cve-research

SkillSecurity

Use when checking a specific dependency or package version for known CVEs and security advisories.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the cve-research skill

What this skill tells your AI

The instructions your AI receives, as published by fusengine/agents in plugins/security-expert/skills/cve-research/SKILL.md and read by ahel’s review.

It queries OSV.dev first for speed and accuracy, cross-checks NVD for CVSS scoring, uses Exa for recent advisories, and checks GitHub Advisory for maintainer responses, then cross-references findings and prioritizes by CVSS score and exploitability — CRITICAL (9.0-10.0) fixed immediately, HIGH (7.0-8.9) before merge, MEDIUM (4.0-6.9) planned, LOW (0.1-3.9) documented — reporting fix versions and workarounds.

Out of scope: this is a single-dependency lookup, not a full project dependency sweep (use dependency-audit for that).

CVE Research Skill

Overview

Research known vulnerabilities for project dependencies using multiple sources.

Data Sources

SourceAPICoverage
NVDnvd.nist.gov/vuln/apiAll CVEs
OSV.devapi.osv.devnpm, PyPI, Go, crates, Maven
GitHub Advisorygithub.com/advisoriesnpm, pip, composer, cargo
Exa SearchVia MCPReal-time web search

Workflow

  1. Extract dependencies from project (package.json, etc.)
  2. Query each source for known CVEs
  3. Cross-reference findings across sources
  4. Prioritize by CVSS score and exploitability
  5. Report with fix versions and workarounds

Query Strategy

For each dependency:

  1. Search OSV.dev first (fastest, most accurate for packages)
  2. Cross-check NVD for CVSS scoring
  3. Use Exa for recent advisories not yet in databases
  4. Check GitHub Advisory for maintainer responses

Severity Mapping

CVSS ScoreSeverityAction
9.0 - 10.0CRITICALFix immediately
7.0 - 8.9HIGHFix before merge
4.0 - 6.9MEDIUMPlan fix
0.1 - 3.9LOWDocument

References

Signals

GitHub stars
25
Forks
4
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
cve-research
Source
github.com/fusengine/agents