"vulnerability", "CVE", "advisory"?
search_advisories / get_advisory
Vulnerability operations for AI agents — search advisories (CVE/GHSA/OSV/RustSec), audit dependencies, score risk by exploitability, generate remediation plans, and export compliance evidence via mcp-security-advisory.
What this skill teaches
An MCP server tells an agent which actions are available. A skill adds the judgment around those actions: how to recognize the job, which sequence to follow, what to avoid, and how to decide that the result is complete.
Manage security vulnerabilities — search advisories (CVE/GHSA/OSV/RustSec), audit dependencies, score risk, generate remediation plans, and export findings. Use when checking for vulnerabilities, auditing dependencies, assessing security risk, planning patches, or generating security reports.
Architecture
The skill stays readable and portable because it contains instructions rather than service credentials or business data. ADK-Rust supplies it to the agent, the agent chooses from its reviewed tool boundary, and the connected MCP server performs the authenticated operation.
The agent receives a goal expressed in ordinary language.
Matches intent, supplies the decision guide, and narrows the tool boundary.
Plans the workflow and streams each meaningful step through the runtime.
Executes authenticated operations against the system that owns the capability.
The skill's completion rules shape the evidence returned to the user.
Decision guide
These routes come directly from the skill instructions. They help the model recognize intent and select a focused tool or workflow instead of improvising across the entire capability surface.
"vulnerability", "CVE", "advisory"?
search_advisories / get_advisory
"audit", "scan", "dependencies"?
audit_dependencies
"risk", "score", "severity"?
score_risk
"fix", "patch", "remediate"?
remediation_plan
"report", "export", "evidence"?
export_findings
Proven workflows
A workflow joins several tool calls into a task the user actually recognizes. The skill explains the sequence and the intended result while ADK-Rust streams the agent's progress through the shared runtime.
Scan → score → remediation plan
Advisory details + reachability
Upgrade paths with breaking changes
Compliance documentation
Tool boundary
This allowlist is declared by the skill. It keeps the agent focused on the actions needed for this job while mcp-security-advisory retains responsibility for authentication, validation, and the connected system.
Working rules
Operating boundaries
Install and connect
Install the repository where your ADK-Rust skill loader can discover it, connect mcp-security-advisory, and confirm the declared tools are available before asking the agent to use the workflow.
git clone https://github.com/zavora-ai/skill-security-vulnerability-management.git \
~/.skills/skills/security-vulnerability-managementlet skills = SkillLoader::from_dir("~/.skills/skills").await?;
let skill = skills.load("security-vulnerability-management").await?;
let agent = LlmAgentBuilder::new("agent")
.instruction(skill.instructions())
.tools(skill.allowed_tools(toolset)?)
.build()?;The repository's compatibility statement: Requires mcp-security-advisory server connected.
Official documentation
The repository remains authoritative for its exact instructions, examples, helper scripts, assets, MCP requirements, license, and later updates.
Keep exploring
Source record
Repository metadata for this skill entry.