agentsclimarketplace

Coff0xc vulnerability lifecycle

Skill Coff0xc/coffee-skill/skills/coff0xc-vulnerability-lifecycle

Use when / 当用户请求 vulnerability lifecycle:CVE、advisory、patch diff、CVSS/EPSS/KEV、PoC 验证、bug bounty、pentest report、影响范围、修复优先级、缓解措施、security patch 或修复跟踪。授权验证优先。手动触发:使用 coff0xc-vulnerability-lifecycle。From its SKILL.md

Install
npx -y skills add Coff0xc/coffee-skill --skill coff0xc-vulnerability-lifecycle

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
  • 15 stars15 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

3.1 KB, ~1.0k tokens by cl100k_base, as published. Nobody here has run it

coff0xc-vulnerability-lifecycle

<!-- skill-id: cs-vlc-6f0d3b8e -->

快速规则(日常任务先读这里)

[来源先行] CVE、vendor advisory、release notes、补丁 diff、KEV/EPSS/CVSS 必须查真实来源。 [资产绑定] 把漏洞影响绑定到版本、配置、暴露面、补丁状态和业务上下文。 [修复闭环] 输出优先级、缓解、补丁/回滚、验证命令和残余风险。 [硬边界] PoC 执行、生产验证、第三方目标、漏洞披露和公开发布先确认。

普通漏洞分析按本节先推进;只有补丁逆向、授权验证或企业治理报告时再展开完整工作流。

能力定位

面向漏洞全生命周期的研究、影响评估、优先级和修复跟踪能力。它把 CVE、补丁、PoC、资产信息和业务影响转成可执行修复计划。

能交付什么

  • 漏洞原理和补丁差异摘要
  • 受影响范围、CVSS/EPSS/KEV 和业务优先级
  • 授权验证计划、缓解措施和修复 owner
  • 报告、跟进表和复测标准

可以接收什么输入

  • CVE/advisory、补丁 diff、版本清单、SBOM
  • 扫描结果、资产暴露、PoC 线索、上游 release notes
  • bug bounty 或 pentest 报告草稿

放心使用的边界

  • 可做授权范围内的影响分析和验证计划
  • 真实目标利用、公开 PoC 扩散、未授权验证必须拒绝或转防御
  • 当前 CVE 状态、KEV、EPSS、版本影响必须查真实来源
  • 安全类能力默认只用于授权、防御、检测、加固、验证和报告;不提供未授权攻击、凭据窃取、持久化、规避检测、C2、钓鱼收集、数据外传或破坏性步骤。

为什么可以放心

  • 把漏洞标题、可达性和业务影响分开判断
  • 优先给修复顺序和临时缓解
  • 明确哪些结论已验证、哪些依赖上游信息

典型使用方式

使用 coff0xc-vulnerability-lifecycle 分析这个 CVE 的影响、补丁和修复优先级。
使用 coff0xc-vulnerability-lifecycle 做授权 PoC 验证计划和修复跟踪。
Use coff0xc-vulnerability-lifecycle to turn this advisory into a vulnerability management report.

默认输出

  • 收口只写完成、验证、还剩、下一步;有文件/代码/规则产物给路径或位置。
  • 未真实运行的检查标为未验证,安全/架构结论标证据等级。

按需展开

  • 日常任务只执行上面的快速规则、能力边界和典型用法,不默认读取完整门禁。
  • 深度架构、复杂多阶段、质量评测、发版、正式交付或当前任务证据不足时,再读取 references/full-workflow.md
  • 读取 reference 后仍保持最小必要上下文;不要因为 reference 存在就输出长篇流程或额外自证材料。

What ships with it: 1 file

6.2 KB alongside SKILL.md

references/

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.