agentsclimarketplace

Cvss score extraction

Skill cxcscmu/SkillLearnBench/skills/b1-one-shot-claude-sonnet-4-6/dependency-vulnerability-check/cvss-score-extraction

Extract CVSS scores from Trivy vulnerability data with proper source priority fallback (NVD > GHSA > RedHat).From its SKILL.md

Install
npx -y skills add cxcscmu/SkillLearnBench --skill cvss-score-extraction

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

SKILL.md

1.0 KB, 320 tokens by cl100k_base, as published. Nobody here has run it

CVSS Score Extraction

Source Priority

NVD (most authoritative) → GHSA → RedHat → N/A

Always prefer CVSS v3 scores. Fall back to v2 only if v3 unavailable.

Implementation

def get_cvss_score(vuln_data):
    """Extract best available CVSS v3 score. Returns float or 'N/A'."""
    cvss = vuln_data.get('CVSS', {})
    for source in ['nvd', 'ghsa', 'redhat']:
        if source in cvss:
            score = cvss[source].get('V3Score')
            if score is not None:
                return score
    return 'N/A'

Trivy CVSS Data Format

"CVSS": {
  "nvd": {
    "V2Score": 7.5,
    "V3Score": 9.8,
    "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
  },
  "ghsa": {
    "V3Score": 9.8
  }
}

Score Severity Mapping

ScoreSeverity
9.0-10.0CRITICAL
7.0-8.9HIGH
4.0-6.9MEDIUM
0.1-3.9LOW

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.