本文へ移動
cccskills
無料GitHub で公開

dashboard

Show what this repository has already decided about its vulnerabilities, read from the durable record rather than by scanning again — open versus resolved, the decision taken on each, and what is still waiting. Use when picking up triage after a break, auditing past decisions, onboarding to a repository with security history, or checking nothing high-severity is open before a release.

インストール方法を見る

含まれるファイル(3)

  • SKILL.md6.0 KB
  • evals/evals.json2.4 KB
  • evals/trigger-eval.json1.2 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Vulnetix Vulnerability Dashboard

Use when

  • You want a single view of every vulnerability tracked in this repo, grouped by status and decision.
  • Someone asks "where did we leave triage last week?".
  • Onboarding to a repo and you want to see prior security decisions before duplicating work.
  • You want to spot stale under_investigation items that need re-triaging.
  • Pre-release: confirm no high-severity entries remain open before tagging.

Don't use for

  • Fetching new vulnerability data — use repo-impact for whether an advisory reaches this repository, or vulnetix_vuln / vulnetix vdb vuln <id> for the advisory itself.
  • Applying fixes — use fix.
  • Cross-repo dashboards — this skill reads only the current repo's memory file.

Conventions

Follows skills/_lib/contract.md. In short: use the vulnetix_* MCP tools when the agent has them and the CLI otherwise — both shape their own output, so there is no jq step any more. Independent calls go out as concurrent Bash tool calls in one message. One trailing suggestion, not a playbook. See the contract for surface selection, output style and memory writes.

This skill reads .vulnetix/memory.yaml and displays a comprehensive vulnerability status report. It is read-only and does not modify any files.

Workflow

Step 1: Load Memory

  1. Use Glob to check if .vulnetix/memory.yaml exists in the repo root
  2. If it does not exist, display: "No vulnerability data found. Run repo-impact <CVE-…> or vulnetix_exploits (MCP) to start tracking." and stop.
  3. Use Read to load the full contents of .vulnetix/memory.yaml

Step 2: Parse and Categorize

From the vulnerabilities: section, categorize each entry:

Open (unresolved):

  • status: affected -- "Vulnerable"
  • status: under_investigation -- "Investigating"

Resolved:

  • status: fixed -- "Fixed"
  • status: not_affected -- "Not affected"
  • Entries with decision.choice: risk-accepted -- "Risk accepted"
  • Entries with decision.choice: deferred -- "Deferred"

From the manifests: section, collect manifest tracking info.

Step 3: Display Summary Header

Vulnetix Security Dashboard
============================
Open: <N> (<X> vulnerable, <Y> investigating)
Resolved: <N> (<X> fixed, <Y> not affected, <Z> risk-accepted, <W> deferred)
Manifests tracked: <N> (last scan: <timestamp>)

If there are zero vulnerabilities and zero manifests, display: "Clean slate -- no vulnerabilities tracked yet."

Step 4: Open Vulnerabilities Table

If there are open vulnerabilities, display them sorted by CWSS priority (P1 first), then by severity:

Open Vulnerabilities
--------------------
| ID | Package | Severity | Status | Priority | Decision |
|----|---------|----------|--------|----------|----------|
| CVE-2021-44228 | log4j-core | critical | Vulnerable | P1 (87.5) | investigating |
| GHSA-xxxx-yyyy | express | high | Investigating | P2 (62.0) | investigating |

For each column:

  • ID: Primary vulnerability key
  • Package: package field
  • Severity: severity field
  • Status: Developer-friendly status (see VEX mapping above)
  • Priority: cwss.priority and cwss.score if available, otherwise "--"
  • Decision: decision.choice if available, otherwise "--"

Step 5: Resolved Vulnerabilities Table

If there are resolved vulnerabilities, display them:

Resolved Vulnerabilities
------------------------
| ID | Package | Severity | Resolution | Decision | Date |
|----|---------|----------|------------|----------|------|
| CVE-2023-1234 | lodash | high | Fixed | fix-applied | 2024-01-15 |

For the Date column, use the most recent history entry timestamp, or discovery.date as fallback.

Step 6: Manifest Tracking

If manifests are tracked, display:

Tracked Manifests
-----------------
| Manifest | Ecosystem | Last Scanned | Vulns Found |
|----------|-----------|--------------|-------------|
| package.json | npm | 2024-01-15T10:30:00Z | 3 |
| go.mod | go | 2024-01-15T10:31:00Z | 0 |

Step 7: Suggested Actions

For each open vulnerability (up to 5), suggest a next action based on its state:

  • Has no threat_model or cwss: "vulnetix vdb exploits <id>" -- get exploit analysis and priority scoring
  • Has cwss but no fix applied: "fix <id>" -- get fix intelligence
  • Has decision risk-accepted, deferred, or mitigated (non-patch): "vulnetix vdb traffic-filters <id>" -- get Snort rules for network-level mitigation
  • General: "fix <id>" -- get a full remediation plan

If there are more than 5 open vulns, add: "Use vulnetix vdb exploits to find exploited vulnerabilities across your ecosystem."

Always end with: "Use vulnetix vdb vuln <id> for detailed info on any vulnerability."

Edge cases & gotchas

  • Reads .vulnetix/memory.yaml only. If the file is missing, the skill exits silently — run repo-impact or vulnetix_vuln (MCP) or vulnetix vdb vuln <id> first to populate.
  • decision.choice is a closed enum; entries with arbitrary strings render under "Unknown decision".
  • Mermaid pie chart of decisions is auto-skipped if the total is < 3 (avoids rendering near-empty visuals).
  • For repos with > 200 tracked vulns, the dashboard caps the table at 50 rows sorted by CWSS — full list is in memory.yaml.
  • CWSS scores can be missing for entries that were created by vulnetix_vuln (MCP) or vulnetix vdb vuln <id> lookup-only mode; the dashboard sorts those to the bottom.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Dockerfile / Containerfile / compose analysis plus optional Trivy / Grype / Syft composition when those binaries are present. Use when reviewing a Dockerfile PR, gating `docker build`, building an image SBOM, evaluating base-image risk, or auditing a registry image for CVEs.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Dependency-conflict resolution when a `fix` version bump fails — diagnose the peer-dep tree, find a compatible safe version set, propose package-manager overrides (`overrides`/`resolutions`/`replace`/`[patch]`), fall back to safe-harbour inline patching. Use when an upgrade is blocked by transitive constraints, a peer-dep conflict surfaces, or you need to override a vulnerable transitive without bumping the parent.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Work through which package to add for a capability, and what each option costs — maintenance, licence, bundle weight, transitive risk, and whether the platform already does it. Use when someone needs a library for a job and has not picked one yet, when weighing two candidates, or when a package looks convenient but unmaintained.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

IDS/IPS detection content for a CVE — Snort/Suricata-compatible rules, YARA signatures, ProjectDiscovery Nuclei templates, traffic-filter rules. Capability-aware: skips families when the binary is not installed (no Snort = no Snort output). Use when deploying defences for a CVE without a patch, augmenting SAST with active detection, or feeding the SOC engineering pipeline.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

eol-check

無料

End-of-life detection for runtimes (Node, Python, Java, Go, .NET) and key packages — surfaces past-EOL items, items reaching EOL within 90 days, and EOL base images for containers. Use when planning a runtime upgrade, auditing for unsupported versions, gating a deploy against EOL deps, or producing a remediation roadmap.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Generate a runnable exploit-validation command (Nuclei template, Metasploit module hint, AI-assisted Python script, or curl-based PoC) against a user-specified authorised target. Use when validating that a fix actually closed the vulnerability path, confirming a patch deployed correctly, or producing a copy-pasteable test command for QA. The skill never executes — the user runs.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Vulnetix のスキルをすべて見る

このスキルの問題を報告する