cve-poc-generator
CVE research, standalone PoC script and report generation. Given a CVE ID, researches NVD and advisories, generates a safe Python PoC, and writes a detailed vulnerability report.
How do I install this agent skill?
npx skills add https://github.com/transilienceai/communitytools --skill cve-poc-generatorIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill researches security vulnerabilities and generates Python scripts. While it includes safety constraints, it is vulnerable to indirect prompt injection because it processes data from untrusted external websites to generate code.
- Socketwarn
1 alert: gptSecurity
- Snykwarn
Risk: MEDIUM · 1 issue
What does this agent skill do?
CVE PoC Generator
Research a CVE by ID, generate a standalone Python proof-of-concept script, and produce a detailed vulnerability report.
Workflow
- NVD Lookup - Query NVD API v2.0 for the CVE ID (
python3 tools/nvd-lookup.py <CVE>). Extract the CVSS score/vector using the v4.0-primary ladder (v4.0 → v3.1 → v3.0 → v2.0; the tool'sJSON_SUMMARYexposescvss_version+cvss_vector), plus CWE IDs, CPE matches, advisory URLs, and patch links. - Advisory Research - Deep-dive vendor advisories, GitHub security advisories, Exploit-DB, and published write-ups. Identify root cause, affected versions, and attack vector details.
- PoC Generation - Write a standalone Python script (
poc.py) that demonstrates the vulnerability safely. Follow the script standards inreference/poc-methodology.md. - Report Generation - Write a comprehensive markdown report (
report.md) with metadata, root cause analysis, risk assessment, and remediation guidance.
NVD Data to Collect
| Field | Source | Usage |
|---|---|---|
| CVE ID | NVD | Primary identifier |
| CVSS Score + Vector (v4.0 primary; v3.1/v3.0/v2.0 fallback) | NVD | Risk scoring |
| CWE ID(s) | NVD | Vulnerability classification |
| CPE Matches | NVD | Affected products and versions |
| Advisory URLs | NVD references | Research sources |
| Patch Links | NVD references / vendor | Remediation guidance |
| Description | NVD | Vulnerability summary |
| Published / Modified dates | NVD | Timeline |
Output
{OUTPUT_DIR}/
artifacts/cve-pocs/CVE-XXXX-XXXXX/
poc.py # Standalone Python PoC script
reports/cve-pocs/CVE-XXXX-XXXXX/
report.md # Detailed vulnerability report
Invocation
/cve-poc-generator CVE-2024-XXXXX
The skill accepts a single CVE ID as argument. Multiple CVEs should be processed with separate invocations.
Rules
- Least harm - PoC scripts MUST demonstrate vulnerability without causing damage. Use detection/verification checks, not destructive payloads.
- Standalone scripts - PoC must run independently with only standard Python libraries plus
requests. No framework dependencies. - Accurate scoring - Use the exact CVSS score and vector from NVD. Do not fabricate or estimate scores.
- Source attribution - Every claim in the report must cite its source (NVD, vendor advisory, CVE description).
- No emoji - Use text severity labels only (CRITICAL, HIGH, MEDIUM, LOW, INFORMATIONAL).
- Verified data only - Do not hallucinate CVE details. If NVD data is unavailable, state it explicitly.
- Safe defaults - PoC scripts must default to read-only, non-destructive operations. Any potentially harmful action requires explicit
--confirmflag.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/transilienceai/communitytools/cve-poc-generator">View cve-poc-generator on skillZs</a>