• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • About Me
  • Privacy Policy
  • Media Mentions

PenTestIT.com

Your source for Detection Engineering, Security Research and Adversary Simulation

  • Search Engine Dorks
  • RSS feed
You are here: Home / Cyber Threat Intelligence / Claude Skill: cve-check

Claude Skill: cve-check

Posted: Sep 8, 2026 by Mayuresh @pentestit 4 min read

Jump to section
  1. cve-check: What is it?
  2. cve-check features
  3. Download cve-check Claude Skill

If you follow me on LinkedIn, I released this skill there first. Resharing here if you don’t. I created the cve-check Claude Skill to resolve multiple searches to begin my vulnerability mitigation research . The skill automates and presents multiple prerequisites that help you prioritize your threat detection backlog. Read on for more details.

cve-check: What is it?

The cve-check Claude skill expects one or more CVE IDs. It the makes out HTTP calls across roughly a dozen public feeds and merges the results into a single per-CVE intelligence record. The contained Python script is pure stdlib that does not need libraries such as requests, and makes use of urllib, concurrent.futures, csv, json, ssl inbuilt libraries.

The manifest file – SKILL.md tells Claude how and when to invoke. When the description field gets matched against your prompt Claude decides to invoke the skill. The earlier version did not worked well on CLI, but now I improved it to work on the portal too. This is how it looks now:

CVE Check Skill

cve-check features

These are the currently provided cve-check data points:

  • CVSS (score, severity, vector)
  • CWE ID
  • CPE information
  • Patches or fixed versions,
  • Mitigations
  • Exploitability information
  • CISA KEV in-the-wild status, EPSS probability, Metasploit/Nuclei/Exploit-DB/GitHub PoC availability
  • Vendor and end-of-life exposure.

Using these datapoints, the script provides a computed “priority tier” along with the recommended “action“. These are how the two data points computed:

cve-check Priority tier:

Remediation urgency = likelihood x impact, combining KEV / EPSS / SSVC / exploit maturity / CVSS

These thresholds are tunable in the assess() function. The output is one of the following:

  • CRITICAL/Exploited in the wild: listed in CISA Known Exploited Vulnerabilities or VulnCheck KEV
    (— ransomware if flagged).
  • HIGH: EPSS >= 50%, a weaponized exploit (MSF exploit module or >=Great rank),
    or SSVC Exploitation: active.
  • MEDIUM: public working exploit (Exploit-DB, any MSF module, popular PoC=50 stars), EPSS >= 10%, or CVSS base >= 9.0.
  • LOW: A PoC/template exists but nothing weaponized.
  • INFO: No public exploit found.

Tier -> action

  • CRITICAL/HIGH: Patch now; if unpatchable, apply the mitigation/workaround shown.
  • MEDIUM: Schedule promptly; prioritize if internet-facing or matches your stack (see CPE).
  • LOW/INFO: Track; reassess if it later lands in KEV or EPSS climbs.

If you run this via Claude CLI, the following environment variables will enrich additional details:

  1. NVD_API_KEY (optional but recommended): Helps to avoid NVD rate
    limiting (403s), especially when querying several CVEs. Without it, CVSS may
    come back “NVD API Rate Limited”.
  2. VULNCHECK_API_KEY (optional): Enables VulnCheck Community KEV, broader
    in-the-wild coverage than CISA KEV.
  3. GITHUB_TOKEN (optional): This raises the GitHub repo-search rate limit (10
    req/min unauthenticated). GitHub search runs alongside the nomi-sec/trickest
    aggregators so fresh CVEs whose PoCs aren’t indexed yet are still found.

All information from the above feeds, vendor-advisory scrape pages, endoflife.date, etc. are cached so that they download once and not once per CVE. each CVE’s full assessment is cached 6h at ~/.cache/cve-check/cve/. The CLI also supports a –refresh command line option to refresh the results. This is the output of a recent vulnerability in the SARIF format:

{
  "$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/main/sarif-2.1/schema/sarif-schema-2.1.0.json",
  "version": "2.1.0",
  "runs": [
    {
      "tool": {
        "driver": {
          "name": "cve-check",
          "informationUri": "https://nvd.nist.gov/vuln/detail/CVE-2026-67276",
          "version": "1.0.0",
          "rules": [
            {
              "id": "CVE-2026-67276",
              "name": "MikroTikRouterOSSSHAuthBypass",
              "shortDescription": {
                "text": "MikroTik RouterOS SSH RSA public-key authentication bypass"
              },
              "fullDescription": {
                "text": "RouterOS validates only RSA key type and modulus during SSH public-key auth, omitting the exponent. Attacker knowing a valid username and the associated RSA modulus can forge a valid signature using a key with exponent 1, bypassing authentication and gaining unauthenticated device access. Chains with CVE-2026-86060 (SSH privilege escalation) in the 'MikroTrick' attack, enabling full takeover."
              },
              "helpUri": "https://nvd.nist.gov/vuln/detail/CVE-2026-67276",
              "help": {
                "text": "Upgrade RouterOS to a fixed train: 7.24.2 (stable), 7.23.4 (long-term), 6.49.21 (v6 long-term), or 7.25beta3+. Restrict SSH to trusted source IPs. Actively exploited since 2026-09-02; assume compromise if SSH was exposed and rotate credentials/keys."
              },
              "defaultConfiguration": {
                "level": "error"
              },
              "properties": {
                "security-severity": "9.2",
                "cvssV3_1_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "cwe": "CWE-347",
                "tags": [
                  "security",
                  "external/cve/CVE-2026-67276",
                  "cwe/CWE-347",
                  "authentication-bypass",
                  "actively-exploited"
                ],
                "affectedProduct": "MikroTik RouterOS",
                "affectedVersions": [
                  ">=7.24 <7.24.2",
                  ">=7.0.0 <7.23.4",
                  ">=6.0.0 <6.49.21"
                ],
                "fixedVersions": [
                  "7.24.2",
                  "7.23.4",
                  "6.49.21",
                  "7.25beta3"
                ],
                "exploitedInWild": true,
                "exploitedSince": "2026-09-02",
                "patchReleased": "2026-09-03",
                "relatedCve": [
                  "CVE-2026-86060"
                ]
              }
            }
          ]
        }
      },
      "results": [
        {
          "ruleId": "CVE-2026-67276",
          "ruleIndex": 0,
          "level": "error",
          "message": {
            "text": "MikroTik RouterOS SSH RSA authentication bypass (CVSS 9.2). Public-key validation omits the RSA exponent, allowing an unauthenticated attacker with a known username and RSA modulus to forge a signature (exponent=1) and take over the device. Actively exploited. Upgrade to 7.24.2 / 7.23.4 / 6.49.21 / 7.25beta3+."
          },
          "locations": [
            {
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "routeros-ssh-server"
                }
              },
              "logicalLocations": [
                {
                  "fullyQualifiedName": "MikroTik.RouterOS.SSH.RSAPublicKeyValidation",
                  "kind": "function"
                }
              ]
            }
          ]
        }
      ]
    }
  ]
}

Download cve-check Claude Skill

Get cve-check v2 at my GitHub here.

Share this post on:
Twitter Facebook LinkedIn Reddit Hacker News WhatsApp
← Previous PostEssential Detection Engineering MetricsNext Post →Microsoft Patch Tuesday September 2026 Exploitability and Patching Priority

Related Posts

  • Offensive Security

    Analysing BigDiskBuster, the Microsoft Defender Update Blocker

    Last week Nightmare Eclipse open sourced BigDiskBuster - although I can see that now all the repositories have been made private. This post is…

    5 min · Sep 27, 2026
  • Cyber Threat Intelligence

    Claude Skill: threat-report-killchain

    Everyday when I come across a threat intelligence report, I have to sift through a lot of data to get to the gist of…

    5 min · Sep 19, 2026
  • Offensive Security

    List of Open Source C2 Post-Exploitation Frameworks

    Restoring this post with the help of the Wayback machine - This post has been lying in my drafts for more than a year…

    9 min · Feb 16, 2026

Filed UnderCyber Threat Intelligence Open Source Tools Vulnerability Research Tagged WithCISA KEV Claude Claude Skill cve-search EPSS metasploit Nuclei open source python VulnCheck

About Mayuresh

Seasoned cybersecurity pioneer with over 15 years building and mentoring elite security research teams. I help drive world-class vulnerability detection and remediation initiatives, delivering patented innovations. A purple-teamer by choice, I transform threat intelligence into actionable protection engineering strategies, actively contributing to the MITRE ATT&CK framework and collaborating with industry evaluators. Passionate about strengthening enterprise cyber resilience, I unite global stakeholders to proactively reduce risk and outpace adversaries in dynamic threat landscapes.

Primary Sidebar

Add PenTestIT as a preferred source on Google

Categories

  • Adversary Emulation
  • Cyber Threat Intelligence
  • Detection Engineering
  • Offensive Security
  • Open Source
  • Penetration Testing
  • Tools
  • Vulnerability Management
  • Vulnerability Research
  • Web Application Security

Archives

  • September 2026
  • April 2026
  • March 2026
  • February 2026
  • August 2022
  • July 2020

Copyright © 2026 - PenTestIT.com | Information shared to be used for LEGAL purposes only!

(opens in a new tab)