Zenodefault Codesentinel Skills Cve Sweep

cve-sweep

aibot88 Updated 3 repo stars

File contents

cve-sweep

Purpose

Scan a repository for vulnerable dependencies and write the results into Durable Memory.

Inputs

  • repoPath: absolute or relative path to a local repository
  • repoUrl: optional git URL; if provided, the skill clones it into a temp workspace first

Behavior

  1. Detect the project ecosystem by locating package.json, requirements.txt, or Cargo.toml.
  2. Parse direct dependencies from the manifest.
  3. Query:
    • NVD REST API v2.0
    • GitHub Advisory Database via GraphQL
  4. Return a structured result with dependency metadata and advisories.

Environment

  • GITHUB_TOKEN: optional but recommended for GitHub Advisory GraphQL calls
  • NVD_API_KEY: optional; used when available to improve NVD rate limits

Output

  • Structured JSON to stdout when run from the CLI
  • Durable Memory updates when invoked through the orchestrator

aibot88/sec_skill_store/tree/main/skills/github/zenodefault-codesentinel-skills-cve-sweep commit 5e3df04f5a

Frequently asked questions

npx skillmds@latest add aibot88/zenodefault-codesentinel-skills-cve-sweep