researching-vulnerabilities

Aggregate threat intelligence, exploit status, and asset exposure for CVE risk assessment.

1|1|Updated Apr 25, 2026
One-click install
npx skills add https://github.com/chenchunrun/onyx-soc --skill researching-vulnerabilities
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: researching-vulnerabilities
Source: https://github.com/chenchunrun/onyx-soc/tree/main/skills/researching-vulnerabilities
Command: npx skills add https://github.com/chenchunrun/onyx-soc --skill researching-vulnerabilities

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

从漏洞编号出发,整合威胁情报、Exploit 状态与资产测绘,评估实际影响并给出处置建议。

Core Features & Use Cases

  • 威胁情报收集与初步评估(ITW、CISA KEV、与勒索软件关联性等)
  • Exploit 状态与可用性评估(PoC、公开模板、利用难度)
  • 资产影响评估与测绘整合(与 cybersec_cloud_mcp_cyberspace-search 结合)
  • 风险评分与处置建议
  • Use Case: 当用户提供 CVE 编号/漏洞名称/受影响产品时,生成定制化的影响评估报告

Quick Start

输入 CVE 编号、漏洞名称和受影响资产,AI 将输出完整的影响评估报告及处置建议。

Frequently Asked Questions about researching-vulnerabilities

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess CVE vulnerability impact using threat intelligence?

To assess CVE vulnerability impact, aggregate threat intelligence, exploit status, and asset exposure to provide tailored risk assessment and actionable remediation guidance.

What's the best way to check exploit availability for a specific CVE?

Check exploit availability by evaluating PoC existence, public exploit templates, and exploitation difficulty to determine the actual risk posed by the vulnerability.

Can I generate a risk assessment report from just a vulnerability name?

Yes, you can generate a customized impact assessment report by providing a vulnerability name, CVE number, or affected product to evaluate threat intel and asset exposure.

How do I map asset exposure to identify vulnerable systems?

Map asset exposure by integrating cyberspace search capabilities to identify affected assets and correlate them with specific vulnerability data for impact evaluation.

What threat intelligence sources are used for vulnerability risk scoring?

Threat intelligence sources include In-The-Wild exploitation status, CISA KEV catalog listings, and ransomware association data to calculate comprehensive vulnerability risk scores.

How do I get remediation guidance for CVEs found in my environment?

Get remediation guidance by inputting identified CVE numbers and affected assets to receive actionable recommendations based on threat intel aggregation and risk scoring.