Daily Cve Digest

Daily scheduled agent. Polls CVE / advisory feeds (GHSA, OSV.dev, NVD) for the past 24 hours, matches against the org's declared stack in `./stack.yml`, and produces a severity-prioritized digest. Each item carries first-response SLA, remediation SLA, and a "what Dependabot will/won't catch" line — Dependabot covers direct dependency CVEs but misses ecosystem-level signals (base-image advisories, transitive depths Dependabot doesn't reach, supply-chain attack disclosures). Runs weekday mornings; outputs to vault/digests/daily/YYYY-MM-DD-daily-cve-digest.md. Use when the user asks to run the CVE or vulnerability digest, or to see what new CVEs or advisories hit the org's stack in the last day — and on its weekday-morning schedule.

themarmack Updated

File contents

themarmack/research-bot/tree/main/.claude/skills/daily-cve-digest commit 1b60dd1469

Frequently asked questions

npx skillmds@latest add themarmack/daily-cve-digest