Run3 Extract CVSS Score with Correct Priority
Extract CVSS score from vulnerability data using the correct priority order (NVD → GHSA → RedHat) and handle nested JSON structure properly. Use case-insensitive field access and correct JSON path navigation.From its SKILL.md
npx -y skills add cxcscmu/SkillLearnBench --skill run3_Extract-CVSS-Score-with-Correct-PriorityAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
SKILL.md
1.0 KB, 211 tokens by cl100k_base, as published. Nobody here has run it
Process
-
Access CVSS nested structure correctly
- Check for
vuln['CVSS']existence - Use the exact key names:
'NVD','GHSA','RedHat'(case-sensitive) - Access score with
vuln['CVSS'][source]['V3Score'](notv3Scoreorscore)
- Check for
-
Implement priority-based fallback
For each vulnerability: - Try NVD first - If NVD missing/null → try GHSA - If GHSA missing/null → try RedHat - If all missing → return "N/A" -
Handle edge cases
- Null or missing CVSS sections
- Missing score keys within a source
- Empty string values (treat as missing)
-
Validate output
- CVSS score should be numeric or "N/A"
- Never use empty strings as fallback
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.