cve-stack-relevance

$npx mdskill add Significant-Gravitas/skills-catalog/cve-stack-relevance

Use this for one advisory or a small related set.

SKILL.md

.github/skills/cve-stack-relevanceView on GitHub ↗
---
name: "cve-stack-relevance"
description: "Decide whether a CVE or advisory matters to the actual stack and show the data behind that judgement."
triggers: ["does this CVE affect us", "CVE relevance", "advisory impact", "are we vulnerable", "stack exposure"]
version: "1"
---

# CVE stack relevance

Use this for one advisory or a small related set.

## Test the chain

Answer each question with evidence:

1. Is the named package and ecosystem the one in this stack?
2. Does the installed version fall in the verified affected range?
3. Does the shipped service include and load it?
4. Is the vulnerable feature or configuration present?
5. Can an attacker meet the access and privilege conditions?
6. What data, control, or availability could be lost?
7. Is a fixed version or verified mitigation available?

## Give a result

Label the result **confirmed**, **likely**, **not affected**, or **unknown**.
Cite the advisory source and the repository, image, configuration, or runtime
evidence used for each step. Explain any conflict between vendor, maintainer,
and database records.

## Next action

Name the smallest check or change that resolves the uncertainty or risk. Do not
use absence from a scanner as proof of safety. Do not claim a fix until the
fixed version is present in the built artifact and the relevant tests or checks
pass.

More from Significant-Gravitas/skills-catalog

SkillDescription
account-health-and-qbrsUse when a support account wobbles or a quarterly business review looms: read the health signals, run the success plan, and prep the review from evidence.
accounts-receivable-follow-upReview open receivables and draft factual, staged payment follow-ups without inventing status or contacting a customer.
ad-copy-variantsWrite ad variants that each test one idea, within platform limits and supported claims.
alex-getting-startedUse on the first conversation with Alex, or whenever their memory has no product preferences yet: learn what the user is building and who for, where specs, roadmap and numbers live, who decides dates and scope, and get them to a first real product deliverable.
alliance-co-commercializationUse when a strategic alliance needs joint selling governance: operating model, joint targeting, steering prep, and milestone accountability.
anika-getting-startedUse on the first conversation with Anika, or whenever their memory has no partnership preferences yet: learn which partners and alliances the user owns, what motion they run, and get one real partner read on screen in the same session.
assure-partner-led-deliveryUse when partners deliver client work in your name: own the in-flight book, run the weekly delivery review, and rescue engagements before clients feel it.
automate-finance-reportingUse to connect a number source, map an export into the finance ledger, or QA a sheet: the column mapping, the dedupe key, the load summary, and the checks that must pass before a read ships.
billing-refunds-and-exceptionsUse when money is on the table: verify the charge, check the policy, and stage a refund or exception draft that stops at the owner's yes.
board-and-investor-metrics-briefPrepare a concise board or investor metrics brief with definitions, sources, comparisons, drivers, risks, and decisions needed.