# Zenodefault Codesentinel Skills Cve Sweep

> cve-sweep

- Skill: `aibot88/zenodefault-codesentinel-skills-cve-sweep` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add aibot88/zenodefault-codesentinel-skills-cve-sweep`
- Raw SKILL.md: https://api.skillmd.com/api/skills/aibot88/zenodefault-codesentinel-skills-cve-sweep/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: aibot88 (https://skillmd.com/u/aibot88)
- Updated: 2026-09-21
- Page: https://skillmd.com/skills/aibot88/zenodefault-codesentinel-skills-cve-sweep

---

# cve-sweep

## Purpose

Scan a repository for vulnerable dependencies and write the results into Durable Memory.

## Inputs

- `repoPath`: absolute or relative path to a local repository
- `repoUrl`: optional git URL; if provided, the skill clones it into a temp workspace first

## Behavior

1. Detect the project ecosystem by locating `package.json`, `requirements.txt`, or `Cargo.toml`.
2. Parse direct dependencies from the manifest.
3. Query:
   - NVD REST API v2.0
   - GitHub Advisory Database via GraphQL
4. Return a structured result with dependency metadata and advisories.

## Environment

- `GITHUB_TOKEN`: optional but recommended for GitHub Advisory GraphQL calls
- `NVD_API_KEY`: optional; used when available to improve NVD rate limits

## Output

- Structured JSON to stdout when run from the CLI
- Durable Memory updates when invoked through the orchestrator

