Scan a repository for vulnerable dependencies and write the results into Durable Memory.
Inputs
repoPath: absolute or relative path to a local repository
repoUrl: optional git URL; if provided, the skill clones it into a temp workspace first
Behavior
Detect the project ecosystem by locating package.json, requirements.txt, or Cargo.toml.
Parse direct dependencies from the manifest.
Query:
NVD REST API v2.0
GitHub Advisory Database via GraphQL
Return a structured result with dependency metadata and advisories.
Environment
GITHUB_TOKEN: optional but recommended for GitHub Advisory GraphQL calls
NVD_API_KEY: optional; used when available to improve NVD rate limits
Output
Structured JSON to stdout when run from the CLI
Durable Memory updates when invoked through the orchestrator
1---2name: zenodefault-codesentinel-skills-cve-sweep3description: cve-sweep4---5# cve-sweep67## Purpose89Scan a repository for vulnerable dependencies and write the results into Durable Memory.1011## Inputs1213- `repoPath`: absolute or relative path to a local repository14- `repoUrl`: optional git URL; if provided, the skill clones it into a temp workspace first1516## Behavior17181. Detect the project ecosystem by locating `package.json`, `requirements.txt`, or `Cargo.toml`.192. Parse direct dependencies from the manifest.203. Query:21 - NVD REST API v2.022 - GitHub Advisory Database via GraphQL234. Return a structured result with dependency metadata and advisories.2425## Environment2627- `GITHUB_TOKEN`: optional but recommended for GitHub Advisory GraphQL calls28- `NVD_API_KEY`: optional; used when available to improve NVD rate limits2930## Output3132- Structured JSON to stdout when run from the CLI33- Durable Memory updates when invoked through the orchestrator
Run npx skillmds@latest add aibot88/zenodefault-codesentinel-skills-cve-sweep in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
cve-sweep It is listed under Coding & Dev Tools on SkillMD.
This skill has not completed SkillMD's automated safety review yet. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
aibot88 (@aibot88) published this skill. Their other Agent Skills are listed on their SkillMD profile.