If you follow me on LinkedIn, I released this skill there first. Resharing here if you don’t. I created the cve-check Claude Skill to resolve multiple searches to begin my vulnerability mitigation research . The skill automates and presents multiple prerequisites that help you prioritize your threat detection backlog. Read on for more details.
cve-check: What is it?
The cve-check Claude skill expects one or more CVE IDs. It the makes out HTTP calls across roughly a dozen public feeds and merges the results into a single per-CVE intelligence record. The contained Python script is pure stdlib that does not need libraries such as requests, and makes use of urllib, concurrent.futures, csv, json, ssl inbuilt libraries.
The manifest file – SKILL.md tells Claude how and when to invoke. When the description field gets matched against your prompt Claude decides to invoke the skill. The earlier version did not worked well on CLI, but now I improved it to work on the portal too. This is how it looks now:

cve-check features
These are the currently provided cve-check data points:
- CVSS (score, severity, vector)
- CWE ID
- CPE information
- Patches or fixed versions,
- Mitigations
- Exploitability information
- CISA KEV in-the-wild status, EPSS probability, Metasploit/Nuclei/Exploit-DB/GitHub PoC availability
- Vendor and end-of-life exposure.
Using these datapoints, the script provides a computed “priority tier” along with the recommended “action“. These are how the two data points computed:
cve-check Priority tier:
Remediation urgency = likelihood x impact, combining KEV / EPSS / SSVC / exploit maturity / CVSS
These thresholds are tunable in the assess() function. The output is one of the following:
CRITICAL/Exploited in the wild: listed in CISA Known Exploited Vulnerabilities or VulnCheck KEV
(— ransomwareif flagged).HIGH: EPSS >= 50%, a weaponized exploit (MSF exploit module or >=Great rank),
or SSVCExploitation: active.MEDIUM: public working exploit (Exploit-DB, any MSF module, popular PoC=50 stars), EPSS >= 10%, or CVSS base >= 9.0.LOW: A PoC/template exists but nothing weaponized.INFO: No public exploit found.
Tier -> action
CRITICAL/HIGH: Patch now; if unpatchable, apply the mitigation/workaround shown.MEDIUM: Schedule promptly; prioritize if internet-facing or matches your stack (see CPE).LOW/INFO: Track; reassess if it later lands in KEV or EPSS climbs.
If you run this via Claude CLI, the following environment variables will enrich additional details:
- NVD_API_KEY (optional but recommended): Helps to avoid NVD rate
limiting (403s), especially when querying several CVEs. Without it, CVSS may
come back “NVD API Rate Limited”. - VULNCHECK_API_KEY (optional): Enables VulnCheck Community KEV, broader
in-the-wild coverage than CISA KEV. - GITHUB_TOKEN (optional): This raises the GitHub repo-search rate limit (10
req/min unauthenticated). GitHub search runs alongside the nomi-sec/trickest
aggregators so fresh CVEs whose PoCs aren’t indexed yet are still found.
All information from the above feeds, vendor-advisory scrape pages, endoflife.date, etc. are cached so that they download once and not once per CVE. each CVE’s full assessment is cached 6h at ~/.cache/cve-check/cve/. The CLI also supports a –refresh command line option to refresh the results. This is the output of a recent vulnerability in the SARIF format:
{
"$schema": "https://raw.githubusercontent.com/oasis-tcs/sarif-spec/main/sarif-2.1/schema/sarif-schema-2.1.0.json",
"version": "2.1.0",
"runs": [
{
"tool": {
"driver": {
"name": "cve-check",
"informationUri": "https://nvd.nist.gov/vuln/detail/CVE-2026-67276",
"version": "1.0.0",
"rules": [
{
"id": "CVE-2026-67276",
"name": "MikroTikRouterOSSSHAuthBypass",
"shortDescription": {
"text": "MikroTik RouterOS SSH RSA public-key authentication bypass"
},
"fullDescription": {
"text": "RouterOS validates only RSA key type and modulus during SSH public-key auth, omitting the exponent. Attacker knowing a valid username and the associated RSA modulus can forge a valid signature using a key with exponent 1, bypassing authentication and gaining unauthenticated device access. Chains with CVE-2026-86060 (SSH privilege escalation) in the 'MikroTrick' attack, enabling full takeover."
},
"helpUri": "https://nvd.nist.gov/vuln/detail/CVE-2026-67276",
"help": {
"text": "Upgrade RouterOS to a fixed train: 7.24.2 (stable), 7.23.4 (long-term), 6.49.21 (v6 long-term), or 7.25beta3+. Restrict SSH to trusted source IPs. Actively exploited since 2026-09-02; assume compromise if SSH was exposed and rotate credentials/keys."
},
"defaultConfiguration": {
"level": "error"
},
"properties": {
"security-severity": "9.2",
"cvssV3_1_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"cwe": "CWE-347",
"tags": [
"security",
"external/cve/CVE-2026-67276",
"cwe/CWE-347",
"authentication-bypass",
"actively-exploited"
],
"affectedProduct": "MikroTik RouterOS",
"affectedVersions": [
">=7.24 <7.24.2",
">=7.0.0 <7.23.4",
">=6.0.0 <6.49.21"
],
"fixedVersions": [
"7.24.2",
"7.23.4",
"6.49.21",
"7.25beta3"
],
"exploitedInWild": true,
"exploitedSince": "2026-09-02",
"patchReleased": "2026-09-03",
"relatedCve": [
"CVE-2026-86060"
]
}
}
]
}
},
"results": [
{
"ruleId": "CVE-2026-67276",
"ruleIndex": 0,
"level": "error",
"message": {
"text": "MikroTik RouterOS SSH RSA authentication bypass (CVSS 9.2). Public-key validation omits the RSA exponent, allowing an unauthenticated attacker with a known username and RSA modulus to forge a signature (exponent=1) and take over the device. Actively exploited. Upgrade to 7.24.2 / 7.23.4 / 6.49.21 / 7.25beta3+."
},
"locations": [
{
"physicalLocation": {
"artifactLocation": {
"uri": "routeros-ssh-server"
}
},
"logicalLocations": [
{
"fullyQualifiedName": "MikroTik.RouterOS.SSH.RSAPublicKeyValidation",
"kind": "function"
}
]
}
]
}
]
}
]
}
Download cve-check Claude Skill
Get cve-check v2 at my GitHub here.