AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Cve Triage

skill-netw0rknoob-vulnclaw-cve-triage · by Netw0rkNoob

CVE lookup and triage — map discovered services/versions to known CVEs via the cve_lookup tool, score by CVSS/exploitability, and prioritize what to verify first.

No reviews yet
0 installs
0 views
view→install

Install

$ agentstack add skill-netw0rknoob-vulnclaw-cve-triage

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-netw0rknoob-vulnclaw-cve-triage)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
today

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Cve Triage? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

CVE Triage

Turn version/banner evidence from recon into a prioritized, exploitability-aware list of CVEs worth verifying. Use this after fingerprinting a service, when a banner or Server: header reveals a product and version, or whenever the target exposes software with a known version.

The cve_lookup tool

VulnClaw ships a read-only cve_lookup tool backed by NVD:

  • Keyword searchcve_lookup(query="Apache httpd 2.4.49", limit=5) returns

the top CVEs sorted by CVSS, highest first.

  • CVE-ID detailcve_lookup(query="CVE-2021-44228") returns the full record

plus best-effort exploit / PoC repositories discovered on GitHub.

It performs no egress to the target and is safe during recon. Without an NVD_API_KEY it still works (lower rate limit); set one for heavier use.

Workflow

  1. Extract product + version from recon — service banners, Server headers,

JS bundles, login footers, package manifests. A precise version string (OpenSSH 8.2p1, nginx 1.18.0) yields far better matches than a bare name.

  1. Query cve_lookup with " ". Pull the detail record for

any high/critical hit by re-querying its CVE-ID.

  1. Score & prioritize — see references/cve-triage-workflow.md. Rank by CVSS,

then by exploit availability, then by exposure (is the vulnerable surface actually reachable on this target?).

  1. Confirm version applicability — match the target's version against the

CVE's affected cpe range before claiming it. Banner ≠ proof of vulnerability.

  1. Record findings with the CVE-ID, CVSS, and the evidence that maps this

target to it. Mark unconfirmed version-only matches as needs-manual-review, not verified.

Pitfalls

  • A keyword match is a hypothesis, not a finding — version ranges and backported

patches mean a banner version can be patched in place.

  • GitHub "PoC" repos are unverified third-party code; treat as leads, never run

blindly against a target.

  • Prefer the CVSS base score for triage, but let exploit availability and real

exposure override raw score when prioritizing verification effort.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.