vulnerability-management

Installation
SKILL.md

Vulnerability Management

A raw scanner report is a list of theoretical problems, not a work plan. Every base image pulls in hundreds of CVEs, most in code paths nobody calls, in packages exposed to nothing, behind network boundaries that block the exploit. Treating every CVE as equally urgent trains the team to ignore the report entirely, which is worse than not scanning at all.

The job is triage, not enumeration. A finding earns attention by being both exploitable and reachable — not by having a high CVSS score in isolation.

A vulnerability nobody can reach is a lower priority than a medium-severity one sitting on your public ingress.

1. Scan everywhere, but don't treat every scan the same

Installs
5
GitHub Stars
3
First Seen
Aug 4, 2026
vulnerability-management — arjunprabhulal/devops-skills