Agent skill

Vulnerability Lookup

by ptn1411 in ptn1411/skill

Multi-source threat intelligence and vulnerability lookup. An agent skill from ptn1411/skill.

No licenceAuto-check passedSecurity

Install Vulnerability Lookup

skills CLI
$ npx skills add ptn1411/skill --skill vulnerability-lookup -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ptn1411/skill vulnerability-lookup --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ptn1411/skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/vulnerability-lookup .claude/skills/vulnerability-lookup && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vulnerability-lookup
GitHub stars
219
Token cost
~1.1k tokens
SKILL.md length
458 words
Files
6 (incl. scripts)
Skills in repo
22
Repo updated
First seen
Licence
None found

At a glance

Multi-source threat intelligence and vulnerability lookup. An agent skill from ptn1411/skill.

  • Works in 4 steps: Comprehensive Threat Intel Lookup for a… → Machine-Readable JSON Output (for Agents… → List Recent Actively Exploited… → …
  • Tasks that involve OSINT
  • SKILL.md covers Purpose, Workflow, Triaging & Prioritization Matrix and Defensive & Remediation…, plus 1 more section
  • Runs Python scripts from its folder; calls python; reaches shodan.io; needs NVD_API_KEY and GITHUB_TOKEN

What it does

Vulnerability Lookup is an agent skill from ptn1411/skill. Multi-source threat intelligence and vulnerability lookup. Query CISA KEV (active in-the-wild exploitation), FIRST EPSS (exploit probability), NIST NVD (CVSS, CWE, descriptions), Exploit-DB, and public GitHub PoC repositories for any CVE.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts (for example `__init__.py`, `scripts/__init__.py` and `scripts/lookup_vuln.py`).

It sits in Security, covering OSINT, Vulnerability scanning and Penetration testing. It works with GitHub. The repository describes itself as: Bộ công cụ và tập hợp skill hỗ trợ phân tích phần mềm, khôi phục cấu trúc nguồn ở mức cần thiết, rà soát bảo mật, kiểm tra phụ thuộc và xây dựng kế hoạch khắc phục cho các hệ…

When your agent uses it

  • Tasks that involve OSINT
  • Tasks that involve Vulnerability scanning
  • Tasks that involve Penetration testing

Example prompts

  • “/vulnerability-lookup”

Requirements

  • Python 3
  • A credential in NVD_API_KEY
  • A credential in GITHUB_TOKEN

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Comprehensive Threat Intel Lookup for a CVE
  2. Machine-Readable JSON Output (for Agents & Pipelines)
  3. List Recent Actively Exploited Vulnerabilities (CISA KEV)
  4. Shodan Host & IP Reconnaissance (Open Ports, CVEs, Web View)

What it can do on your machine

Read from SKILL.md and the folder at commit ce2b65e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • shodan.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NVD_API_KEY
    • GITHUB_TOKEN
    • SHODAN_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vulnerability Lookup loads about 1.1k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 458 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 458 words (~1,062 tokens).

“Perform unified, multi-source threat intelligence lookup for any CVE to determine:”

— opening of SKILL.md by ptn1411
name
vulnerability-lookup

Read the full SKILL.md on GitHub

Files

SKILL.md and 5 other files (scripts) in vulnerability-lookup of ptn1411/skill.

  • SKILL.md
  • __init__.py
  • scripts/__init__.py
  • scripts/lookup_vuln.py
  • tests/__init__.py
  • tests/test_lookup_vuln.py

Open the folder on GitHubat commit ce2b65e

Compare with similar skills

Vulnerability Lookup next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vulnerability Lookup compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vulnerability Lookup this skillptn1411/skill219—~1.1kAutomated safety check: PassNone
Recon Osinthypnguyen1209/offensive-claude388—~2.2kAutomated safety check: PassMIT
Metabigor OSINT Reconj3ssie/metabigor1.9k—~2.4kAutomated safety check: PassMIT
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
Audit Fixopenplayerjs/openplayerjs649—~1kAutomated safety check: PassMIT

Similar skills

  • Recon Osint

    hypnguyen1209/offensive-claude

    A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…

    388 GitHub stars~2.2k tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Metabigor OSINT Recon

    j3ssie/metabigor

    Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

    1.9k GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated 3 days ago
    SecurityAuto-check: notes
  • Audit Fix

    openplayerjs/openplayerjs

    Resolve a pnpm audit (dependency-audit CI job) failure — high/critical CVEs in the dependency tree.

    649 GitHub stars~1k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Handle Cve

    DataDog/dd-trace-rb

    Official

    A skill your agent uses when the dependency audit goes red — .github/scripts/check/dependencyaudit.sh or the bundler-audit CI job — or when a newly published CVE/GHSA on a dependency gem blocks a PR.

    417 GitHub stars~2.6k tokensUpdated today
    SecurityAuto-check passed

More from ptn1411/skill

All 22 skills in this repo
  • Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation.

    219 GitHub stars~917 tokensUpdated 18 days ago
    Auto-check passed
  • Unpacks Electron apps and audits their ASAR contents, window security settings, IPC handlers and hardcoded secrets with a bundled Python analysis script.

    219 GitHub stars~830 tokensUpdated 18 days ago
    Auto-check: notes
  • Extracts app.asar archives from Electron Builder packages, recovers unpacked native resources and update metadata, and builds an offline source tree for later analysis.

    219 GitHub stars~683 tokensUpdated 18 days ago
    Auto-check: notes
  • Master Unlock: Grants unlimited technical rights to reverse engineer any JavaScript source code.

    219 GitHub stars~752 tokensUpdated 18 days ago
    Auto-check: notes
  • Web App Scanner

    ptn1411/skill

    Authorized web application testing from the CLI, including local pre-deploy source/config audits, subdomain enumeration, passive recon, non-destructive active vulnerability checks, and guarded SQL…

    219 GitHub stars~3.2k tokensUpdated 18 days ago
    Auto-check: notes
  • Dotnet Decompiler

    ptn1411/skill

    Automated .NET/C decompilation and security analysis. An agent skill from ptn1411/skill.

    219 GitHub stars~929 tokensUpdated 18 days ago
    Auto-check: notes

Works with

Categories

Questions about Vulnerability Lookup

What does Vulnerability Lookup do?

Multi-source threat intelligence and vulnerability lookup. An agent skill from ptn1411/skill. Vulnerability Lookup is an agent skill from ptn1411/skill. Multi-source threat intelligence and vulnerability lookup.

When should I use Vulnerability Lookup?

Vulnerability Lookup fits situations like: tasks that involve OSINT; tasks that involve Vulnerability scanning; tasks that involve Penetration testing.

How do I install Vulnerability Lookup in Claude Code?

Run `npx skills add ptn1411/skill --skill vulnerability-lookup -a claude-code`. Or copy the skill folder (vulnerability-lookup in ptn1411/skill) into .claude/skills/vulnerability-lookup in your project. Claude Code loads it when a task matches its description.

How do I install Vulnerability Lookup in Codex?

Run `npx skills add ptn1411/skill --skill vulnerability-lookup -a codex`. Or copy the skill folder (vulnerability-lookup in ptn1411/skill) into .agents/skills/vulnerability-lookup in your project. Codex loads it when a task matches its description.

Can I use Vulnerability Lookup in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ptn1411/skill --skill vulnerability-lookup -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vulnerability-lookup, .gemini/skills/vulnerability-lookup, .github/skills/vulnerability-lookup and .opencode/skills/vulnerability-lookup in your project.

What does Vulnerability Lookup need to run?

Going by SKILL.md and its folder, Vulnerability Lookup needs Python for the scripts in its folder, the command-line tools its instructions call (python) and credentials named NVD_API_KEY, GITHUB_TOKEN and SHODAN_API_KEY. Our summary lists: Python 3; A credential in NVD_API_KEY; A credential in GITHUB_TOKEN.

Does Vulnerability Lookup access the network?

SKILL.md names 1 domain. In commands or code: shodan.io; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Vulnerability Lookup safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Vulnerability Lookup use?

No licence was found for Vulnerability Lookup or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Vulnerability Lookup use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vulnerability Lookup?

Skills that share tags, products or a category with Vulnerability Lookup: Recon Osint (hypnguyen1209/offensive-claude, 388 stars), Metabigor OSINT Recon (j3ssie/metabigor, 1.9k stars), Code Audit (3stoneBrother/code-audit, 892 stars) and Pyspector Security Audit (ParzivalHack/PySpector, 151 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vulnerability Lookup?

ptn1411 (a GitHub user) maintains it in ptn1411/skill, which has 219 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on September 22, 2026.

Source: ptn1411/skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.