endor-explain

Explain CVEs and findings with severity, impact, attack vectors, and remediation steps.

2|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/Endor-Solutions-Architecture/endor-solutions-claude-skills --skill endor-explain
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: endor-explain
Source: https://github.com/Endor-Solutions-Architecture/endor-solutions-claude-skills/tree/main/.claude/skills/endor-explain
Command: npx skills add https://github.com/Endor-Solutions-Architecture/endor-solutions-claude-skills --skill endor-explain

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides detailed explanations of CVEs and security findings to help security teams quickly understand risk, assess impact, and plan remediation.

Core Features & Use Cases

  • CVE explanations: comprehensive details including severity, CVSS score, CWE, and timeline.
  • Finding details: map findings to CVEs, show affected components and context.
  • Remediation guidance: actionable remediation steps and upgrade recommendations.
  • Project impact assessment: determine whether a vulnerability affects the current project using Endor Labs MCP tooling.

Quick Start

Use this Skill to retrieve in-depth information about a CVE or finding. For example:

  • endor explain CVE-2021-23337
  • endor explain finding-uuid-1234

Frequently Asked Questions about endor-explain

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I get detailed vulnerability explanations and remediation steps for a specific CVE?

To get detailed CVE explanations, provide a CVE ID, Finding UUID, or package name. The system returns a structured report covering severity, impact, attack vectors, and actionable remediation steps.

What information is included in a CVE vulnerability report?

A CVE vulnerability report includes severity, CVSS score, CWE classification, attack vectors, and a timeline. It also provides actionable remediation steps and upgrade recommendations.

Can I assess whether a CVE affects my current project?

Yes, you can assess project impact by using Endor Labs MCP tooling. The system evaluates whether a specific vulnerability or finding actually affects your current project context.

How do I find CVE details using a finding UUID?

To find CVE details using a finding UUID, input the UUID into the system. It maps the finding to the corresponding CVE and displays affected components and contextual details.

Does this tool work with Endor Labs MCP tools for security analysis?

Yes, it works with Endor Labs MCP tools for security analysis. It leverages these tools to assess project impact and provide comprehensive vulnerability explanations and remediation guidance.