agent-bom vulnerability intel

👤 msaad00 📦 v0.96.3 ⭐ 4.3 ⬇️ 2.4K 下載
🔒 IT運維與安全 免費

📖 技能介紹

agent-bom-vulnerability-intel

Use this skill to answer vulnerability-intelligence questions through agent-bom's existing scanners and canonical evidence model. Do not create one-off OSV, GHSA, NVD, EPSS, or KEV clients in the agent session; route through agent-bom so advisory provenance, aliases, severity gates, cache behavior, redaction, and output schemas stay consistent.

Modes

Start with the smallest mode that answers the user:

想要更強大的技能外掛,就來小蔥技能站7w4.net看看吧。

Mode Use When Data Boundary
explain-only User wants to know what would be queried No advisory calls
check-package User names one package/version/ecosystem Only that package identifier is queried
scan-local User wants findings from local agents or a local inventory file Local parse first; advisory calls use package identifiers only
offline-review Private package names cannot leave the environment Use local/cache-approved data only; disclose reduced coverage
export User wants PR gate, SARIF, JSON, or audit evidence Write only to an operator-selected path

Guardrails

  • Ask before scanning a broad filesystem path or local agent configs.
  • Do not paste or reveal NVD_API_KEY, GITHUB_TOKEN, package-registry credentials, cloud credentials, or env values.
  • Do not send full source files, lockfiles, config contents, secrets, or scan reports to advisory providers. agent-bom extracts package identifiers first.
  • Treat unknown or unresolvable versions as coverage gaps, not clean results.
  • Preserve advisory provenance. Do not collapse OSV, GHSA, NVD, EPSS, and KEV into a single unlabelled severity.
  • Do not modify dependencies or install fixes unless the user explicitly asks for a remediation workflow.

Workflows

Explain the Boundary

When the user asks "what leaves my environment?", answer before running:

This lookup sends package identifiers (name, version, ecosystem/PURL) and CVE
IDs to public advisory databases. It does not send source code, raw configs,
secrets, env values, credentials, or full scan reports. Use offline-review if
private package names are sensitive.

Check One Package

agent-bom check flask==2.0.0 --ecosystem pypi

Use this for quick triage and fix-version checks. If the package name belongs to a private registry or internal project, use explain-only first and let the operator decide whether the identifier may be queried externally.

Scan a Canonical Inventory

agent-bom scan --inventory inventory.json --format json --output findings.json

Use this after an operator-pull adapter or discovery skill emits canonical inventory. The inventory can stop at the file boundary; scanning is an explicit operator handoff.

Export for a PR Gate

agent-bom scan --inventory inventory.json --format sarif --output agent-bom.sarif

Use SARIF only when the user wants GitHub code-scanning or AppSec PR-gate evidence. Keep JSON for local analysis and audit trails.

Offline Review

If external advisory calls are not allowed, run with the project's offline or cache-approved mode and say clearly that coverage depends on the locally available vulnerability database. Do not call a clean offline result equivalent to a fresh OSV/GHSA/NVD lookup.

Output Rules

  • Show CVE/GHSA/PYSEC aliases together when available.
  • Include severity source, fix version, EPSS, KEV status, CWE, and advisory source chain when present.
  • Separate "no vulnerabilities found" from "not enough data to evaluate."
  • Keep raw credentials and credential-bearing URLs out of output, logs, prompts, SARIF locations, and exported reports.

🤖 AI 評測

這個 Skill 質量不錯,文件清晰詳細,安全考慮充分。它能幫你查詢軟體包的漏洞資訊,支援多種使用場景,並有隱私保護措施。主要優點是資料邊界說明清楚,不會洩露你的原始碼;主要不足是許可證標註存在不一致,且文件提到未對工具本身做過獨立安全檢查。總體適合用於軟體安全檢查,但在敏感環境使用前建議先了解其資料傳送範圍。

📊 多維度評分

適應性4.7
規範性4.4
有效性4.6
可靠性3.7
可信度4.3

📁 包含檔案 (3 個)

📄 SKILL.md 6.7 KB
📄 _meta.json 149 B
📄 skill-card.md 3.1 KB