomated safety check: PassApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Cve Remediation

    rundeck/rundeck

    Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    190 GitHub stars~2.5k tokensUpdated 13 days ago
    SecurityAuto-check: notes
  • Write Cve Rule

    evdenis/cvehound

    Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.

    138 GitHub stars~2.5k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Performing Endpoint Vulnerability Remediation

What does Performing Endpoint Vulnerability Remediation do?

Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes. Performing Endpoint Vulnerability Remediation is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches, applying configuration changes, and validating fixes.

When should I use Performing Endpoint Vulnerability Remediation?

Performing Endpoint Vulnerability Remediation fits situations like: remediating findings from vulnerability scans; responding to critical CVE advisories; maintaining endpoint compliance with patch management SLAs.

How do I install Performing Endpoint Vulnerability Remediation in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-endpoint-vulnerability-remediation -a claude-code`. Or copy the skill folder (skills/performing-endpoint-vulnerability-remediation in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-endpoint-vulnerability-remediation in your project. Claude Code loads it when a task matches its description.

How do I install Performing Endpoint Vulnerability Remediation in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-endpoint-vulnerability-remediation -a codex`. Or copy the skill folder (skills/performing-endpoint-vulnerability-remediation in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-endpoint-vulnerability-remediation in your project. Codex loads it when a task matches its description.

Can I use Performing Endpoint Vulnerability Remediation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-endpoint-vulnerability-remediation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-endpoint-vulnerability-remediation, .gemini/skills/performing-endpoint-vulnerability-remediation, .github/skills/performing-endpoint-vulnerability-remediation and .opencode/skills/performing-endpoint-vulnerability-remediation in your project.

What does Performing Endpoint Vulnerability Remediation need to run?

Going by SKILL.md and its folder, Performing Endpoint Vulnerability Remediation needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Performing Endpoint Vulnerability Remediation access the network?

SKILL.md names 3 domains. In commands or code: msrc.microsoft.com and helpx.adobe.com; the agent is likely to contact these when it follows the instructions. As links in the text: cisa.gov. This is read from the text; nothing was executed.

Is Performing Endpoint Vulnerability Remediation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Endpoint Vulnerability Remediation use?

Performing Endpoint Vulnerability Remediation is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Endpoint Vulnerability Remediation use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.

What are the alternatives to Performing Endpoint Vulnerability Remediation?

Skills that share tags, products or a category with Performing Endpoint Vulnerability Remediation: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Shiro Attack CLI (SummerSec/ShiroAttack2, 2.6k stars), Cve Remediation (rundeck/rundeck, 6.3k stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Endpoint Vulnerability Remediation?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.