本文へ移動
cccskills
無料GitHub で公開

advisory-mining

Mine GitHub Security Advisories and CVE databases for incomplete fixes, finding variant vulnerabilities in patched code or similar patterns in related packages.

インストール方法を見る

含まれるファイル(3)

  • SKILL.md3.3 KB
  • references/diff-analysis.md1.8 KB
  • references/ghsa-api.md2.0 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Advisory Mining -- Finding Incomplete Fixes

When to Use

Looking for high-acceptance-rate findings. Incomplete fix variants have ~95% acceptance rate because:

  1. The vulnerability class is already acknowledged
  2. The fix proves the maintainer cares about security
  3. The variant proves the fix was insufficient

Process

Step 1: Find Recent Advisories

# GitHub Advisory API -- recent npm advisories
gh api graphql -f query='
{
  securityAdvisories(first: 20, orderBy: {field: PUBLISHED_AT, direction: DESC}, ecosystem: NPM) {
    nodes {
      ghsaId
      summary
      severity
      publishedAt
      vulnerabilities(first: 5) {
        nodes {
          package { name ecosystem }
          vulnerableVersionRange
          firstPatchedVersion { identifier }
        }
      }
    }
  }
}'

# Search by keyword
gh api "/advisories?ecosystem=npm&keyword=injection&per_page=20"
gh api "/advisories?ecosystem=pip&keyword=traversal&per_page=20"

Step 2: Read the Patch Diff

For each advisory:

  1. Find the fix commit (linked in the advisory or CHANGELOG)
  2. Read the diff carefully
  3. Ask: what did they fix? What did they NOT fix?
# Find security-related commits
git log --oneline --all | grep -i "security\|fix\|vuln\|CVE\|patch\|sanitize"

# Read the patch
git show <commit_hash>
git diff <before_commit>..<fix_commit>

Step 3: Check for Incomplete Fix Patterns

Common incomplete fixes:

What Was FixedWhat Was Missed
../ blocked..\ not blocked (Windows)
__proto__ filteredconstructor.prototype not filtered
One regex fixedSimilar regex in same file not fixed
One function fixedWrapper function calls it differently
Parsing fixedSerialization has same bug
Validation addedCan be bypassed with encoding
One entry point fixedOther entry points not covered
Input sanitizedError messages leak unsanitized data

Step 4: Search for Same Pattern in Other Packages

If the vulnerability is in a common pattern (e.g., path.join without validation), search for it in similar packages:

# Use grep.app to find same pattern across repos
# See cross-pollination skill for details

Step 5: Verify the Variant

Apply the fp-check skill to verify the variant is real before submitting.

NVD API

# Search NVD for CVEs by keyword
curl "https://services.nvd.nist.gov/rest/json/cves/2.0?keywordSearch=xml+parser+javascript"

# Search by CPE
curl "https://services.nvd.nist.gov/rest/json/cves/2.0?cpeName=cpe:2.3:a:vendor:product:*"

CVSS Guidance

Variant findings typically get:

  • Same CVSS as original if the variant has same impact
  • Higher CVSS if the variant bypasses the fix AND adds new impact
  • Lower CVSS if the variant has additional prerequisites

References

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

You are helping a penetration tester exploit misconfigured Active Directory

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

You are helping a penetration tester enumerate an Active Directory domain and

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

You are helping a penetration tester establish persistent access in Active

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

You are helping a penetration tester exploit ADCS through template/CA access

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

You are helping a penetration tester establish persistence through AD CS

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

You are helping a penetration tester exploit misconfigured AD CS certificate

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

ajtazer のスキルをすべて見る

このスキルの問題を報告する