Search the U.S. An agent skill from mvanhorn/printing-press-library.

Apache-2.0Auto-check: notesSecurity

Install Pp Nvd

skills CLI
$ npx skills add mvanhorn/printing-press-library --skill pp-nvd -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mvanhorn/printing-press-library pp-nvd --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mvanhorn/printing-press-library.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cli-skills/pp-nvd .claude/skills/pp-nvd && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pp-nvd
GitHub stars
2.1k
Token cost
~1.9k tokens
SKILL.md length
766 words
Files
1
Skills in repo
506
Repo updated
First seen
Licence
Apache-2.0

At a glance

Search the U.S. An agent skill from mvanhorn/printing-press-library.

  • Works in 3 steps: Install via the Printing Press… → Verify: nvd-pp-cli --version → Ensure the reported install directory is…
  • Phrases: look up CVE
  • SKILL.md covers Prerequisites: Install the CLI, When Not to Use This CLI, Command Reference and Auth Setup, plus 8 more sections
  • Calls go, claude and npx

What it does

Pp Nvd is an agent skill from mvanhorn/printing-press-library. Search the U.S. National Vulnerability Database for CVEs, CVSS scores, affected versions, and severity ratings — by keyword, product (CPE name), CVE ID, or date range. Trigger phrases: look up CVE, CVSS score for, vulnerabilities in <product, use nvd.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning. The repository describes itself as: Official library of CLIs generated by the CLI Printing Press. Endorsed, tested, and community-contributed. The licence is Apache-2.0.

When your agent uses it

  • Phrases: look up CVE
  • Vulnerabilities in <product

Example prompts

  • “/pp-nvd”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Read, Bash

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Install via the Printing Press installer. It defaults binaries to $HOME/.local/bin on macOS/Linux and…
  2. Verify: nvd-pp-cli --version
  3. Ensure the reported install directory is on $PATH for the agent/runtime that will invoke this skill.

What it can do on your machine

Read from SKILL.md and the folder at commit 76de244. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go
    • claude
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pp Nvd loads about 1.9k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 766 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mvanhorn/printing-press-library at commit 76de244, republished under its Apache-2.0 licence (© mvanhorn). 766 words, ~1,883 tokens.

Download SKILL.mdSave it as .claude/skills/pp-nvd/SKILL.md (or your agent's skills folder).
name
pp-nvd
description
Search the U.S. National Vulnerability Database for CVEs, CVSS scores, affected versions, and severity ratings — by keyword, product (CPE name), CVE ID, or date range. Trigger phrases: `look up CVE`, `CVSS score for`, `vulnerabilities in <product>`, `use nvd`.
allowed-tools
Read, Bash
author
Hiten Shah
license
Apache-2.0
argument-hint
<command> [args] | install cli|mcp
<!-- GENERATED FILE — DO NOT EDIT.
     This file is a verbatim mirror of library/developer-tools/nvd/SKILL.md,
     regenerated post-merge by tools/generate-skills/. Hand-edits here are
     silently overwritten on the next regen. Edit the library/ source instead.
     See the repository agent guide, section "Generated artifacts: registry.json, cli-skills/". -->

Nvd — Printing Press CLI

Prerequisites: Install the CLI

This skill drives the nvd-pp-cli binary. You must verify the CLI is installed before invoking any command from this skill. If it is missing, install it first:

  1. Install via the Printing Press installer. It defaults binaries to $HOME/.local/bin on macOS/Linux and %LOCALAPPDATA%\Programs\PrintingPress\bin on Windows:
    bash
    npx -y @mvanhorn/printing-press-library install nvd --cli-only
  2. Verify: nvd-pp-cli --version
  3. Ensure the reported install directory is on $PATH for the agent/runtime that will invoke this skill.

If the npx install fails (no Node, offline, etc.), fall back to a direct Go install (requires Go 1.26.6 or newer):

bash
go install github.com/mvanhorn/printing-press-library/library/developer-tools/nvd/cmd/nvd-pp-cli@latest

If --version reports "command not found" after install, the runtime cannot see the binary directory on $PATH. Do not proceed with skill commands until verification succeeds.

When Not to Use This CLI

Do not activate this CLI for requests that require creating, updating, deleting, publishing, commenting, upvoting, inviting, ordering, sending messages, booking, purchasing, or changing remote state. This printed CLI exposes read-only commands for inspection, export, sync, and analysis.

Command Reference

json — Manage json

  • nvd-pp-cli json search-cpes — Search Common Platform Enumeration names to find exact product identifiers for vulnerability lookups.
  • nvd-pp-cli json search-cves — Search vulnerabilities by keyword, CVE ID, CPE name, publication date, or CVSS severity.
Finding the right command

When you know what you want to do but not which command does it, ask the CLI directly:

bash
nvd-pp-cli which "<capability in your own words>"

which resolves a natural-language capability query to the best matching command from this CLI's curated feature index. Exit code 0 means at least one match; exit code 2 means no confident match — fall back to --help or use a narrower query.

Auth Setup

No authentication required.

Run nvd-pp-cli doctor to verify setup.

Agent Mode

Add --agent to any command. Expands to: --json --compact --no-input --no-color --yes.

  • Pipeable — JSON on stdout, errors on stderr

  • Filterable — --select keeps a subset of fields. Dotted paths descend into nested structures; arrays traverse element-wise. Critical for keeping context small on verbose APIs:

    bash
    nvd-pp-cli json search-cpes --agent --select id,name,status
  • Previewable — --dry-run shows the request without sending

  • Offline-friendly — sync/search commands can use the local SQLite store when available

  • Non-interactive — never prompts, every input is a flag

  • Read-only — do not use this CLI for create, update, delete, publish, comment, upvote, invite, order, send, or other mutating requests

Response envelope

Commands that read from the local store or the API wrap output in a provenance envelope:

json
{
  "meta": {"source": "live" | "local", "synced_at": "...", "reason": "..."},
  "results": <data>
}

Parse .results for data and .meta.source to know whether it's live or local. A human-readable N results (live) summary is printed to stderr only when stdout is a terminal — piped/agent consumers get pure JSON on stdout.

Show full SKILL.md (362 more words)Show less

Agent Feedback

When you (or the agent) notice something off about this CLI, record it:

nvd-pp-cli feedback "the --since flag is inclusive but docs say exclusive"
nvd-pp-cli feedback --stdin < notes.txt
nvd-pp-cli feedback list --json --limit 10

Entries are stored locally at ~/.nvd-pp-cli/feedback.jsonl. They are never POSTed unless NVD_FEEDBACK_ENDPOINT is set AND either --send is passed or NVD_FEEDBACK_AUTO_SEND=true. Default behavior is local-only.

Write what surprised you, not a bug report. Short, specific, one line: that is the part that compounds.

Output Delivery

Every command accepts --deliver <sink>. The output goes to the named sink in addition to (or instead of) stdout, so agents can route command results without hand-piping. Three sinks are supported:

SinkEffect
stdoutDefault; write to stdout only
file:<path>Atomically write output to <path> (tmp + rename)
webhook:<url>POST the output body to the URL (application/json or application/x-ndjson when --compact)

Unknown schemes are refused with a structured error naming the supported set. Webhook failures return non-zero and log the URL + HTTP status on stderr.

Named Profiles

A profile is a saved set of flag values, reused across invocations. Use it when a scheduled agent calls the same command every run with the same configuration - HeyGen's "Beacon" pattern.

nvd-pp-cli profile save briefing --json
nvd-pp-cli --profile briefing json search-cpes
nvd-pp-cli profile list --json
nvd-pp-cli profile show briefing
nvd-pp-cli profile delete briefing --yes

Explicit flags always win over profile values; profile values win over defaults. agent-context lists all available profiles under available_profiles so introspecting agents discover them at runtime.

Exit Codes

CodeMeaning
0Success
2Usage error (wrong arguments)
3Resource not found
5API error (upstream issue)
7Rate limited (wait and retry)
10Config error

Argument Parsing

Parse $ARGUMENTS:

  1. Empty, help, or --help → show nvd-pp-cli --help output
  2. Starts with install → ends with mcp → MCP installation; otherwise → see Prerequisites above
  3. Anything else → Direct Use (execute as CLI command with --agent)

MCP Server Installation

  1. Install the MCP server:
    bash
    go install github.com/mvanhorn/printing-press-library/library/developer-tools/nvd/cmd/nvd-pp-mcp@latest
  2. Register with Claude Code:
    bash
    claude mcp add nvd-pp-mcp -- nvd-pp-mcp
  3. Verify: claude mcp list

Direct Use

  1. Check if installed: which nvd-pp-cli If not found, offer to install (see Prerequisites at the top of this skill).
  2. Match the user query to the best command from the Command Reference above, or resolve it with nvd-pp-cli which "<capability>".
  3. Execute with the --agent flag:
    bash
    nvd-pp-cli <command> [subcommand] [args] --agent
  4. If ambiguous, drill into subcommand help: nvd-pp-cli <command> --help.

© mvanhorn, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in cli-skills/pp-nvd of mvanhorn/printing-press-library.

Open the folder on GitHubat commit 76de244

Compare with similar skills

Pp Nvd next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pp Nvd compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pp Nvd this skillmvanhorn/printing-press-library2.1k—~1.9kAutomated safety check: NotesApache-2.0
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT
Cve Remediationrundeck/rundeck6.3k—~2.9kAutomated safety check: PassApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Cve Remediation

    rundeck/rundeck

    Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 12 days ago
    SecurityAuto-check: notes
  • Write Cve Rule

    evdenis/cvehound

    Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.

    138 GitHub stars~2.5k tokensUpdated yesterday
    SecurityAuto-check passed

More from mvanhorn/printing-press-library

All 506 skills in this repo
  • Agent Desktop

    mvanhorn/printing-press-library

    Desktop automation through the real Rust agent-desktop CLI, published in Printing Press through a small bridge.

    2.1k GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Gfonts

    mvanhorn/printing-press-library

    Search, browse, and download Google Fonts from the terminal via the gfonts CLI.

    2.1k GitHub stars~574 tokensUpdated today
    Auto-check passed
  • Pp 1688

    mvanhorn/printing-press-library

    The free, offline Trigger phrases: search 1688 for, find a factory on 1688 for, wholesale price on 1688 for, who is the cheapest supplier on 1688 for, compare 1688 suppliers for, use 1688, run 1688.

    2.1k GitHub stars~3k tokensUpdated today
    Auto-check: notes
  • Pp Activity Japan

    mvanhorn/printing-press-library

    Inspect known Activity Japan plan IDs or URLs, compare dated prices and sessions, check language-sitemap coverage, and hand off to canonical booking pages.

    2.1k GitHub stars~2k tokensUpdated today
    Auto-check: notes
  • Pp Adminbyrequest

    mvanhorn/printing-press-library

    Every Admin By Request portal action, plus a local SQLite mirror of audit, events, inventory and requests for ad-hoc...

    2.1k GitHub stars~3.3k tokensUpdated today
    Auto-check: notes
  • Pp Agent Capture

    mvanhorn/printing-press-library

    macOS screen capture, window recording, GIF conversion, and agent evidence bundles from the terminal.

    2.1k GitHub stars~1.6k tokensUpdated today
    Auto-check: notes

Categories

Questions about Pp Nvd

What does Pp Nvd do?

Search the U.S. An agent skill from mvanhorn/printing-press-library. Pp Nvd is an agent skill from mvanhorn/printing-press-library.S.

When should I use Pp Nvd?

Pp Nvd fits situations like: phrases: look up CVE; vulnerabilities in <product.

How do I install Pp Nvd in Claude Code?

Run `npx skills add mvanhorn/printing-press-library --skill pp-nvd -a claude-code`. Or copy the skill folder (cli-skills/pp-nvd in mvanhorn/printing-press-library) into .claude/skills/pp-nvd in your project. Claude Code loads it when a task matches its description.

How do I install Pp Nvd in Codex?

Run `npx skills add mvanhorn/printing-press-library --skill pp-nvd -a codex`. Or copy the skill folder (cli-skills/pp-nvd in mvanhorn/printing-press-library) into .agents/skills/pp-nvd in your project. Codex loads it when a task matches its description.

Can I use Pp Nvd in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mvanhorn/printing-press-library --skill pp-nvd -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pp-nvd, .gemini/skills/pp-nvd, .github/skills/pp-nvd and .opencode/skills/pp-nvd in your project.

What does Pp Nvd need to run?

Going by SKILL.md and its folder, Pp Nvd needs the command-line tools its instructions call (go, claude and npx). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Read, Bash.

Does Pp Nvd access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Pp Nvd safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Pp Nvd use?

Pp Nvd is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pp Nvd use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pp Nvd?

Skills that share tags, products or a category with Pp Nvd: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Shiro Attack CLI (SummerSec/ShiroAttack2, 2.6k stars), Cve Remediation (rundeck/rundeck, 6.3k stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pp Nvd?

mvanhorn (a GitHub user) maintains it in mvanhorn/printing-press-library, which has 2,056 GitHub stars. The repository holds 506 skills in this directory. The repository was last updated on October 9, 2026.

Source: mvanhorn/printing-press-library on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.