Agent skill

Cve Remediation

by rundeck in rundeck/rundeck

Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

Apache-2.0Auto-check passedSecurity

Install Cve Remediation

skills CLI
$ npx skills add rundeck/rundeck --skill cve-remediation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rundeck/rundeck cve-remediation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rundeck/rundeck.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/cve-remediation .claude/skills/cve-remediation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cve-remediation
GitHub stars
6.3k
Token cost
~2.9k tokens
SKILL.md length
575 words
Files
1
Skills in repo
10
Repo updated
First seen
Licence
Apache-2.0

At a glance

Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck.

  • Works in 7 steps: CVE Analysis → Dependency Check → Impact Assessment → …
  • Analyzing security vulnerabilities
  • SKILL.md covers When to Use, Process Overview, Phase 1: CVE Analysis and Phase 2: Dependency Check, plus 5 more sections
  • Calls npm, rg and git; reaches nvd.nist.gov and cve.circl.lu

What it does

Cve Remediation is an agent skill from rundeck/rundeck. Verify if a CVE affects the project and remediate it. Checks dependencies, identifies vulnerable versions, suggests/applies fixes, and validates changes. Use when analyzing security vulnerabilities or responding to CVE reports.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning. The repository describes itself as: Enable Self-Service Operations: Give specific users access to your existing tools, services, and scripts. The licence is Apache-2.0.

When your agent uses it

  • Analyzing security vulnerabilities
  • Responding to CVE reports

Example prompts

  • “/cve-remediation”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. CVE Analysis
  2. Dependency Check
  3. Impact Assessment
  4. Fix Strategy
  5. Implementation
  6. Validation
  7. Documentation

What it can do on your machine

Read from SKILL.md and the folder at commit a83e3ca. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • rg
    • git
    • curl
    • jq
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • nvd.nist.gov
    • cve.circl.lu
    • services.nvd.nist.gov

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cve Remediation loads about 2.9k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 575 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rundeck/rundeck at commit a83e3ca, republished under its Apache-2.0 licence (© rundeck). 575 words, ~2,938 tokens.

Download SKILL.mdSave it as .claude/skills/cve-remediation/SKILL.md (or your agent's skills folder).
name
cve-remediation
description
Verify if a CVE affects the project and remediate it. Checks dependencies, identifies vulnerable versions, suggests/applies fixes, and validates changes. Use when analyzing security vulnerabilities or responding to CVE reports.

CVE Remediation Skill

Systematic process for verifying and remediating CVE (Common Vulnerabilities and Exposures) impacts on Rundeck.

When to Use

  • Security team reports a CVE
  • Automated security scan identifies vulnerability
  • Upstream dependency announces security issue
  • Proactive security review
  • Before major releases

Process Overview

1. CVE Analysis → 2. Dependency Check → 3. Impact Assessment → 4. Fix Strategy → 5. Implementation → 6. Validation → 7. Documentation

Phase 1: CVE Analysis

Input Required
  • CVE ID: e.g., CVE-2024-1234
  • CVE Details: Description, affected versions, severity
  • Source: Where the CVE was reported (scanner, security team, upstream)
Gather Information
bash
# Quick CVE lookup
curl -s "https://cve.circl.lu/api/cve/${CVE_ID}" | jq

# Or use NVD API
curl -s "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=${CVE_ID}"

What to extract:

  • Affected library/component
  • Vulnerable version ranges
  • Fixed versions available
  • CVSS score and severity
  • Attack vector and exploitability

Phase 2: Dependency Check

Step 1: Identify Dependency Locations

Check these files for dependency definitions:

bash
# Root dependencies
cat gradle.properties

# All build files
find . -name "build.gradle" -not -path "*/node_modules/*"

# Frontend dependencies
cat rundeckapp/grails-spa/packages/ui-trellis/package.json
Step 2: Search for Vulnerable Dependency

Use Grep to find the dependency across the codebase:

bash
# Example: Search for log4j versions
rg "log4j" gradle.properties build.gradle
rg "log4jVersion" --type gradle

# Example: Search for jackson versions
rg "jackson" gradle.properties
Step 3: Check Transitive Dependencies
bash
# Generate dependency tree
./gradlew dependencies > dependency-tree.txt

# Search for vulnerable library in tree
grep -i "vulnerable-library" dependency-tree.txt

# Check specific module
./gradlew :module-name:dependencies
Step 4: Frontend Dependencies
bash
# Check npm dependencies
cd rundeckapp/grails-spa/packages/ui-trellis
npm list <vulnerable-package>

# Check for vulnerabilities
npm audit
npm audit --json | jq '.vulnerabilities'

Phase 3: Impact Assessment

Determine Impact Level

Critical Impact:

  • Direct dependency
  • Used in production code paths
  • Exploitable in our deployment
  • High CVSS score (7.0+)

Medium Impact:

  • Transitive dependency
  • Used in non-critical paths
  • Requires specific conditions to exploit
  • Medium CVSS score (4.0-6.9)

Low Impact:

  • Test-only dependency
  • Not used in production
  • Difficult to exploit in our context
  • Low CVSS score (<4.0)
Document Findings

Create a summary:

markdown
## CVE Impact Assessment: ${CVE_ID}

**Affected Component:** [library name and version]
**Current Version:** [version in project]
**Vulnerable Versions:** [range from CVE]
**Fixed Version:** [recommended upgrade]
**Severity:** [Critical/High/Medium/Low]
**Impact on Rundeck:** [Direct/Transitive/Not Affected]

**Usage in Project:**
- Location: [file paths]
- Modules affected: [list]
- Production impact: [Yes/No - explain]

**Exploitability:**
- Attack vector: [Local/Network/Adjacent]
- Requires: [Authentication/User interaction/etc]
- Impact on us: [likely/unlikely - explain]

Phase 4: Fix Strategy

Strategy A: Version Upgrade (Preferred)

When to use:

  • Fixed version available
  • Upgrade is backward compatible
  • No breaking changes

Steps:

  1. Identify fixed version from CVE report
  2. Check for breaking changes in changelog
  3. Plan upgrade path
  4. Update version in gradle.properties or build.gradle
Strategy B: Dependency Exclusion + Alternative

When to use:

  • Fixed version not available
  • Upgrade has breaking changes
  • Vulnerability is in transitive dependency we don't use

Steps:

  1. Identify which direct dependency pulls in vulnerable library
  2. Exclude vulnerable transitive dependency
  3. Add explicit dependency on fixed version
  4. Verify functionality
Strategy C: Workaround/Mitigation

When to use:

  • No fix available yet
  • Upgrade not feasible immediately
  • Need temporary protection

Options:

  • Configuration changes to disable vulnerable features
  • Network/firewall rules
  • Input validation
  • WAF rules
  • Runtime monitoring
Strategy D: Accept Risk (Documented)

When to use:

  • Low impact
  • Not exploitable in our environment
  • Fix causes more issues than vulnerability

Requirements:

  • Document decision in a GitHub issue
  • Get security team approval
  • Add to risk register
  • Set reminder to revisit
Show full SKILL.md (213 more words)Show less

Phase 5: Implementation

Write Tests First

Even for dependency upgrades, write a test first:

groovy
// Example: Test that vulnerable version is NOT present
def "should not use vulnerable log4j version"() {
    when:
    def dependencies = project.configurations.runtimeClasspath.resolvedConfiguration.resolvedArtifacts

    then:
    !dependencies.any { it.name == 'log4j-core' && it.moduleVersion.id.version.startsWith('2.14') }
}
Update Dependencies

For gradle.properties:

properties
# Before
log4jVersion=2.14.1

# After (with comment explaining why)
# Updated from 2.14.1 to fix CVE-2021-44228 (Log4Shell)
log4jVersion=2.17.1

For build.gradle:

groovy
// Exclude vulnerable transitive dependency
dependencies {
    implementation('some-library:1.0') {
        exclude group: 'vulnerable-lib', module: 'vulnerable-module'
    }
    // Add fixed version explicitly
    implementation 'vulnerable-lib:vulnerable-module:fixed-version'
}

For package.json:

json
{
  "dependencies": {
    "vulnerable-package": "^fixed.version"
  },
  "overrides": {
    "transitive-vulnerable": "^fixed.version"
  }
}
Run Formatting and Compilation
bash
# Format code
./gradlew spotlessApply

# Quick compilation check
./gradlew compileGroovy compileJava

Phase 6: Validation

Step 1: Verify Dependency Updated
bash
# Check gradle dependencies
./gradlew dependencies | grep -i "vulnerable-library"

# Check npm dependencies
npm list vulnerable-package

# Verify version in build output
./gradlew build --info | grep "vulnerable-library"
Step 2: Run Test Suite
bash
# Full test suite (REQUIRED)
./gradlew test

# Specific module tests
./gradlew :affected-module:test

# Frontend tests
CORE_UI=rundeckapp/grails-spa/packages/ui-trellis
npm run --prefix "$CORE_UI" ci:test:unit
Step 3: Functional Testing
bash
# API functional tests
./gradlew :functional-test:apiTest

# Selenium tests (if UI affected)
./gradlew :functional-test:seleniumTest
Step 4: Build and Smoke Test
bash
# Full build
./gradlew build

# Start application locally
./gradlew bootRun

# Manual smoke test checklist:
# - Application starts without errors
# - Login works
# - Core functionality works
# - No new warnings/errors in logs
Step 5: Security Verification
bash
# Re-run security scanner
./gradlew dependencyCheckAnalyze

# Check for CVE in updated dependencies
./gradlew dependencies | grep -i "CVE"

# Frontend audit
npm audit
npm audit fix --dry-run

Phase 7: Documentation

Create a GitHub Issue

If not already created:

Title: Fix CVE-XXXX-XXXX in [library]
Labels: security
Body:
  CVE: CVE-XXXX-XXXX
  Affected: [library] version [X.X.X]
  Severity: [CVSS score and rating]
  Fix: Upgrade to version [Y.Y.Y]
  Impact: [Description of impact on Rundeck]

  Links:
  - NVD: https://nvd.nist.gov/vuln/detail/CVE-XXXX-XXXX
  - Vendor advisory: [link]
Commit Message
Fix CVE-XXXX-XXXX in [library]

Upgrade [library] from [old-version] to [new-version] to address
security vulnerability CVE-XXXX-XXXX.

Vulnerability Details:
- Severity: [Critical/High/Medium/Low]
- CVSS: [score]
- Impact: [brief description]

Changes:
- Updated [library]Version in gradle.properties
- Ran full test suite - all passing
- Verified no functional regressions
Create Pull Request
bash
gh pr create --title "Fix CVE-XXXX-XXXX in [library]" --body "..."

PR Description (in addition to template):

markdown
## Security Fix

**CVE:** CVE-XXXX-XXXX
**Severity:** [Critical/High/Medium/Low] (CVSS [score])
**Affected:** [library] [version-range]
**Fix:** Upgrade to [new-version]

**Impact Assessment:**
- [X] Direct dependency / [ ] Transitive dependency
- [X] Production code / [ ] Test code only
- Exploitable: [Yes/No - explanation]

**Testing:**
- [X] All unit tests pass
- [X] All functional tests pass
- [X] Manual smoke test completed
- [X] Security scan shows CVE resolved

**References:**
- NVD: https://nvd.nist.gov/vuln/detail/CVE-XXXX-XXXX
- Vendor advisory: [link]
Update Security Documentation

If the project has a security changelog or vulnerability log, update it:

markdown
## [Date] - CVE-XXXX-XXXX

**Fixed in:** Version X.Y.Z
**CVE:** CVE-XXXX-XXXX
**Severity:** [level]
**Component:** [library] [old-version] → [new-version]
**Impact:** [description]
**Credit:** [who reported it]

Common Scenarios

Scenario 1: Gradle Dependency CVE
bash
1. Search for dependency in gradle.properties
2. Update version
3. Run ./gradlew dependencies to verify
4. Run ./gradlew test
5. Create PR
Scenario 2: Transitive Dependency CVE
bash
1. Find which direct dependency pulls it in
2. Add explicit dependency with fixed version
3. Or exclude vulnerable transitive and add fixed version
4. Verify with ./gradlew dependencies
5. Run tests and create PR
Scenario 3: Frontend NPM Package CVE
bash
1. cd to package directory
2. Run npm audit
3. Update package.json or use overrides
4. Run npm test
5. Commit and create PR
Scenario 4: No Fix Available Yet
bash
1. Document the issue in a GitHub issue
2. Assess actual risk/exploitability
3. Implement workarounds if needed
4. Set up monitoring/alerts
5. Schedule re-assessment when fix available

Checklist

Use this checklist for every CVE remediation:

  • CVE analyzed and understood
  • Affected dependencies identified
  • Impact assessed (Critical/High/Medium/Low)
  • Fix strategy determined
  • GitHub issue created (if not already)
  • Branch created (fix-cve-description)
  • Dependencies updated with comments
  • Code formatted (./gradlew spotlessApply)
  • Compilation passes (./gradlew compileGroovy compileJava)
  • All tests pass (./gradlew test)
  • Functional tests pass
  • Manual smoke test completed
  • Security scan confirms fix
  • Commit message includes CVE reference
  • PR created with security details
  • PR description includes CVE details
  • Security team notified (if critical)
  • Documentation updated

Quick Reference Commands

bash
# Find dependency in project
rg "library-name" gradle.properties build.gradle

# Check dependency tree
./gradlew dependencies | grep "library-name"

# Update and verify
vim gradle.properties  # Update version
./gradlew spotlessApply
./gradlew compileGroovy compileJava
./gradlew test

# Security checks
./gradlew dependencyCheckAnalyze
npm audit

# Create PR
git checkout -b fix-cve-xxxx-xxxx
git add gradle.properties
git commit -m "Fix CVE-XXXX in library"
gh pr create --web

See Also

  • Testing: .claude/docs/testing-guidelines.md
  • Conventions: CLAUDE.md - Code conventions, git workflow, dependency management
  • Build Commands: .claude/docs/build-commands.md

© rundeck, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/cve-remediation of rundeck/rundeck.

Open the folder on GitHubat commit a83e3ca

Compare with similar skills

Cve Remediation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cve Remediation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cve Remediation this skillrundeck/rundeck6.3k—~2.9kAutomated safety check: PassApache-2.0
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Shiro Attack CLISummerSec/ShiroAttack22.6k—~945Automated safety check: PassMIT
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesCustom licence
Write Cve Ruleevdenis/cvehound138—~2.5kAutomated safety check: PassGPL-3.0

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    190 GitHub stars~2.5k tokensUpdated 14 days ago
    SecurityAuto-check: notes
  • Write Cve Rule

    evdenis/cvehound

    Write, debug, or validate a CVEhound detection rule (.cocci or .grep) for a Linux kernel CVE.

    138 GitHub stars~2.5k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    551 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes

More from rundeck/rundeck

All 10 skills in this repo
  • Backport PR

    rundeck/rundeck

    Backport commits from an existing GitHub Pull Request to a target branch and open a new backport PR.

    6.3k GitHub stars~3k tokensUpdated yesterday
    Auto-check passed
  • Generate standardized CONTEXT.md files for features. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • I18n Vue Template

    rundeck/rundeck

    Internationalize Vue component templates by replacing all hardcoded strings with $t() calls and adding translations to i18n.ts or enUS.js.

    6.3k GitHub stars~523 tokensUpdated yesterday
    Auto-check: notes
  • Onboard Contributor

    rundeck/rundeck

    Guide a new contributor through the rundeck OSS repo. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~848 tokensUpdated yesterday
    Auto-check passed
  • Write Jest Tests

    rundeck/rundeck

    Write Vue component unit tests. An agent skill from rundeck/rundeck.

    6.3k GitHub stars~486 tokensUpdated yesterday
    Auto-check: notes
  • Create API Endpoint

    rundeck/rundeck

    Create REST API endpoints with proper OpenAPI annotations, API versioning, and testing following Rundeck standards.

    6.3k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Cve Remediation

What does Cve Remediation do?

Verify if a CVE affects the project and remediate it. An agent skill from rundeck/rundeck. Cve Remediation is an agent skill from rundeck/rundeck. Verify if a CVE affects the project and remediate it.

When should I use Cve Remediation?

Cve Remediation fits situations like: analyzing security vulnerabilities; responding to CVE reports.

How do I install Cve Remediation in Claude Code?

Run `npx skills add rundeck/rundeck --skill cve-remediation -a claude-code`. Or copy the skill folder (.claude/skills/cve-remediation in rundeck/rundeck) into .claude/skills/cve-remediation in your project. Claude Code loads it when a task matches its description.

How do I install Cve Remediation in Codex?

Run `npx skills add rundeck/rundeck --skill cve-remediation -a codex`. Or copy the skill folder (.claude/skills/cve-remediation in rundeck/rundeck) into .agents/skills/cve-remediation in your project. Codex loads it when a task matches its description.

Can I use Cve Remediation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rundeck/rundeck --skill cve-remediation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cve-remediation, .gemini/skills/cve-remediation, .github/skills/cve-remediation and .opencode/skills/cve-remediation in your project.

What does Cve Remediation need to run?

Going by SKILL.md and its folder, Cve Remediation needs the command-line tools its instructions call (npm, rg, git, curl, jq and gh).

Does Cve Remediation access the network?

SKILL.md names 3 domains. In commands or code: nvd.nist.gov, cve.circl.lu and services.nvd.nist.gov; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Cve Remediation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cve Remediation use?

Cve Remediation is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cve Remediation use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cve Remediation?

Skills that share tags, products or a category with Cve Remediation: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Shiro Attack CLI (SummerSec/ShiroAttack2, 2.6k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Forensify (alexgreensh/repo-forensics, 190 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cve Remediation?

rundeck (a GitHub organization) maintains it in rundeck/rundeck, which has 6,330 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 9, 2026.

Source: rundeck/rundeck on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.