本文へ移動
cccskills
無料GitHub で公開

detection-rules

IDS/IPS detection content for a CVE — Snort/Suricata-compatible rules, YARA signatures, ProjectDiscovery Nuclei templates, traffic-filter rules. Capability-aware: skips families when the binary is not installed (no Snort = no Snort output). Use when deploying defences for a CVE without a patch, augmenting SAST with active detection, or feeding the SOC engineering pipeline.

インストール方法を見る

含まれるファイル(3)

  • SKILL.md4.7 KB
  • evals/evals.json2.7 KB
  • evals/trigger-eval.json1.4 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Vulnetix Detection Rules Skill

Use when

  • A CVE has no patch yet and you need detection-only mitigation.
  • Augmenting SAST with active runtime detection (Snort/Suricata).
  • Feeding the SOC engineering pipeline with rule files.
  • Building a Nuclei scan template for an authorised target assessment.
  • Hardening a YARA ruleset against a newly-discovered malware family.

Don't use for

  • Executing the rules — this skill writes files; the user runs the engine.
  • Patching the underlying issue — use fix.
  • Single-CVE enrichment — use vulnetix_vuln (MCP) or vulnetix vdb vuln <id>.

Conventions

Follows skills/_lib/contract.md. In short: use the vulnetix_* MCP tools when the agent has them and the CLI otherwise — both shape their own output, so there is no jq step any more. Independent calls go out as concurrent Bash tool calls in one message. One trailing suggestion, not a playbook. See the contract for surface selection, output style and memory writes.

Pulls IDS/IPS, malware-detection, and active-scan content for a CVE. Capability-aware: only fetches rule families the user can actually use.

Step 1: Load capabilities

Read .vulnetix/capabilities.yaml. Capture derived.detection_stack. If empty, prompt:

No detection tooling found (snort, suricata, yara, nuclei, semgrep). I can still fetch the raw rules — proceed?

If the user accepts, treat the stack as [snort, yara, nuclei] for completeness. Otherwise abort with a one-liner pointing at install docs.

Step 2: Fetch each available family

For each family in detection_stack:

# Snort/Suricata
vulnetix vdb snort-rules get "$ARGUMENTS" -o json
vulnetix vdb traffic-filters "$ARGUMENTS" -o json

# YARA
vulnetix vdb yara-rules get "$ARGUMENTS" -o json

# Nuclei
vulnetix vdb nuclei get "$ARGUMENTS" -o json

Skip families absent from detection_stack to avoid wasted API calls.

Step 3: Save rule files (raw form)

Write rule content to .vulnetix/detection/<VULN_ID>/:

  • snort.rules (concat of all Snort rule bodies)
  • suricata.rules (if family present)
  • vuln.yar (concat of YARA rules)
  • nuclei-<id>.yaml (one per template)

Use --format rules / --format yaml against the same subcommand:

vulnetix vdb snort-rules list --cve-id "$ARGUMENTS" --format rules > .vulnetix/detection/$ARGUMENTS/snort.rules
vulnetix vdb yara-rules list --cve-id "$ARGUMENTS" --format rules > .vulnetix/detection/$ARGUMENTS/vuln.yar
vulnetix vdb nuclei get "$ARGUMENTS" --format yaml > .vulnetix/detection/$ARGUMENTS/nuclei.yaml

Step 4: Render report

For each family, list:

  • Rule count + highest signature severity
  • File path on disk
  • A copy-pasteable invocation hint based on installed binaries:
    • snort -c snort.conf -A console (only if binaries.snort: true)
    • yara vuln.yar /path/to/scan (only if binaries.yara: true)
    • nuclei -t .vulnetix/detection/$ARGUMENTS/nuclei.yaml -u <target> (only if binaries.nuclei: true)

Step 5: Memory update

Append event: detection-rules with counts per family to the vuln entry.

Notes

  • This skill never executes rules. The user (or exploit-test) runs them.
  • Filter is honest: if YARA is missing, the YARA section is omitted from the report and from disk writes.

Edge cases & gotchas

  • Each family is fetched ONLY if the binary is in derived.detection_stack. Override by passing --force if you want raw rule output regardless.
  • vdb snort-rules, vdb yara-rules, vdb nuclei accept --format rules|yaml for non-JSON output (the engine's native format).
  • Some CVEs return zero rules across all families — that means no community detection content exists, not that the skill failed.
  • YARA rules can have multiple hash-only matchers; if your YARA build was compiled without hash-module support, those rules fail silently.
  • Nuclei templates require a target URL/IP at invocation time; the skill produces the template, not the scan.
  • vdb traffic-filters <id> returns Snort-format rules tagged for Suricata compatibility — confirm Suricata accepts the rule before deploying to Suricata.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Dockerfile / Containerfile / compose analysis plus optional Trivy / Grype / Syft composition when those binaries are present. Use when reviewing a Dockerfile PR, gating `docker build`, building an image SBOM, evaluating base-image risk, or auditing a registry image for CVEs.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

dashboard

無料

Show what this repository has already decided about its vulnerabilities, read from the durable record rather than by scanning again — open versus resolved, the decision taken on each, and what is still waiting. Use when picking up triage after a break, auditing past decisions, onboarding to a repository with security history, or checking nothing high-severity is open before a release.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Dependency-conflict resolution when a `fix` version bump fails — diagnose the peer-dep tree, find a compatible safe version set, propose package-manager overrides (`overrides`/`resolutions`/`replace`/`[patch]`), fall back to safe-harbour inline patching. Use when an upgrade is blocked by transitive constraints, a peer-dep conflict surfaces, or you need to override a vulnerable transitive without bumping the parent.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Work through which package to add for a capability, and what each option costs — maintenance, licence, bundle weight, transitive risk, and whether the platform already does it. Use when someone needs a library for a job and has not picked one yet, when weighing two candidates, or when a package looks convenient but unmaintained.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

eol-check

無料

End-of-life detection for runtimes (Node, Python, Java, Go, .NET) and key packages — surfaces past-EOL items, items reaching EOL within 90 days, and EOL base images for containers. Use when planning a runtime upgrade, auditing for unsupported versions, gating a deploy against EOL deps, or producing a remediation roadmap.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Generate a runnable exploit-validation command (Nuclei template, Metasploit module hint, AI-assisted Python script, or curl-based PoC) against a user-specified authorised target. Use when validating that a fix actually closed the vulnerability path, confirming a patch deployed correctly, or producing a copy-pasteable test command for QA. The skill never executes — the user runs.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Vulnetix のスキルをすべて見る

このスキルの問題を報告する