What problem does it solve? Security teams drown in scanner output and CVE volume without knowing which vulnerabilities are actually exploitable or worth fixing first. This Skill provides a complete vulnerability assessment methodology covering discovery, scoring, prioritization, verification, remediation, and closure. ## Core Features & Use Cases - Scoring and Prioritization: Applies CVSS 3.1/4.0 correctly (including naming conventions like CVSS-BT), then fuses EPSS exploit probability and CISA KEV in-the-wild data into a VPT priority matrix with SLA recommendations. - Scanner Operations and False-Positive Governance: Deep configuration guidance for Nessus, OpenVAS, and Nuclei, plus a verification methodology that treats scanner output as leads requiring manual confirmation before becoming findings. - Supply Chain, Cloud, and AI-Assisted Assessment: Covers SBOM generation with Trivy/Syft, Kubernetes and container scanning, and LLM-assisted triage with confidence thresholds and mandatory human review. - Use Case: Given a list of CVEs affecting your assets, query EPSS and KEV, apply the priority matrix, verify high-risk items with harmless PoC techniques (DNSLog, timing), and produce a report with evidence chains and remediation SLAs. ## Quick Start Ask the AI to assess the vulnerabilities found on your authorized target scope, prioritize them using CVSS, EPSS, and KEV data, and produce a verified findings report with remediation recommendations.