vulnerability-management

Track security vulnerabilities with CVSS severity mapping and SLA-aligned remediation timelines.

37|1|Updated Mar 17, 2026
One-click install
npx skills add https://github.com/saolalab/clawforce --skill vulnerability-management-saolalab
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vulnerability-management
Source: https://github.com/saolalab/clawforce/tree/main/marketplace/roles/security-engineer/workspace/skills/vulnerability-management
Command: npx skills add https://github.com/saolalab/clawforce --skill vulnerability-management-saolalab

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Centralizes guidance for discovering, assessing, prioritizing, and tracking security vulnerabilities so teams can reduce risk, meet remediation SLAs, and close findings consistently across the organization.

Core Features & Use Cases

  • Vulnerability Lifecycle: End-to-end workflow from discovery through verification and closure to ensure consistent handling.
  • CVSS Scoring & SLA Mapping: Severity thresholds mapped to remediation SLAs to drive response timelines for critical, high, medium, and low findings.
  • Reporting & Templates: Ready-to-use vulnerability report structure including affected assets, technical details, impact analysis, remediation steps, and references.
  • Scanning Cadence & Prioritization: Recommended scan schedules for external, internal, container, dependency, and web app scans plus a prioritization matrix that weights asset criticality, exposure, exploitability, and data sensitivity.
  • Metrics & Compliance: Track MTTR, vulnerability age, open counts, SLA compliance, and recurrence to measure program health.

Quick Start

Run a scan of the target assets, classify findings by CVSS and asset criticality, assign owners with SLA-based due dates, and generate a vulnerability report for remediation tracking.

Frequently Asked Questions about vulnerability-management

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prioritize vulnerability remediation using CVSS scores and asset criticality?

Vulnerability prioritization uses a matrix weighting asset criticality, exposure, exploitability, and data sensitivity alongside CVSS scores. This approach maps severity thresholds to remediation SLAs, driving response timelines for critical, high, medium, and low findings.

What is the recommended scanning cadence for external, internal, and container vulnerability assessments?

Recommended vulnerability scanning cadence provides specific schedules for external, internal, container, dependency, and web app scans. Consistent scan schedules ensure continuous discovery and tracking across an organization's systems and software.

How do I track MTTR and SLA compliance for open security vulnerabilities?

Track MTTR, vulnerability age, open counts, SLA compliance, and recurrence to measure program health. Assigning owners with SLA-based due dates after classifying findings by CVSS and asset criticality enables consistent tracking of remediation timelines.

What should be included in a vulnerability report for remediation tracking?

A vulnerability report structure includes affected assets, technical details, impact analysis, remediation steps, and references. This ready-to-use template ensures consistent documentation from discovery through verification and closure.

Can I apply vulnerability management workflows to container image builds and dependency monitoring?

Vulnerability management workflows apply to external and internal scans, container image builds, dependency monitoring, and web application assessments. The end-to-end lifecycle handles discovery, assessment, prioritization, tracking, and verification.

How do I map CVSS severity thresholds to remediation SLAs for security findings?

CVSS scoring and SLA mapping establish severity thresholds mapped to remediation SLAs for critical, high, medium, and low findings. This mapping drives response timelines and ensures teams meet remediation SLAs consistently across the organization.