agentsclimarketplace

Run3 cvss data normalization

Skill cxcscmu/SkillLearnBench/skills/b3-teacher-feedback-gemini-3.1-flash-lite-preview/dependency-vulnerability-check/run3_cvss_data_normalization

Logic to parse nested security database objects into a scalar CVSS score for the final CSV report.From its SKILL.md

Install
npx -y skills add cxcscmu/SkillLearnBench --skill run3_cvss_data_normalization

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

SKILL.md

0.9 KB, 198 tokens by cl100k_base, as published. Nobody here has run it

When processing vulnerability metadata, extract the score using the following hierarchy to ensure data accuracy:

  1. NVD Source: Look for cve.cvss.cvssV3.baseScore within the JSON metadata.
  2. GHSA Source: Look for github.cvss.score.
  3. RedHat Source: Look for redhat.cvss.cvss3.score.

Transformation Rules:

  • The input is a nested JSON object (e.g., {"cvssV3": {"baseScore": 8.8, "vectorString": "..."}}).
  • The output must be the scalar value of the baseScore or score field identified from the highest priority source.
  • If no CVSS v3 score is present across all sources, check for cvssV2 scores before finally returning "N/A".
  • Ensure the extracted value is formatted as a decimal string in the final /root/security_audit.csv file.

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.