performing-cve-prioritization-with-kev-catalog
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the Known Exploited Vulnerabilities (KEV) catalog from CISA's official domain (
www.cisa.gov). This is a well-known, trusted government service for cybersecurity intelligence. - [EXTERNAL_DOWNLOADS]: Fetches EPSS (Exploit Prediction Scoring System) data from the official API provided by FIRST (
api.first.org). FIRST is a well-known international organization for incident response. - [COMMAND_EXECUTION]: The skill uses Python's
requestsandpandaslibraries to process vulnerability data. There are no instances of arbitrary command execution, shell spawning, or unsafe evaluation of external input.
Audit Metadata