agentsclimarketplace

Cvss score extraction

Skill cxcscmu/SkillLearnBench/skills/b1-one-shot-gemini-3-flash-preview/dependency-vulnerability-check/cvss-score-extraction

Extract and prioritize CVSS scores from multiple sources in vulnerability reports to ensure the most accurate data is used.From its SKILL.md

Install
npx -y skills add cxcscmu/SkillLearnBench --skill cvss-score-extraction

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

SKILL.md

1.7 KB, 427 tokens by cl100k_base, as published. Nobody here has run it

CVSS Score Extraction

Vulnerability reports from tools like Trivy often include CVSS scores from multiple authorities (e.g., NVD, GHSA, RedHat). This skill covers how to extract these scores with a fallback priority.

CVSS Data Structure in Trivy

Trivy JSON reports store CVSS data in a CVSS map within each vulnerability object:

"CVSS": {
  "ghsa": {
    "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "V3Score": 9.8
  },
  "nvd": {
    "V3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "V3Score": 9.8
  }
}

Extraction Logic

When multiple scores are available, a common priority order is:

  1. NVD (National Vulnerability Database): The standard authority.
  2. GHSA (GitHub Security Advisories): Often more up-to-date for ecosystem-specific packages.
  3. RedHat/Vendor: Specific to vendor-patched versions.

Python Example for Extraction

def extract_cvss(cvss_data):
    if not cvss_data:
        return "N/A"
    
    # Priority: nvd, then ghsa, then others
    for source in ['nvd', 'ghsa']:
        source_data = cvss_data.get(source)
        if source_data:
            score = source_data.get('V3Score') or source_data.get('V2Score')
            if score is not None:
                return score
                
    # Fallback to any available source
    for source_data in cvss_data.values():
        score = source_data.get('V3Score') or source_data.get('V2Score')
        if score is not None:
            return score
            
    return "N/A"

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.