Works with the AI tools you already use
CVEWatch
Monitors vulnerability databases to produce severity-ranked, actionable security digests for your tech stack.
$19
CVEWatch
Example session with this skill installed
Check for critical vulnerabilities in Node.js, Redis, and Nginx from the last 14 days. CVSS floor 8.0.
- Read your context and instructions
- Compiled the cvewatch
I have scanned CISA KEV, NVD, and GitHub Advisories for Node.js, Redis, and Nginx. Below is the digest of critical vulnerabilities meeting your criteria from the last 14 days.
Security Digest — Node.js / Redis / Nginx
| CVE ID | Product | CVSS | Status |
|---|---|---|---|
| CVE-2024-22025 | Node.js < 20.11.1 | 8.8 | High Severity |
| CVE-2024-31449 | Redis < 7.2.4 | 8.2 | High Severity |
| CVE-2024-24989 | Nginx 1.25.x | 9.1 | CISA KEV: Actively Exploited |
[CVE-2024-24989] nginx 1.25.3 — CVSS 9.1 (KEV: actively exploited)
Risk: Memory corruption in the HTTP/3 stack allows remote attackers to cause a denial of service or potentially execute code.
Fix: Upgrade to Nginx 1.25.4 or disable the HTTP/3 module if patching is not immediate.
Source: https://nvd.nist.gov/vuln/detail/CVE-2024-24989
[CVE-2024-22025] nodejs < 20.11.1 — CVSS 8.8
Risk: A vulnerability in the experimental permission model allows unauthorized file system access via path traversal.
Fix: Update to Node.js v20.11.1, v18.19.1, or v21.6.2.
Source: https://github.com/advisories/GHSA-955p-3m45-3jcw
[CVE-2024-31449] redis < 7.2.4 — CVSS 8.2
Risk: Integer overflow in Lua scripting engine allows authenticated users to trigger a crash or remote code execution.
Fix: Upgrade to Redis version 7.2.4, 7.0.15, or 6.2.14.
Source: https://nvd.nist.gov/vuln/detail/CVE-2024-31449
Summary: 3 entries found, 1 actively exploited.
Highest-priority action: Patch Nginx to 1.25.4 immediately due to active exploitation status in CISA KEV.
Next steps
- Verify Nginx version in production and apply the 1.25.4 patch.
- Schedule an update for the Node.js runtime to the latest LTS.
- Review Redis Lua script usage for potential exposure before patching.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Manual monitoring of vulnerability databases is slow and prone to oversight. This skill automates the tracking of critical security threats by scanning NVD, CISA KEV, and GitHub Advisories against your specific tech stack. It converts dense advisory data into a prioritized, actionable digest for developers and security teams.
What it does
- Multi-source scanning Aggregates data from CISA KEV, NVD, GitHub Security Advisories, and vendor bulletins.
- Priority ranking Places actively exploited vulnerabilities (CISA KEV) at the top, regardless of their CVSS score.
- Source verification Requires a valid CVE ID and official source URL for every reported vulnerability.
- Actionable reporting Provides plain-language risk assessments and specific patch versions for every entry.
- Defensive focus Filters out noise to show only high-severity threats or known exploited bugs.
How it works
- Define the stack Provide the list of languages, frameworks, and platforms to monitor.
- Set thresholds Optionally specify a lookback period and a minimum CVSS severity floor.
- Automated search The agent queries multiple databases for matching CPEs and package ecosystems.
- Digest generation Review the ranked list of vulnerabilities with impact summaries and fix instructions.
Frameworks & tools
This tool interfaces with the NIST National Vulnerability Database (NVD), CISA's Known Exploited Vulnerabilities catalog, and GitHub's Advisory Database.
Why this beats prompting it yourself
Generic prompts often return outdated info or hallucinate CVE IDs and scores. This skill enforces strict source-citing and prioritizes CISA KEV data, ensuring you act on real-world exploits rather than theoretical scores.
Use cases
- Daily security standups Generate a quick summary of new threats affecting the production environment.
- Dependency vetting Check the recent vulnerability history of a library before adding it to your stack.
- Compliance reporting Create source-backed digests for internal security audits or team briefings.
Known limitations
Does not perform static or dynamic code analysis to find new bugs. Requires a specific stack list to function. Refuses all requests for exploit code or weaponization steps.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 2 days ago
- Passed all security checks, Safe to install
Needs access to