Advisory Mining -- Finding Incomplete Fixes

SkillDatabases & data

Mine GitHub Security Advisories and CVE databases for incomplete fixes, finding variant vulnerabilities in patched code or similar patterns in related packages.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Advisory Mining -- Finding Incomplete Fixes skill

What this skill tells your AI

The instructions your AI receives, as published by byamb4/find-cve-agent in skills/advisory-mining/SKILL.md and read by ahel’s review.

When to Use

Looking for high-acceptance-rate findings. Incomplete fix variants have ~95% acceptance rate because:

  1. The vulnerability class is already acknowledged
  2. The fix proves the maintainer cares about security
  3. The variant proves the fix was insufficient

Process

Step 1: Find Recent Advisories

# GitHub Advisory API -- recent npm advisories
gh api graphql -f query='
{
  securityAdvisories(first: 20, orderBy: {field: PUBLISHED_AT, direction: DESC}, ecosystem: NPM) {
    nodes {
      ghsaId
      summary
      severity
      publishedAt
      vulnerabilities(first: 5) {
        nodes {
          package { name ecosystem }
          vulnerableVersionRange
          firstPatchedVersion { identifier }
        }
      }
    }
  }
}'

# Search by keyword
gh api "/advisories?ecosystem=npm&keyword=injection&per_page=20"
gh api "/advisories?ecosystem=pip&keyword=traversal&per_page=20"

Step 2: Read the Patch Diff

For each advisory:

  1. Find the fix commit (linked in the advisory or CHANGELOG)
  2. Read the diff carefully
  3. Ask: what did they fix? What did they NOT fix?
# Find security-related commits
git log --oneline --all | grep -i "security\|fix\|vuln\|CVE\|patch\|sanitize"

# Read the patch
git show <commit_hash>
git diff <before_commit>..<fix_commit>

Step 3: Check for Incomplete Fix Patterns

Common incomplete fixes:

What Was FixedWhat Was Missed
../ blocked..\ not blocked (Windows)
__proto__ filteredconstructor.prototype not filtered
One regex fixedSimilar regex in same file not fixed
One function fixedWrapper function calls it differently
Parsing fixedSerialization has same bug
Validation addedCan be bypassed with encoding
One entry point fixedOther entry points not covered
Input sanitizedError messages leak unsanitized data

Step 4: Search for Same Pattern in Other Packages

If the vulnerability is in a common pattern (e.g., path.join without validation), search for it in similar packages:

# Use grep.app to find same pattern across repos
# See cross-pollination skill for details

Step 5: Verify the Variant

Apply the fp-check skill to verify the variant is real before submitting.

NVD API

# Search NVD for CVEs by keyword
curl "https://services.nvd.nist.gov/rest/json/cves/2.0?keywordSearch=xml+parser+javascript"

# Search by CPE
curl "https://services.nvd.nist.gov/rest/json/cves/2.0?cpeName=cpe:2.3:a:vendor:product:*"

CVSS Guidance

Variant findings typically get:

  • Same CVSS as original if the variant has same impact
  • Higher CVSS if the variant bypasses the fix AND adds new impact
  • Lower CVSS if the variant has additional prerequisites

References

Signals

GitHub stars
50
Forks
9
Last commit
Mar 2026
Advanced
Catalog kind
skill
Gateway key
advisory-mining
Source
github.com/byamb4/find-cve-agent