Agent skill

Vulners API Python SDK

by vulnersCom in vulnersCom/api

A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.

MITAuto-check passedSecurity

Install Vulners API Python SDK

skills CLI
$ npx skills add vulnersCom/api --skill vulners-api-python-sdk -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vulnersCom/api vulners-api-python-sdk --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vulnersCom/api.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/vulners-api .claude/skills/vulners-api-python-sdk && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vulners-api-python-sdk
GitHub stars
375
Token cost
~2.3k tokens
SKILL.md length
959 words
Files
6 (incl. scripts, references)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.

  • Works in 6 steps: Pick the resource module in… → Declare a module-level RequestSpec for… → Run make unasync to regenerate the sync… → …
  • Reviewing the Vulners Python SDK
  • SKILL.md covers Purpose, Repository context, Architecture and Adding or changing an endpoint…, plus 5 more sections
  • Runs Python scripts from its folder; calls make, uv and python; needs VULNERS_API_KEY

What it does

Vulners API Python SDK is an agent skill from vulnersCom/api. Use when modifying, testing, documenting, or reviewing the Vulners Python SDK. Covers the v4 architecture (typed sync/async clients, resource namespaces, bulletin model hierarchy, unasync codegen), the preserved legacy v3 surface, uv-based tooling, the 100% branch-coverage gate, safe API-key handling, and defensive vulnerability-intelligence examples.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `README.md`, `references/api-overview.md` and `references/repo-layout.md`).

It sits in Security, covering Vulnerability scanning, Project scaffolding and Supply chain security. It works with Python and Model Context Protocol. The repository describes itself as: Official Python SDK for the Vulners vulnerability-intelligence API — search CVEs, exploits and advisories (CVSS/EPSS/KEV), audit software, Linux/Windows hosts and SBOMs, and… The licence is MIT.

When your agent uses it

  • Reviewing the Vulners Python SDK
  • Tasks that involve Vulnerability scanning
  • Tasks that involve Project scaffolding

Example prompts

  • “/vulners-api-python-sdk”

Requirements

  • Python 3
  • A credential in VULNERS_API_KEY

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Pick the resource module in src/vulners/_resources/_async/ by API domain
  2. Declare a module-level RequestSpec for the endpoint and add a typed async
  3. Run make unasync to regenerate the sync mirror.
  4. Add tests (mocked HTTP via respx; no live calls) asserting URL, method,
  5. Document the method (the mkdocs reference picks up docstrings; add how-to
  6. Regenerate api.md if the public surface changed

What it can do on your machine

Read from SKILL.md and the folder at commit e708afc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • make
    • uv
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.astral.sh

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • VULNERS_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vulners API Python SDK loads about 2.3k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 959 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from vulnersCom/api at commit e708afc, republished under its MIT licence (© vulnersCom). 959 words, ~2,308 tokens.

Download SKILL.mdSave it as .claude/skills/vulners-api-python-sdk/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
vulners-api-python-sdk
description
Use when modifying, testing, documenting, or reviewing the Vulners Python SDK. Covers the v4 architecture (typed sync/async clients, resource namespaces, bulletin model hierarchy, unasync codegen), the preserved legacy v3 surface, uv-based tooling, the 100% branch-coverage gate, safe API-key handling, and defensive vulnerability-intelligence examples.

Vulners API Python SDK skill

Purpose

Maintain the Vulners Python API SDK safely and consistently.

Use this skill for:

  • Editing the src/vulners/ package (v4 core or the legacy v3 layer).
  • Adding SDK methods for Vulners API endpoints.
  • Writing or updating tests under tests/.
  • Updating examples in samples/ and documentation under documentation/.
  • Reviewing README changes, release automation, and API-key handling.

Do not use this skill for:

  • Storing or generating real Vulners API keys.
  • Writing exploit weaponization/execution code or operational abuse workflows.
  • Moving non-runtime agent instructions into the src/vulners/ package.

Repository context

This skill is consumed from .agents/skills/vulners-api/SKILL.md by Codex-compatible agent harnesses. This repository is the source of truth for the skill.

Current repository layout (src layout, uv_build backend):

text
api/
├── .agents/skills/vulners-api/   # this skill
├── dev-tools/                    # maintainer tooling (not shipped)
├── documentation/                # mkdocs site source (Material theme)
├── samples/                      # runnable examples: v4/ and legacy/
├── src/vulners/                  # the shipped package
├── tests/                        # pytest suite (core, bc, live, benchmarks)
├── Makefile
├── mkdocs.yml
└── pyproject.toml

Architecture

The primary API is the pair of typed clients in src/vulners/_client.py:

  • Vulners (sync) and AsyncVulners (async), re-exported from the package root.
  • Resources hang off each client as cached_property namespaces: search, audit, archive, misc, report, stix, subscriptions, subscriptions_v4, webhooks, vscanner (which nests licenses, projects, projects.tasks, projects.results).
  • Each resource method declares its endpoint as a module-level RequestSpec (method, path, body mode, unwrap keys, timeout profile, rate-limit group) and routes through one shared request pipeline: credential-safety transport, retries with Retry-After support, and token-bucket rate-limit pacing.
  • client.get/post/put/delete are untyped escape hatches for any API path.

Async is the source of truth. The sync mirror is generated:

  • Hand-write async code in src/vulners/_resources/_async/ (and _transport_client_async.py, _ratelimit_async.py).
  • make unasync regenerates src/vulners/_resources/_sync/ and the sync transport/ratelimit modules via unasyncd (mapping table in [tool.unasyncd] in pyproject.toml). Both sides are committed; make unasync-check gates drift in CI.
  • Never hand-edit generated sync files — edit the async source and regenerate.

Bulletin models (src/vulners/_models/) form a base → family → per-collection hierarchy:

  • Bulletin — fields common to every document (hand-written, bulletin.py).
  • Family models (CveBulletin, ExploitBulletin, …) — one per bulletinFamily, hand-written; construct_bulletin picks the right class.
  • Per-collection models — one per collection type, built lazily by the factory in collections.py from generated data in _collections_data.py.
  • Field descriptions live once in _field_descriptions.py and flow to models and reference docs. Refresh everything against the live API with python dev-tools/data-models/sample_collections.py (needs an API key).

Legacy v3 surface is preserved for backward compatibility: base.py, vscanner.py, and the src/vulners/vulners/ subpackage keep the old VulnersApi / VScannerApi working unchanged (deprecated — new code should use Vulners / AsyncVulners). The v3 layer is frozen: excluded from strict typing and the coverage gate, guarded by the compatibility oracle in tests/bc/. Do not extend it with new features.

An MCP server (vulners-mcp / python -m vulners.mcp) lives in src/vulners/_mcp/, behind the optional mcp extra (fastmcp).

Adding or changing an endpoint (v4)

  1. Pick the resource module in src/vulners/_resources/_async/ by API domain (search.py, audit.py, archive.py, misc.py, report.py, stix.py, subscriptions*.py, webhooks.py, vscanner.py).
  2. Declare a module-level RequestSpec for the endpoint and add a typed async method with a Google-style docstring (args, returns, raises).
  3. Run make unasync to regenerate the sync mirror.
  4. Add tests (mocked HTTP via respx; no live calls) asserting URL, method, body, response parsing, and error paths. The v4 core is held at 100% branch coverage — make cov must stay green.
  5. Document the method (the mkdocs reference picks up docstrings; add how-to material under documentation/ if the method is a common task) and add a sample under samples/v4/ if it is commonly used.
  6. Regenerate api.md if the public surface changed: python dev-tools/generate_api_md.py.

Backward compatibility: breaking changes only deliberately, documented in release notes / CHANGELOG with the intended versioning impact.

Show full SKILL.md (401 more words)Show less

Tooling and quality commands

The project uses uv with PEP 735 dependency groups (uv sync installs the dev toolchain). Python >=3.10; ruff targets py310 — do not use syntax or stdlib APIs unavailable on 3.10. Line length 98.

bash
uv sync                # install project + dev groups
make format            # ruff format + import sorting
make lint              # ruff check + format --check
make typecheck         # mypy + basedpyright
make test              # full pytest suite, parallel (xdist)
make cov               # coverage gate: v4 core at 100% branch coverage
make cov-mcp           # MCP server coverage (isolated env with the mcp extra)
make bc                # backward-compatibility oracle only
make unasync           # regenerate the sync mirror from async sources
make unasync-check     # fail if the committed mirror drifted
make docs              # mkdocs build --strict (any warning fails)
make check             # lint + typecheck + unasync-check + test

uv run pytest tests/<file> runs a single module; make test-fast runs serially for easier debugging.

Testing expectations

Tests live in tests/:

  • tests/core/ and top-level tests/test_*.py — the v4 suite: mocked HTTP (respx), request construction, parsing, retries, rate limiting, streaming, secret handling. Deterministic; never require VULNERS_API_KEY.
  • tests/bc/ — the backward-compatibility oracle pinning the v3 surface and wire behavior against surface.json / golden files.
  • tests/live/ — opt-in live-API tests (marker live); the key comes from the VULNERS_API_KEY env var or the untracked tests/live.local.toml. Skipped by default; keep them minimal and read-only.
  • tests/benchmarks/ — pytest-codspeed micro-benchmarks, excluded from the default run.
  • tests/test_mcp.py — MCP server tests; run in an isolated env (make cov-mcp) because fastmcp cannot share the default env.

Warnings are errors (filterwarnings = ["error"]): tests that intentionally exercise deprecated shims must opt in locally with pytest.warns(...), never by weakening the global gate.

Security rules

  1. Never hardcode API keys, tokens, cookies, or credentials.
  2. Use VULNERS_API_KEY from the environment in examples; live tests read it from the environment or tests/live.local.toml (untracked).
  3. Mock HTTP responses for unit tests; live tests are opt-in and skipped by default.
  4. Do not log API keys or full request headers. The SDK redacts the key in logs, strips it on cross-origin redirects, and keeps it out of reprs — preserve those guarantees when touching transport code.
  5. Do not add offensive exploitation workflows; keep examples focused on defensive vulnerability intelligence.
  6. Avoid committing real customer data, scan output from private systems, or proprietary asset inventories.

Defensive example categories

Good examples: CVE lookup, bulletin lookup, vulnerability search, software audit, Linux/Windows host audit, SBOM audit, CPE lookup, archive streaming, error handling, pagination and rate-limit handling.

Avoid: exploit weaponization or execution (exploit metadata search is fine), credential harvesting, unapproved scanning of third-party targets, examples that disclose real infrastructure details.

Definition of done

A change is ready when:

  • The package imports successfully and make check passes.
  • make cov stays at 100% for the v4 core; make unasync-check is clean.
  • make docs builds strictly with no warnings.
  • No secrets are committed.
  • Public SDK methods have docstrings, docs, and (when commonly used) samples.
  • Live network tests are opt-in only.
  • The v3 compatibility surface is unchanged unless the change is intentionally breaking and documented.

© vulnersCom, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in .agents/skills/vulners-api of vulnersCom/api.

  • SKILL.md
  • README.md
  • references/api-overview.md
  • references/repo-layout.md
  • references/tool-selection.md
  • scripts/smoke_vulners_api.py

Open the folder on GitHubat commit e708afc

Compare with similar skills

Vulners API Python SDK next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vulners API Python SDK compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vulners API Python SDK this skillvulnersCom/api375—~2.3kAutomated safety check: PassMIT
Skill InspectorNVIDIA/SkillSpector20k—~1.8kAutomated safety check: PassApache-2.0
Cyber NeoHainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT
npm Supply Chain Checkmajiayu000/spellbook286—~1.5kAutomated safety check: PassMIT
Sca TrivyAgentSecOps/SecOpsAgentKit2192 repos~3.7kAutomated safety check: PassCustom licence
Agent BomLeoYeAI/openclaw-master-skills2.2k—~4.4kAutomated safety check: PassApache-2.0

Similar skills

  • Skill Inspector

    NVIDIA/SkillSpector

    Official

    Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

    20k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    281 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    286 GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    219 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Agent Bom

    LeoYeAI/openclaw-master-skills

    Open security platform for agentic infrastructure — broad scanning plus MCP discovery, CVEs, blast radius, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS…

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Manage Artifacts

    harness/harness-skills

    Manage Harness Artifact Registry (AR) via MCP. An agent skill from harness/harness-skills.

    115 GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check passed

Categories

Questions about Vulners API Python SDK

What does Vulners API Python SDK do?

A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK. Vulners API Python SDK is an agent skill from vulnersCom/api. Use when modifying, testing, documenting, or reviewing the Vulners Python SDK.

When should I use Vulners API Python SDK?

Vulners API Python SDK fits situations like: reviewing the Vulners Python SDK; tasks that involve Vulnerability scanning; tasks that involve Project scaffolding.

How do I install Vulners API Python SDK in Claude Code?

Run `npx skills add vulnersCom/api --skill vulners-api-python-sdk -a claude-code`. Or copy the skill folder (.agents/skills/vulners-api in vulnersCom/api) into .claude/skills/vulners-api-python-sdk in your project. Claude Code loads it when a task matches its description.

How do I install Vulners API Python SDK in Codex?

Run `npx skills add vulnersCom/api --skill vulners-api-python-sdk -a codex`. Or copy the skill folder (.agents/skills/vulners-api in vulnersCom/api) into .agents/skills/vulners-api-python-sdk in your project. Codex loads it when a task matches its description.

Can I use Vulners API Python SDK in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vulnersCom/api --skill vulners-api-python-sdk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vulners-api-python-sdk, .gemini/skills/vulners-api-python-sdk, .github/skills/vulners-api-python-sdk and .opencode/skills/vulners-api-python-sdk in your project.

What does Vulners API Python SDK need to run?

Going by SKILL.md and its folder, Vulners API Python SDK needs Python for the scripts in its folder, the command-line tools its instructions call (make, uv and python) and credentials named VULNERS_API_KEY. Our summary lists: Python 3; A credential in VULNERS_API_KEY.

Does Vulners API Python SDK access the network?

SKILL.md names 1 domain. As links in the text: docs.astral.sh. This is read from the text; nothing was executed.

Is Vulners API Python SDK safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Vulners API Python SDK use?

Vulners API Python SDK is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vulners API Python SDK use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Vulners API Python SDK?

Skills that share tags, products or a category with Vulners API Python SDK: Skill Inspector (NVIDIA/SkillSpector, 20k stars), Cyber Neo (Hainrixz/cyber-neo, 281 stars), npm Supply Chain Check (majiayu000/spellbook, 286 stars) and Sca Trivy (AgentSecOps/SecOpsAgentKit, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vulners API Python SDK?

vulnersCom (a GitHub user) maintains it in vulnersCom/api, which has 375 GitHub stars. The repository was last updated on September 28, 2026.

Source: vulnersCom/api on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.