Run3 cvss data normalization
Logic to parse nested security database objects into a scalar CVSS score for the final CSV report.From its SKILL.md
npx -y skills add cxcscmu/SkillLearnBench --skill run3_cvss_data_normalizationAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
SKILL.md
0.9 KB, 198 tokens by cl100k_base, as published. Nobody here has run it
When processing vulnerability metadata, extract the score using the following hierarchy to ensure data accuracy:
- NVD Source: Look for
cve.cvss.cvssV3.baseScorewithin the JSON metadata. - GHSA Source: Look for
github.cvss.score. - RedHat Source: Look for
redhat.cvss.cvss3.score.
Transformation Rules:
- The input is a nested JSON object (e.g.,
{"cvssV3": {"baseScore": 8.8, "vectorString": "..."}}). - The output must be the scalar value of the
baseScoreorscorefield identified from the highest priority source. - If no CVSS v3 score is present across all sources, check for
cvssV2scores before finally returning "N/A". - Ensure the extracted value is formatted as a decimal string in the final
/root/security_audit.csvfile.
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.