threat-advisory

Generate a daily threat advisory digest from SBOMs and threat feeds.

7|2|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/kkmookhey/shasta --skill threat-advisory
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: threat-advisory
Source: https://github.com/kkmookhey/shasta/tree/main/.claude/skills/threat-advisory
Command: npx skills add https://github.com/kkmookhey/shasta --skill threat-advisory

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Tailored threat intelligence saves security teams hours by filtering global risk data to focus on your tech stack.

Core Features & Use Cases

  • Personalized threat digest focused on KEV, supply-chain, and CVE advisories relevant to your environment.
  • SBOM-driven context combined with threat intel feeds to surface actionable advisories for remediation.
  • Use Case: Run daily to get a prioritized briefing that guides patching and security controls.

Quick Start

Use this skill to generate a daily threat advisory for your current cloud stack.

Frequently Asked Questions about threat-advisory

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a personalized threat intelligence digest for my cloud tech stack?

To generate a personalized threat intelligence digest, you need to build a tech-stack profile from SBOMs and threat feeds to surface KEV, supply chain, and CVE advisories. The generate_daily_advisory workflow automates this filtering process for your environment.

Can I use SBOMs to filter CVE and KEV advisories in AWS or Azure?

Yes, you can use SBOMs to filter CVE and KEV advisories in AWS or Azure by applying the generate_daily_advisory workflow. This requires an authenticated AWS or Azure client to discover SBOMs and match them against active threat feeds.

Do I need an authenticated cloud client to discover SBOMs for threat advisories?

Yes, an authenticated AWS or Azure client is required to discover SBOMs and generate threat advisories. This authenticated access allows the system to build your tech-stack profile and accurately map threat intelligence feeds to your specific environment.

What is the best way to prioritize patching using supply chain threat intelligence?

The best way to prioritize patching is to run a daily threat advisory that combines SBOM-driven context with threat intel feeds. This surfaces actionable KEV and supply chain advisories, providing a prioritized briefing that directly guides your security controls.

How does SBOM-driven context improve threat intelligence feeds for remediation?

SBOM-driven context improves threat intelligence feeds by filtering global risk data to match your specific tech stack. This combination surfaces actionable advisories for remediation, saving security teams hours by focusing strictly on relevant KEV and CVE vulnerabilities.

Are there limitations when generating threat advisories for environments without SBOMs?

Generating threat advisories without SBOMs limits the ability to build a tech-stack profile, meaning the system cannot filter threat intelligence feeds to your specific environment. Accurate KEV and CVE advisory generation relies entirely on SBOM discovery and authenticated cloud client access.