vulnerability-prioritizerPrioritize vulnerabilities beyond CVSS scores using EPSS (Exploit Prediction Scoring), CISA KEV, asset criticality, reachability analysis, and exploit maturi...
Install via ClawdBot CLI:
clawdbot install charlie-morrison/vulnerability-prioritizerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://api.first.org/data/v1/epss?cve=CVE-2024-1234Audited Apr 30, 2026 · audit v1.0
Generated Sep 9, 2026
A penetration tester has identified multiple vulnerabilities in a client's web application. They need to prioritize remediation efforts based on exploitability and business impact.
A security analyst at a bank receives scan reports from Snyk and Qualys, listing thousands of CVEs. They must triage them to focus on the most critical issues affecting internet-facing systems handling sensitive financial data.
A cloud service provider needs to manage vulnerabilities across multi-tenant infrastructure. They must prioritize based on EPSS, asset criticality, and exploit reachability to ensure high-risk vulnerabilities are patched first to avoid SLA breaches.
A healthcare organization runs routine scans on its network, including patient record systems and IoT devices. They need to prioritize vulnerabilities considering regulatory compliance (HIPAA) and potential impact on patient safety.
A startup uses containers heavily and receives frequent security alerts from Trivy and Grype. They need to focus on exploitable vulnerabilities in libraries that are actually used in production, ignoring phantom dependencies.
Offers vulnerability prioritization as a managed service, integrating with client scanners to deliver risk-ranked remediation plans and ongoing SLA tracking.
Provides consulting services to help organizations implement risk-based vulnerability prioritization processes, including custom tooling and workflow integration.
Develops a software platform that ingests scan data and generates prioritized recommendations using EPSS, KEV, and asset context, sold as a SaaS product.
💬 Integration Tip
Integrate the vulnerability prioritizer as a post-processing step in your CI/CD pipeline to automatically produce prioritized reports from scan outputs.
Scored Sep 9, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...