Skill Inspector
NVIDIA/SkillSpector
Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.
A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.
$ npx skills add vulnersCom/api --skill vulners-api-python-sdk -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vulnersCom/api vulners-api-python-sdk --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vulnersCom/api.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/vulners-api .claude/skills/vulners-api-python-sdk && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vulners-api-python-sdk" agent skill from https://github.com/vulnersCom/api/tree/master/.agents/skills/vulners-api into .claude/skills/vulners-api-python-sdk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulners-api-python-sdk", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vulnersCom/api/tree/master/.agents/skills/vulners-apiType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vulnersCom/api --skill vulners-api-python-sdk -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vulnersCom/api vulners-api-python-sdk --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vulnersCom/api.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/vulners-api .agents/skills/vulners-api-python-sdk && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vulners-api-python-sdk" agent skill from https://github.com/vulnersCom/api/tree/master/.agents/skills/vulners-api into .agents/skills/vulners-api-python-sdk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulners-api-python-sdk", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vulnersCom/api --skill vulners-api-python-sdk -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vulnersCom/api vulners-api-python-sdk --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vulnersCom/api.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/vulners-api .cursor/skills/vulners-api-python-sdk && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vulners-api-python-sdk" agent skill from https://github.com/vulnersCom/api/tree/master/.agents/skills/vulners-api into .cursor/skills/vulners-api-python-sdk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulners-api-python-sdk", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vulnersCom/api.git --path .agents/skills/vulners-api--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vulnersCom/api --skill vulners-api-python-sdk -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vulnersCom/api vulners-api-python-sdk --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vulnersCom/api.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/vulners-api .gemini/skills/vulners-api-python-sdk && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vulners-api-python-sdk" agent skill from https://github.com/vulnersCom/api/tree/master/.agents/skills/vulners-api into .gemini/skills/vulners-api-python-sdk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulners-api-python-sdk", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vulnersCom/api vulners-api-python-sdkInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vulnersCom/api --skill vulners-api-python-sdk -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vulnersCom/api.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/vulners-api .github/skills/vulners-api-python-sdk && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vulners-api-python-sdk" agent skill from https://github.com/vulnersCom/api/tree/master/.agents/skills/vulners-api into .github/skills/vulners-api-python-sdk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulners-api-python-sdk", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vulnersCom/api --skill vulners-api-python-sdk -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vulnersCom/api vulners-api-python-sdk --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vulnersCom/api.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/vulners-api .opencode/skills/vulners-api-python-sdk && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vulners-api-python-sdk" agent skill from https://github.com/vulnersCom/api/tree/master/.agents/skills/vulners-api into .opencode/skills/vulners-api-python-sdk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulners-api-python-sdk", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vulners-api-python-sdkA skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.
Vulners API Python SDK is an agent skill from vulnersCom/api. Use when modifying, testing, documenting, or reviewing the Vulners Python SDK. Covers the v4 architecture (typed sync/async clients, resource namespaces, bulletin model hierarchy, unasync codegen), the preserved legacy v3 surface, uv-based tooling, the 100% branch-coverage gate, safe API-key handling, and defensive vulnerability-intelligence examples.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `README.md`, `references/api-overview.md` and `references/repo-layout.md`).
It sits in Security, covering Vulnerability scanning, Project scaffolding and Supply chain security. It works with Python and Model Context Protocol. The repository describes itself as: Official Python SDK for the Vulners vulnerability-intelligence API — search CVEs, exploits and advisories (CVSS/EPSS/KEV), audit software, Linux/Windows hosts and SBOMs, and… The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e708afc. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
makeuvpythonFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.astral.shFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
VULNERS_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vulners API Python SDK loads about 2.3k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 959 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from vulnersCom/api at commit e708afc, republished under its MIT licence (© vulnersCom). 959 words, ~2,308 tokens.
.claude/skills/vulners-api-python-sdk/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Maintain the Vulners Python API SDK safely and consistently.
Use this skill for:
src/vulners/ package (v4 core or the legacy v3 layer).tests/.samples/ and documentation under documentation/.Do not use this skill for:
src/vulners/ package.This skill is consumed from .agents/skills/vulners-api/SKILL.md by Codex-compatible
agent harnesses. This repository is the source of truth for the skill.
Current repository layout (src layout, uv_build backend):
api/
├── .agents/skills/vulners-api/ # this skill
├── dev-tools/ # maintainer tooling (not shipped)
├── documentation/ # mkdocs site source (Material theme)
├── samples/ # runnable examples: v4/ and legacy/
├── src/vulners/ # the shipped package
├── tests/ # pytest suite (core, bc, live, benchmarks)
├── Makefile
├── mkdocs.yml
└── pyproject.tomlThe primary API is the pair of typed clients in src/vulners/_client.py:
Vulners (sync) and AsyncVulners (async), re-exported from the package root.cached_property namespaces: search,
audit, archive, misc, report, stix, subscriptions,
subscriptions_v4, webhooks, vscanner (which nests licenses,
projects, projects.tasks, projects.results).RequestSpec
(method, path, body mode, unwrap keys, timeout profile, rate-limit group) and
routes through one shared request pipeline: credential-safety transport,
retries with Retry-After support, and token-bucket rate-limit pacing.client.get/post/put/delete are untyped escape hatches for any API path.Async is the source of truth. The sync mirror is generated:
src/vulners/_resources/_async/ (and
_transport_client_async.py, _ratelimit_async.py).make unasync regenerates src/vulners/_resources/_sync/ and the sync
transport/ratelimit modules via unasyncd (mapping table in
[tool.unasyncd] in pyproject.toml). Both sides are committed;
make unasync-check gates drift in CI.Bulletin models (src/vulners/_models/) form a base → family → per-collection
hierarchy:
Bulletin — fields common to every document (hand-written, bulletin.py).CveBulletin, ExploitBulletin, …) — one per
bulletinFamily, hand-written; construct_bulletin picks the right class.type, built lazily by the
factory in collections.py from generated data in _collections_data.py._field_descriptions.py and flow to models
and reference docs. Refresh everything against the live API with
python dev-tools/data-models/sample_collections.py (needs an API key).Legacy v3 surface is preserved for backward compatibility: base.py,
vscanner.py, and the src/vulners/vulners/ subpackage keep the old
VulnersApi / VScannerApi working unchanged (deprecated — new code should use
Vulners / AsyncVulners). The v3 layer is frozen: excluded from strict
typing and the coverage gate, guarded by the compatibility oracle in
tests/bc/. Do not extend it with new features.
An MCP server (vulners-mcp / python -m vulners.mcp) lives in
src/vulners/_mcp/, behind the optional mcp extra (fastmcp).
src/vulners/_resources/_async/ by API domain
(search.py, audit.py, archive.py, misc.py, report.py, stix.py,
subscriptions*.py, webhooks.py, vscanner.py).RequestSpec for the endpoint and add a typed async
method with a Google-style docstring (args, returns, raises).make unasync to regenerate the sync mirror.respx; no live calls) asserting URL, method,
body, response parsing, and error paths. The v4 core is held at 100%
branch coverage — make cov must stay green.documentation/ if the method is a common task) and add a
sample under samples/v4/ if it is commonly used.api.md if the public surface changed:
python dev-tools/generate_api_md.py.Backward compatibility: breaking changes only deliberately, documented in release notes / CHANGELOG with the intended versioning impact.
The project uses uv with PEP 735 dependency
groups (uv sync installs the dev toolchain). Python >=3.10; ruff targets
py310 — do not use syntax or stdlib APIs unavailable on 3.10. Line length 98.
uv sync # install project + dev groups
make format # ruff format + import sorting
make lint # ruff check + format --check
make typecheck # mypy + basedpyright
make test # full pytest suite, parallel (xdist)
make cov # coverage gate: v4 core at 100% branch coverage
make cov-mcp # MCP server coverage (isolated env with the mcp extra)
make bc # backward-compatibility oracle only
make unasync # regenerate the sync mirror from async sources
make unasync-check # fail if the committed mirror drifted
make docs # mkdocs build --strict (any warning fails)
make check # lint + typecheck + unasync-check + testuv run pytest tests/<file> runs a single module; make test-fast runs
serially for easier debugging.
Tests live in tests/:
tests/core/ and top-level tests/test_*.py — the v4 suite: mocked HTTP
(respx), request construction, parsing, retries, rate limiting, streaming,
secret handling. Deterministic; never require VULNERS_API_KEY.tests/bc/ — the backward-compatibility oracle pinning the v3 surface and
wire behavior against surface.json / golden files.tests/live/ — opt-in live-API tests (marker live); the key comes from the
VULNERS_API_KEY env var or the untracked tests/live.local.toml. Skipped
by default; keep them minimal and read-only.tests/benchmarks/ — pytest-codspeed micro-benchmarks, excluded from the
default run.tests/test_mcp.py — MCP server tests; run in an isolated env
(make cov-mcp) because fastmcp cannot share the default env.Warnings are errors (filterwarnings = ["error"]): tests that intentionally
exercise deprecated shims must opt in locally with pytest.warns(...), never
by weakening the global gate.
VULNERS_API_KEY from the environment in examples; live tests read it
from the environment or tests/live.local.toml (untracked).Good examples: CVE lookup, bulletin lookup, vulnerability search, software audit, Linux/Windows host audit, SBOM audit, CPE lookup, archive streaming, error handling, pagination and rate-limit handling.
Avoid: exploit weaponization or execution (exploit metadata search is fine), credential harvesting, unapproved scanning of third-party targets, examples that disclose real infrastructure details.
A change is ready when:
make check passes.make cov stays at 100% for the v4 core; make unasync-check is clean.make docs builds strictly with no warnings.© vulnersCom, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts, references) in .agents/skills/vulners-api of vulnersCom/api.
Open the folder on GitHubat commit e708afc
Vulners API Python SDK next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vulners API Python SDK this skillvulnersCom/api | 375 | — | ~2.3k | Automated safety check: Pass | MIT | |
| Skill InspectorNVIDIA/SkillSpector | 20k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Cyber NeoHainrixz/cyber-neo | 281 | — | ~5.9k | Automated safety check: Warn | MIT | |
| npm Supply Chain Checkmajiayu000/spellbook | 286 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Sca TrivyAgentSecOps/SecOpsAgentKit | 219 | 2 repos | ~3.7k | Automated safety check: Pass | Custom licence | |
| Agent BomLeoYeAI/openclaw-master-skills | 2.2k | — | ~4.4k | Automated safety check: Pass | Apache-2.0 |
NVIDIA/SkillSpector
Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.
Hainrixz/cyber-neo
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
majiayu000/spellbook
Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
LeoYeAI/openclaw-master-skills
Open security platform for agentic infrastructure — broad scanning plus MCP discovery, CVEs, blast radius, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS…
harness/harness-skills
Manage Harness Artifact Registry (AR) via MCP. An agent skill from harness/harness-skills.
Works with
Categories
A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK. Vulners API Python SDK is an agent skill from vulnersCom/api. Use when modifying, testing, documenting, or reviewing the Vulners Python SDK.
Vulners API Python SDK fits situations like: reviewing the Vulners Python SDK; tasks that involve Vulnerability scanning; tasks that involve Project scaffolding.
Run `npx skills add vulnersCom/api --skill vulners-api-python-sdk -a claude-code`. Or copy the skill folder (.agents/skills/vulners-api in vulnersCom/api) into .claude/skills/vulners-api-python-sdk in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vulnersCom/api --skill vulners-api-python-sdk -a codex`. Or copy the skill folder (.agents/skills/vulners-api in vulnersCom/api) into .agents/skills/vulners-api-python-sdk in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vulnersCom/api --skill vulners-api-python-sdk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vulners-api-python-sdk, .gemini/skills/vulners-api-python-sdk, .github/skills/vulners-api-python-sdk and .opencode/skills/vulners-api-python-sdk in your project.
Going by SKILL.md and its folder, Vulners API Python SDK needs Python for the scripts in its folder, the command-line tools its instructions call (make, uv and python) and credentials named VULNERS_API_KEY. Our summary lists: Python 3; A credential in VULNERS_API_KEY.
SKILL.md names 1 domain. As links in the text: docs.astral.sh. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Vulners API Python SDK is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Vulners API Python SDK: Skill Inspector (NVIDIA/SkillSpector, 20k stars), Cyber Neo (Hainrixz/cyber-neo, 281 stars), npm Supply Chain Check (majiayu000/spellbook, 286 stars) and Sca Trivy (AgentSecOps/SecOpsAgentKit, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vulnersCom (a GitHub user) maintains it in vulnersCom/api, which has 375 GitHub stars. The repository was last updated on September 28, 2026.
Source: vulnersCom/api on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.