agent-bom-vulnerability-intel
Installation
SKILL.md
agent-bom-vulnerability-intel
Use this skill to answer vulnerability-intelligence questions through agent-bom's existing scanners and canonical evidence model. Do not create one-off OSV, GHSA, NVD, EPSS, or KEV clients in the agent session; route through agent-bom so advisory provenance, aliases, severity gates, cache behavior, redaction, and output schemas stay consistent.
Modes
Start with the smallest mode that answers the user:
| Mode | Use When | Data Boundary |
|---|---|---|
explain-only |
User wants to know what would be queried | No advisory calls |
check-package |
User names one package/version/ecosystem | Only that package identifier is queried |
scan-local |
User wants findings from local agents or a local inventory file | Local parse first; advisory calls use package identifiers only |
offline-review |
Private package names cannot leave the environment | Use local/cache-approved data only; disclose reduced coverage |
export |
User wants PR gate, SARIF, JSON, or audit evidence | Write only to an operator-selected path |