CVE/CWE Database Skill

CVE and CWE database querying and management

509 stars

Best use case

CVE/CWE Database Skill is best used when you need a repeatable AI agent workflow instead of a one-off prompt.

CVE and CWE database querying and management

Teams using CVE/CWE Database Skill should expect a more consistent output, faster repeated execution, less prompt rewriting.

When to use this skill

  • You want a reusable workflow that can be run more than once with consistent structure.

When not to use this skill

  • You only need a quick one-off answer and do not need a reusable workflow.
  • You cannot install or maintain the underlying files, dependencies, or repository context.

Installation

Claude Code / Cursor / Codex

$curl -o ~/.claude/skills/cve-cwe-db/SKILL.md --create-dirs "https://raw.githubusercontent.com/a5c-ai/babysitter/main/library/specializations/security-research/skills/cve-cwe-db/SKILL.md"

Manual Installation

  1. Download SKILL.md from GitHub
  2. Place it in .claude/skills/cve-cwe-db/SKILL.md inside your project
  3. Restart your AI agent — it will auto-discover the skill

How CVE/CWE Database Skill Compares

Feature / AgentCVE/CWE Database SkillStandard Approach
Platform SupportNot specifiedLimited / Varies
Context Awareness High Baseline
Installation ComplexityUnknownN/A

Frequently Asked Questions

What does this skill do?

CVE and CWE database querying and management

Where can I find the source code?

You can find the source code on GitHub using the link provided at the top of the page.

SKILL.md Source

# CVE/CWE Database Skill

## Overview

This skill provides CVE and CWE database querying, CVSS scoring, and vulnerability management capabilities.

## Capabilities

- Query NVD for CVE details
- Search CWE database for weaknesses
- Calculate CVSS scores (v2, v3.1, v4)
- Generate CVE request templates
- Track CVE assignment status
- Map vulnerabilities to CWE
- Generate vulnerability advisories
- Support CPE matching

## Target Processes

- vulnerability-root-cause-analysis.js
- responsible-disclosure.js
- security-advisory-writing.js
- variant-analysis.js

## Dependencies

- NVD API access
- CWE database (local or API)
- cvss library (Python)
- Python 3.x

## Usage Context

This skill is essential for:
- Vulnerability classification
- CVSS score calculation
- CVE request preparation
- Advisory writing
- Vulnerability tracking

## Integration Notes

- Supports NVD API v2
- Can cache CVE data locally
- Integrates with vulnerability management systems
- Supports CPE-based vulnerability matching
- Can generate machine-readable advisories (CSAF)