Agent skill

Managing Vulnerabilities

by trilwu in trilwu/secskills

Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using…

MITAuto-check passedSecurity

Install Managing Vulnerabilities

skills CLI
$ npx skills add trilwu/secskills --skill managing-vulnerabilities -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills managing-vulnerabilities --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-defense/skills/managing-vulnerabilities .claude/skills/managing-vulnerabilities && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
managing-vulnerabilities
GitHub stars
157
Token cost
~2.2k tokens
SKILL.md length
1,221 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using…

  • Works in 3 steps: Is it being exploited? — EPSS and KEV → Is it reachable? — exposure and context → What does it protect? — asset value
  • Triaging scanner output
  • SKILL.md covers When to Use, When NOT to Use, CVSS Is Severity, Not Priority and The Three Signals to Combine, plus 5 more sections
  • Calls curl; reaches defuddle.md

What it does

Managing Vulnerabilities is an agent skill from trilwu/secskills. Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using SSVC-style decisions, distinguishing reachable from merely present, and tracking remediation and exceptions. Use when triaging scanner output, deciding what to patch first, building a risk-based vulnerability management process, or explaining why a critical CVE is not the top priority.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning and Penetration testing. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Triaging scanner output
  • Deciding what to patch first
  • Building a risk-based vulnerability management process
  • Explaining why a critical CVE is not the top priority

Example prompts

  • “/managing-vulnerabilities”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Is it being exploited? — EPSS and KEV
  2. Is it reachable? — exposure and context
  3. What does it protect? — asset value

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • defuddle.md

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Managing Vulnerabilities loads about 2.2k tokens when it runs. Until then it costs about 127 tokens; SKILL.md has 1,221 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~127
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,221 words, ~2,224 tokens.

Download SKILL.mdSave it as .claude/skills/managing-vulnerabilities/SKILL.md (or your agent's skills folder).
name
managing-vulnerabilities
description
Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using SSVC-style decisions, distinguishing reachable from merely present, and tracking remediation and exceptions. Use when triaging scanner output, deciding what to patch first, building a risk-based vulnerability management process, or explaining why a critical CVE is not the top priority.
verified
2026-07-27

Managing Vulnerabilities

A scanner returns ten thousand findings, most rated High or Critical, and the team can patch a few hundred a month. Vulnerability management is the function that decides which few hundred — and the default of "sort by CVSS descending" is close to the worst possible order, because CVSS measures theoretical severity, not the probability that this vulnerability, on this asset, gets exploited.

The whole discipline is turning an undifferentiated backlog into a defensible order of operations that a limited team can actually execute.

When to Use

  • Triaging vulnerability scanner output into a remediation order
  • Deciding what to patch first under a fixed remediation budget
  • Building or reviewing a risk-based vulnerability management process
  • Explaining why a CVSS 9.8 is not this week's top priority
  • Deciding whether a finding warrants an exception rather than a fix

When NOT to Use

  • Working a security alert queue (EDR/SIEM detections) — use triaging-security-alerts; that is detected activity, this is latent weakness
  • Auditing source for new vulnerabilities — use auditing-code-for-vulnerabilities
  • Cloud misconfiguration rather than software CVEs — use hardening-cloud-posture
  • Exploiting a vulnerability to prove it — use the relevant offensive skill

CVSS Is Severity, Not Priority

CVSS base score answers "how bad is this if exploited, in the abstract?" It does not answer "will it be exploited here?" — which is the question remediation order actually turns on. The evidence is stark: the large majority of CVEs are never exploited in the wild, yet most are scored High or Critical. Sorting by CVSS spends the team's finite capacity on vulnerabilities that will never be attacked while genuinely exploited ones wait behind them.

Use CVSS 4.0 as one input — the severity term — and combine it with signals that speak to probability and impact-here.

The Three Signals to Combine

1. Is it being exploited? — EPSS and KEV
  • CISA KEV (Known Exploited Vulnerabilities). A curated catalog of CVEs with confirmed, observed exploitation in the wild. Presence in KEV is the single strongest prioritization signal available: it is not a prediction, it is a fact of exploitation. Anything in your environment that is on the KEV list jumps the queue. For US federal agencies KEV also carries a binding remediation deadline; treat those dates as a sensible default even if you are not bound by them.
  • EPSS (Exploit Prediction Scoring System). A daily-updated machine-learning probability, from 0 to 1, that a CVE will be exploited in the next 30 days. It is a prediction, not observed fact, and it is a probability, not a ranking — a 0.90 means ~90% likely, and most CVEs sit far below 0.10. Use it to rank the long tail that is not (yet) in KEV. Because it updates daily, re-pull it; a CVE's EPSS can climb sharply when exploitation tooling appears.

KEV and EPSS answer different questions — "known exploited" versus "likely to be" — and you want both. KEV is the floor of certainty; EPSS orders everything below it.

2. Is it reachable? — exposure and context

A vulnerability that is present but not reachable is not the same as one an attacker can touch:

  • Is the affected service internet-facing, internal-only, or on an isolated segment?
  • Is the vulnerable code path actually invoked, or is it a dependency present but never called? (Reachability analysis — see auditing-supply-chain for the dependency case.)
  • Is there a compensating control — a WAF rule, network policy, a disabled feature — that breaks the exploit precondition?
  • Does exploitation need authentication, local access, or user interaction that the placement makes unlikely?

An internet-facing, unauthenticated, KEV-listed RCE and an internal, authenticated, same-CVSS bug are not the same priority, whatever the score says.

3. What does it protect? — asset value

The same vulnerability on a domain controller, a crown-jewel database, and a developer's throwaway VM warrants three different urgencies. Tie the finding to asset criticality; a vulnerability management programme without an asset inventory is ranking blind.

Decide with SSVC, Not a Single Number

Rather than collapsing everything into one score, a decision-tree approach (SSVC — Stakeholder-Specific Vulnerability Categorization) asks the questions above in order and lands on an action: exploitation status → exposure → automatable → impact → {track / track* / attend / act}. The value is that each decision is explainable to the team doing the work and to the risk owner signing the exceptions, in a way "it scored 8.7" never is.

Whatever the framing, the output must be an ordered, executable list with owners and dates, not a risk score. The programme's product is patched systems, not a dashboard.

Show full SKILL.md (487 more words)Show less

Track Remediation and Exceptions Honestly

  • A finding is open until verified fixed, not until a ticket is closed. Re-scan to confirm; "patched" and "no longer detected" are different claims.
  • Exceptions are decisions with an owner and an expiry, not silent suppressions. "Accepted risk" with no name and no review date is how a KEV CVE sits open for a year.
  • Recurrence is a process finding. The same vulnerability returning after a fix means the base image, the golden template, or the pipeline is reintroducing it — fix the source, not the instance, the same way cloud guardrails beat point-fixes.

Rationalizations to Reject

  • "It's a 9.8, so it's top priority." CVSS is severity, not probability of exploitation. A 9.8 that is not in KEV, has a low EPSS, and sits on an isolated internal host ranks below a 7.5 that is KEV-listed and internet-facing.
  • "It's only a 5.3, we can ignore it." Not if it is KEV-listed and reachable. Observed exploitation outranks a mediocre severity score.
  • "We patch everything Critical within 30 days." A blanket SLA by severity spends the budget by the wrong axis. Patch exploited and reachable within days; let unexploited, unreachable Criticals follow.
  • "The dependency is vulnerable, so we're vulnerable." Only if the vulnerable code path is reachable. Present-but-uncalled is real backlog but not the same urgency as invoked.
  • "EPSS is low, so it's safe." EPSS is a 30-day prediction that moves. Re-pull it, and remember KEV overrides it — observed beats predicted.
  • "We closed the ticket." Closing a ticket is not fixing a vulnerability. Re-scan and verify, or it is still open.
  • "It's an accepted risk." Accepted by whom, reviewed when? An exception with no owner and no expiry is an unmanaged vulnerability wearing a label.

Reading External Sources

Fetch public advisories, specifications, and vendor reports as Markdown:

bash
curl -sL "https://defuddle.md/<url>"      # scheme in the path is optional

This strips page boilerplate — roughly 78% fewer tokens on a prose page — and returns the full text rather than a summary, so you can grep it and trust a negative result.

Three things it is not for. Fetch JSON and API responses raw, because readability extraction mangles structured data. Fetch authenticated or JavaScript-rendered pages directly, because it retrieves them anonymously. And never route adversary infrastructure (phishing links, C2, malware hosting), client-owned hosts, or engagement URLs through it — the request leaves your machine to a third party, and for live adversary infrastructure it also tips off the operator.

Some sites block the extractor and return an error blob rather than the page — {"error":"Failed to fetch: 418 I'm a teapot"} from freedesktop.org, for instance. That is the fetch being refused, not the source saying the thing does not exist. Re-fetch the URL directly before drawing any conclusion from it.

References

  • triaging-security-alerts — the detected-activity counterpart to this latent-weakness work; both rank by real risk under finite capacity
  • auditing-supply-chain — dependency reachability, the input to signal 2 for library CVEs
  • hardening-cloud-posture — the config-misconfiguration counterpart to software CVEs
  • reporting-security-findings — communicating prioritized risk to owners

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-defense/skills/managing-vulnerabilities of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Managing Vulnerabilities next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Managing Vulnerabilities compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Managing Vulnerabilities this skilltrilwu/secskills157—~2.2kAutomated safety check: PassMIT
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone
NmapBrownFineSecurity/iothackbot8591 repos~3.8kAutomated safety check: NotesMIT
Security Auditdavila7/claude-code-templates32k4 repos~1.3kAutomated safety check: PassMIT
Cybersecurityohmyjahh/xquads-squads277—~895Automated safety check: PassMIT
Security AuditRightNow-AI/openfang18k—~858Automated safety check: PassApache-2.0

Similar skills

  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Nmap

    BrownFineSecurity/iothackbot

    Professional network reconnaissance and port scanning using nmap.

    859 GitHub starsUsed in 1 repo~3.8k tokens
    SecurityAuto-check: notes
  • Security Audit

    davila7/claude-code-templates

    Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.

    32k GitHub starsUsed in 4 repos~1.3k tokens
    SecurityAuto-check passed
  • Cybersecurity

    ohmyjahh/xquads-squads

    Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

    277 GitHub stars~895 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Security Audit

    RightNow-AI/openfang

    Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology

    18k GitHub stars~858 tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Exploiting Vulnerabilities With Metasploit Framework

    mukul975/Anthropic-Cybersecurity-Skills

    Uses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather…

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check: notes

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Managing Vulnerabilities

What does Managing Vulnerabilities do?

Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using…. Managing Vulnerabilities is an agent skill from trilwu/secskills. Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using SSVC-style decisions, distinguishing reachable from merely present, and tracking remediation and exceptions.

When should I use Managing Vulnerabilities?

Managing Vulnerabilities fits situations like: triaging scanner output; deciding what to patch first; building a risk-based vulnerability management process; explaining why a critical CVE is not the top priority.

How do I install Managing Vulnerabilities in Claude Code?

Run `npx skills add trilwu/secskills --skill managing-vulnerabilities -a claude-code`. Or copy the skill folder (secskills-defense/skills/managing-vulnerabilities in trilwu/secskills) into .claude/skills/managing-vulnerabilities in your project. Claude Code loads it when a task matches its description.

How do I install Managing Vulnerabilities in Codex?

Run `npx skills add trilwu/secskills --skill managing-vulnerabilities -a codex`. Or copy the skill folder (secskills-defense/skills/managing-vulnerabilities in trilwu/secskills) into .agents/skills/managing-vulnerabilities in your project. Codex loads it when a task matches its description.

Can I use Managing Vulnerabilities in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill managing-vulnerabilities -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/managing-vulnerabilities, .gemini/skills/managing-vulnerabilities, .github/skills/managing-vulnerabilities and .opencode/skills/managing-vulnerabilities in your project.

What does Managing Vulnerabilities need to run?

Going by SKILL.md and its folder, Managing Vulnerabilities needs the command-line tools its instructions call (curl).

Does Managing Vulnerabilities access the network?

SKILL.md names 1 domain. In commands or code: defuddle.md; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Managing Vulnerabilities safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Managing Vulnerabilities use?

Managing Vulnerabilities is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Managing Vulnerabilities use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Managing Vulnerabilities?

Skills that share tags, products or a category with Managing Vulnerabilities: Code Audit (3stoneBrother/code-audit, 892 stars), Nmap (BrownFineSecurity/iothackbot, 859 stars), Security Audit (davila7/claude-code-templates, 32k stars) and Cybersecurity (ohmyjahh/xquads-squads, 277 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Managing Vulnerabilities?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.