Skill registry
Developer workflowsPublic skills

Security Vulnerability Management

Vulnerability operations for AI agents — search advisories (CVE/GHSA/OSV/RustSec), audit dependencies, score risk by exploitability, generate remediation plans, and export compliance evidence via mcp-security-advisory.

What this skill teaches

A reusable playbook for a specific kind of work.

An MCP server tells an agent which actions are available. A skill adds the judgment around those actions: how to recognize the job, which sequence to follow, what to avoid, and how to decide that the result is complete.

Manage security vulnerabilities — search advisories (CVE/GHSA/OSV/RustSec), audit dependencies, score risk, generate remediation plans, and export findings. Use when checking for vulnerabilities, auditing dependencies, assessing security risk, planning patches, or generating security reports.

Architecture

How Security Vulnerability Management guides an ADK-Rust agent.

The skill stays readable and portable because it contains instructions rather than service credentials or business data. ADK-Rust supplies it to the agent, the agent chooses from its reviewed tool boundary, and the connected MCP server performs the authenticated operation.

01

User request

The agent receives a goal expressed in ordinary language.

02

Security Vulnerability Management skill

Matches intent, supplies the decision guide, and narrows the tool boundary.

03

ADK-Rust agent

Plans the workflow and streams each meaningful step through the runtime.

04

mcp-security-advisory

Executes authenticated operations against the system that owns the capability.

05

Verified result

The skill's completion rules shape the evidence returned to the user.

Portable instructions: SKILL.md · Capability boundary: mcp-security-advisory · Allowed tools: 6

Decision guide

How the agent turns a request into the right action.

These routes come directly from the skill instructions. They help the model recognize intent and select a focused tool or workflow instead of improvising across the entire capability surface.

01

"vulnerability", "CVE", "advisory"?

search_advisories / get_advisory

02

"audit", "scan", "dependencies"?

audit_dependencies

03

"risk", "score", "severity"?

score_risk

04

"fix", "patch", "remediate"?

remediation_plan

05

"report", "export", "evidence"?

export_findings

Proven workflows

Repeatable sequences for useful outcomes.

A workflow joins several tool calls into a task the user actually recognizes. The skill explains the sequence and the intended result while ADK-Rust streams the agent's progress through the shared runtime.

013 calls

Dependency Audit

Scan → score → remediation plan

022 calls

CVE Investigation

Advisory details + reachability

032 calls

Patch Planning

Upgrade paths with breaking changes

041 calls

Evidence Export

Compliance documentation

Tool boundary

The skill may use 6 documented tools.

This allowlist is declared by the skill. It keeps the agent focused on the actions needed for this job while mcp-security-advisory retains responsibility for authentication, validation, and the connected system.

search_advisories
get_advisory
audit_dependencies
score_risk
remediation_plan
export_findings

Working rules

What the agent should do.

  • Treat critical/exploitable as P0 (immediate action)
  • Verify patches actually resolve the vulnerability
  • Export evidence for all remediation actions
  • Re-scan after patching

Operating boundaries

What the agent should avoid.

  • Never suppress advisories without documented risk acceptance
  • Don't just bump versions — verify the fix
  • Don't delay critical patches for convenience

Install and connect

Add the skill beside the capability it expects.

Install the repository where your ADK-Rust skill loader can discover it, connect mcp-security-advisory, and confirm the declared tools are available before asking the agent to use the workflow.

Install the skill
git clone https://github.com/zavora-ai/skill-security-vulnerability-management.git \
  ~/.skills/skills/security-vulnerability-management
ADK-Rust loading shape
let skills = SkillLoader::from_dir("~/.skills/skills").await?;
let skill = skills.load("security-vulnerability-management").await?;

let agent = LlmAgentBuilder::new("agent")
    .instruction(skill.instructions())
    .tools(skill.allowed_tools(toolset)?)
    .build()?;

The repository's compatibility statement: Requires mcp-security-advisory server connected.

Official documentation

Read the complete skill package.

The repository remains authoritative for its exact instructions, examples, helper scripts, assets, MCP requirements, license, and later updates.

Source record

Repository metadata for this skill entry.

View public repository ↗
License
Apache-2.0
Allowed tools
6
References
3
Revision
7e18bce79985
Updated
May 31, 2026