It queries OSV.dev first for speed and accuracy, cross-checks NVD for CVSS scoring, uses Exa
for recent advisories, and checks GitHub Advisory for maintainer responses, then
cross-references findings and prioritizes by CVSS score and exploitability — CRITICAL
(9.0-10.0) fixed immediately, HIGH (7.0-8.9) before merge, MEDIUM (4.0-6.9) planned, LOW
(0.1-3.9) documented — reporting fix versions and workarounds.
Out of scope: this is a single-dependency lookup, not a full project dependency sweep (use
dependency-audit for that).
CVE Research Skill
Overview
Research known vulnerabilities for project dependencies using multiple sources.
Data Sources
| Source |
API |
Coverage |
| NVD |
nvd.nist.gov/vuln/api |
All CVEs |
| OSV.dev |
api.osv.dev |
npm, PyPI, Go, crates, Maven |
| GitHub Advisory |
github.com/advisories |
npm, pip, composer, cargo |
| Exa Search |
Via MCP |
Real-time web search |
Workflow
- Extract dependencies from project (package.json, etc.)
- Query each source for known CVEs
- Cross-reference findings across sources
- Prioritize by CVSS score and exploitability
- Report with fix versions and workarounds
Query Strategy
For each dependency:
- Search OSV.dev first (fastest, most accurate for packages)
- Cross-check NVD for CVSS scoring
- Use Exa for recent advisories not yet in databases
- Check GitHub Advisory for maintainer responses
Severity Mapping
| CVSS Score |
Severity |
Action |
| 9.0 - 10.0 |
CRITICAL |
Fix immediately |
| 7.0 - 8.9 |
HIGH |
Fix before merge |
| 4.0 - 6.9 |
MEDIUM |
Plan fix |
| 0.1 - 3.9 |
LOW |
Document |
References
- CVE APIs Reference
- Query Templates
1---2name: cve-research3description: Use when checking a specific dependency or package version for known CVEs and security advisories.4---56<objective>7This skill researches known vulnerabilities for a specific dependency across multiple8sources: OSV.dev (npm, PyPI, Go, crates, Maven), NVD (CVSS scoring), GitHub Advisory9Database (maintainer responses), and Exa web search for advisories not yet indexed.1011It queries OSV.dev first for speed and accuracy, cross-checks NVD for CVSS scoring, uses Exa12for recent advisories, and checks GitHub Advisory for maintainer responses, then13cross-references findings and prioritizes by CVSS score and exploitability — CRITICAL14(9.0-10.0) fixed immediately, HIGH (7.0-8.9) before merge, MEDIUM (4.0-6.9) planned, LOW15(0.1-3.9) documented — reporting fix versions and workarounds.1617Out of scope: this is a single-dependency lookup, not a full project dependency sweep (use18dependency-audit for that).19</objective>2021# CVE Research Skill2223## Overview2425Research known vulnerabilities for project dependencies using multiple sources.2627## Data Sources2829| Source | API | Coverage |30|--------|-----|----------|31| NVD | nvd.nist.gov/vuln/api | All CVEs |32| OSV.dev | api.osv.dev | npm, PyPI, Go, crates, Maven |33| GitHub Advisory | github.com/advisories | npm, pip, composer, cargo |34| Exa Search | Via MCP | Real-time web search |3536## Workflow37381. **Extract** dependencies from project (package.json, etc.)392. **Query** each source for known CVEs403. **Cross-reference** findings across sources414. **Prioritize** by CVSS score and exploitability425. **Report** with fix versions and workarounds4344## Query Strategy4546For each dependency:471. Search OSV.dev first (fastest, most accurate for packages)482. Cross-check NVD for CVSS scoring493. Use Exa for recent advisories not yet in databases504. Check GitHub Advisory for maintainer responses5152## Severity Mapping5354| CVSS Score | Severity | Action |55|------------|----------|--------|56| 9.0 - 10.0 | CRITICAL | Fix immediately |57| 7.0 - 8.9 | HIGH | Fix before merge |58| 4.0 - 6.9 | MEDIUM | Plan fix |59| 0.1 - 3.9 | LOW | Document |6061## References6263- [CVE APIs Reference](references/cve-apis.md)64- [Query Templates](references/templates/cve-query.md)