This skill provides a methodical six-step process to determine if a known vulnerability (CVE or GHSA) in a dependency is actually exploitable within the current project. It moves beyond simple version checking by analyzing whether the vulnerable API surface is actually reached by attacker-controllable input.
Use this skill when a security scanner flags a vulnerable dependency and you need a reachability verdict to decide if the advisory is actionable noise or a genuine risk.
Designed for agents with shell execution capabilities, such as Claude Code, Codex, Gemini CLI, and GitHub Copilot.
This skill has not been reviewed by our automated audit pipeline yet.