agentsclimarketplace

Run3 Extract CVSS Score with Correct Priority

Skill cxcscmu/SkillLearnBench/skills/b3-teacher-feedback-claude-haiku-4-5/dependency-vulnerability-check/run3_Extract-CVSS-Score-with-Correct-Priority

Extract CVSS score from vulnerability data using the correct priority order (NVD → GHSA → RedHat) and handle nested JSON structure properly. Use case-insensitive field access and correct JSON path navigation.From its SKILL.md

Install
npx -y skills add cxcscmu/SkillLearnBench --skill run3_Extract-CVSS-Score-with-Correct-Priority

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

SKILL.md

1.0 KB, 211 tokens by cl100k_base, as published. Nobody here has run it

Process

  1. Access CVSS nested structure correctly

    • Check for vuln['CVSS'] existence
    • Use the exact key names: 'NVD', 'GHSA', 'RedHat' (case-sensitive)
    • Access score with vuln['CVSS'][source]['V3Score'] (not v3Score or score)
  2. Implement priority-based fallback

    For each vulnerability:
    - Try NVD first
    - If NVD missing/null → try GHSA
    - If GHSA missing/null → try RedHat
    - If all missing → return "N/A"
    
  3. Handle edge cases

    • Null or missing CVSS sections
    • Missing score keys within a source
    • Empty string values (treat as missing)
  4. Validate output

    • CVSS score should be numeric or "N/A"
    • Never use empty strings as fallback

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.