cve-advisory

Generate CVE-format security advisories compliant with CNA rules.

5|3|Updated Apr 10, 2026
One-click install
npx skills add https://github.com/zebbern/termstack --skill cve-advisory
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cve-advisory
Source: https://github.com/zebbern/termstack/tree/main/.github/skills/cve-advisory
Command: npx skills add https://github.com/zebbern/termstack --skill cve-advisory

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

CVE advisory creation and coordination guidelines that ensure vulnerability disclosures follow official CNA rules and CVE Record schema.

Core Features & Use Cases

  • Generate CVE-formatted advisories in compliance with CNA requirements.
  • Compile CVE records, references, CWE mappings, and disclosure timelines for vendor communications.
  • Use case: publish disclosures, coordinate responses, or prepare vendor advisories needing CVE identifiers.

Quick Start

Draft a CVE-format vulnerability advisory for a disclosed issue, including a placeholder CVE ID and references.

Frequently Asked Questions about cve-advisory

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I draft a CVE advisory that complies with CNA rules?

To draft a CVE advisory compliant with CNA rules, generate structured security records that include CWE mappings, references, and disclosure timelines formatted according to the official CVE Record schema 5.x.

What is a CVE Record schema 5.x formatted vulnerability disclosure?

A CVE Record schema 5.x formatted vulnerability disclosure is a structured security advisory containing standardized fields for CVE identifiers, CWE mappings, references, and coordinated disclosure timelines adhering to MITRE specifications.

How do I automate CVE record generation for vendor security advisories?

Automate CVE record generation for vendor security advisories by structuring vulnerability disclosures into standardized records with placeholder CVE IDs, CWE mappings, and publication timelines that meet CNA requirements.

What do I need to include when publishing a vulnerability disclosure with a CVE identifier?

When publishing a vulnerability disclosure with a CVE identifier, you need to include structured CVE records, external references, CWE mappings, and a detailed disclosure timeline to comply with CNA guidelines.

Can I use this to coordinate vulnerability response and prepare vendor advisories?

Yes, you can prepare vendor advisories and coordinate vulnerability response by generating structured CVE records with required references and disclosure timelines that align with official CNA coordination guidelines.

Does CVE advisory generation support CWE mappings and disclosure timelines?

CVE advisory generation supports compiling CWE mappings and disclosure timelines directly into the structured CVE records, ensuring the final vulnerability advisory fully complies with CNA rules.