SS

    soc security ops

    1

    A zero-API-key security toolkit for CISA KEV monitoring, threat news aggregation, and update decision-making.

    Free

    0 installsSecurity scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more
    SS

    soc security ops

    Example session with this skill installed

    Run the threat aggregator to see the latest news and then check my watchlist.json for any active CISA KEV matches.

    • Read your context and instructions
    • Compiled the soc security ops
    • Generated the document

    I have executed the security operations workflow. First, I aggregated the latest threat intelligence from five trusted sources. Second, I scanned the CISA Known Exploited Vulnerabilities (KEV) catalog against your local watchlist.json.

    Security Operations Report

    SourceHeadlineCategory
    The Hacker NewsNew Linux Kernel Vulnerability (CVE-2024-XXXX) Allows Root EscalationVulnerability
    BleepingComputerRansomware Group Targets Unpatched VPN ConcentratorsThreat Actor
    Dark ReadingCISA Adds 3 New Flaws to Known Exploited Vulnerabilities CatalogCompliance
    The RegisterMajor Cloud Provider Patches Critical Auth BypassPatch

    KEV Watchlist Results:

    • Match Found: CVE-2023-49103 (ownCloud Graph API)
    • Vendor: ownCloud
    • EPSS Score: 0.941 (High Probability)
    • Ransomware Use: Known
    • Required Action: Update to version 0.3.1 or higher.
    • Remediation Due: 2024-05-15

    Update Verdict:

    • 🔴

    URGENT: The match for ownCloud in your watchlist is currently being exploited in ransomware campaigns. Immediate patching is required.

    Next steps

    1. Update ownCloud to version 0.3.1 immediately to mitigate CVE-2023-49103.
    2. Review the Linux Kernel vulnerability details to see if your distro is affected.
    3. Check your VPN logs for any suspicious activity mentioned in the BleepingComputer report.

    soc-security-ops.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    About this skill

    The problem

    Security teams and solo developers waste hours manually checking CVE databases and scrolling through noise-heavy threat news to see if their specific stack is at risk.

    What it does

    • Monitors the CISA KEV catalog against a local watchlist of your vendors and products.
    • Enriches vulnerability alerts with FIRST.org EPSS exploit probability scores and ransomware indicators.
    • Aggregates and dedupes security news from five major sources including The Hacker News and BleepingComputer.
    • Provides a structured decision framework for software updates with clear safety verdicts.

    Frameworks & tools

    Python 3 (Standard Library only), CISA KEV JSON, FIRST.org EPSS API.

    Why this beats prompting it yourself

    This skill provides a pre-configured monitoring pipeline that requires zero API keys and runs entirely client-side. It replaces vague "check for news" prompts with specific, repeatable workflows and exit-code-driven automation for cron jobs.

    Use cases

    • Automate a daily morning check for actively exploited vulnerabilities in your specific production stack.
    • Generate a clean, deduped daily cyber threat briefing for your team.
    • Evaluate incoming update notifications to determine if they are urgent security patches or optional feature releases.

    Known limitations

    KEV absence does not guarantee safety. The threatline.io source relies on a Val Town endpoint that may experience downtime. The Hacker News Feedburner source may have high latency.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    Free forever

    No account required to browse

    Trust & safety

    Security scanned

    Verified clean today

    • Free to download with an account

    Listedtoday

    Frequently Asked Questions