npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

cve-skill-forge

v0.3.1

Published

Compile CVE intelligence into evidence-backed security skill updates

Readme

CVE Skill Forge

CI npm license Python Node.js

Turn vulnerability intelligence into evidence-backed, reviewable security skills.

CVE Skill Forge collects recent CVE changes, enriches them with exploitation and weakness data, and produces deterministic month-over-month SKILL.md candidates. It is designed for security teams that want current agent guidance without allowing untrusted advisory text to become trusted instructions automatically.

[!IMPORTANT] Generated skills are candidates, not security findings or production policy. Promotion always requires explicit human review.

Why CVE Skill Forge?

Vulnerability feeds change continuously, while security guidance often becomes stale. CVE Skill Forge turns that moving data into a reviewable update process:

  • Evidence-backed: every candidate has a structured evidence sidecar and input hashes.
  • Month-over-month: identify new and changed weakness patterns instead of rebuilding blindly.
  • Risk-enriched: prioritize with CISA KEV, FIRST EPSS, CVSS, OSV aliases, and CWE metadata.
  • Safe by design: upstream prose and third-party links never become generated instructions.
  • Human-controlled: no scheduled workflow can promote a candidate into the trusted collection.
  • Auditable: atomic state, manifests, reconciliation diffs, health evidence, SBOMs, and checksums.

How it works

CVE List V5 ─┐
CISA KEV ────┼─> normalize ─> monthly diff ─> candidate skills ─> human review
FIRST EPSS ──┤                         │                              │
OSV.dev ─────┤                         └─ evidence + manifest         v
CWE ─────────┘                                                   trusted skills

The daily workflow stores normalized state on the dedicated feed-data branch. The monthly workflow compares snapshots, groups recurring evidence by CWE, creates candidate packages, and publishes them as workflow artifacts. Promotion is a separate, explicit command.

See Architecture and the Security model for the complete trust boundaries.

Quick start

Install the skill in a repository

Install uv, open the repository you want to review, and run:

cd my-project
npx cve-skill-forge@latest init

This installs the verified skill at .agents/skills/cve-security-review and adds a monthly GitHub workflow that proposes intelligence updates through pull requests. Commit those files, open the repository in Codex, and ask:

Use $cve-security-review to assess this repository against current CVE intelligence.

For automatic pull requests, enable Settings → Actions → General → Workflow permissions → Allow GitHub Actions to create and approve pull requests in the consuming repository. The workflow uses only its repository-scoped GITHUB_TOKEN; no person or external service needs write access.

Check or apply an update manually with:

npx cve-skill-forge@latest status --target .
npx cve-skill-forge@latest update --target .

The updater verifies the pack manifest and every declared SHA-256 hash before replacing the Forge-owned skill directory. Locally modified pack files are rejected unless --force is explicit.

Run from source

Requirements: Python 3.12 or newer and uv.

git clone https://github.com/boyeesu/cve-skill-forge.git
cd cve-skill-forge
uv sync --locked --all-groups
uv run cve-skill-forge --help

Build your first monthly candidate set

# Collect changes and enrich them with KEV, EPSS, and OSV.
uv run cve-skill-forge ingest --since 2026-09-01T00:00:00Z

# Refresh official CWE names and descriptions.
uv run cve-skill-forge sync-cwe

# Generate and validate the monthly candidates.
uv run cve-skill-forge build --month 2026-09
uv run cve-skill-forge validate-skills monthly/2026-09

# Compare candidates with an existing trusted skill directory.
uv run cve-skill-forge reconcile --month 2026-09 --trusted ./skills

Use --max-records 10 for a small network smoke test, or --no-osv to disable OSV enrichment. For an offline run against an extracted CVE List V5 release:

uv run cve-skill-forge ingest --cve-source ./cvelistV5/cves --no-enrich

Review and promote a candidate

Review the generated SKILL.md, evidence.json, and reconciliation diff. Promotion requires the explicit --approve acknowledgement:

uv run cve-skill-forge promote --month 2026-09 --trusted ./skills \
  --slug path-traversal-review --approve

Promotion preserves the evidence under the trusted skill's references/ directory.

Commands

| Command | Purpose | | --- | --- | | ingest | Collect, normalize, and enrich CVE changes | | build | Generate a monthly report and candidate skills | | reconcile | Compare candidates with trusted skills and write unified diffs | | promote | Promote one reviewed candidate into a trusted collection | | validate-skills | Validate candidate frontmatter and evidence | | health | Check snapshot freshness and canonical-source health | | sync-cwe | Refresh official CWE definitions | | schemas | Export JSON Schemas for downstream integrations | | pack | Compile normalized intelligence into the consumer skill | | verify-pack | Verify the pack schema, bounds, file set, and hashes | | init | Install the skill and monthly updater in a repository | | update | Retrieve, verify, and atomically install current intelligence | | status | Compare installed and available pack versions |

Run cve-skill-forge COMMAND --help for all options.

Outputs

.agents/skills/cve-security-review/
├── SKILL.md                       # stable review workflow and confidence model
├── manifest.json                  # pack version, source health, and content hashes
└── references/
    ├── advisories/                # bounded structured CVE intelligence shards
    ├── weakness-index.md          # routing index for relevant weakness guidance
    └── weaknesses/                # curated CWE review references
data/
├── current.jsonl                  # latest normalized record by CVE ID
├── health/latest.json             # latest source-health evidence
└── runs/<timestamp>.jsonl         # immutable ingestion run
monthly/<YYYY-MM>/
├── report.md                      # human-readable release summary
├── changes.json                   # machine-readable candidate list
├── mom.json                       # month-over-month changes
├── manifest.json                  # input and output integrity hashes
├── reconciliation.json           # candidate status and unified diffs
└── skill-candidates/<slug>/
    ├── SKILL.md                   # candidate agent skill
    └── evidence.json              # provenance and prioritization evidence

Data sources

| Source | Role | | --- | --- | | CVE List V5 | Canonical vulnerability identity and records | | CISA KEV | Known exploitation signal | | FIRST EPSS | Exploitation probability and percentile | | OSV.dev | Ecosystem aliases and package context | | MITRE CWE | Weakness taxonomy and metadata |

Each upstream source retains its own terms and license. The MIT license covers this project's software and original templates, not third-party feed contents. See the Source policy.

Prioritization

The default score is a transparent triage aid:

  • 45% CISA KEV status
  • 30% maximum EPSS
  • 15% maximum CVSS
  • 10% evidence volume

It is not an assertion of organizational risk. Asset exposure, business impact, compensating controls, exploit preconditions, and primary advisory evidence still require human assessment.

Security and operations

Network inputs are untrusted. The pipeline enforces source allowlists, response and archive size limits, hardened XML parsing, transient-failure retries, atomic writes, and canonical-source health checks. Generated instructions do not embed upstream-authored prose or supplied links.

Development

make dev
make check
make audit
make build

The CI gate runs formatting, linting, type analysis, tests with an 85% coverage floor, Bandit, secret detection, dependency audits, and package validation. GitHub Actions are pinned to full commit SHAs.

Contributing

Contributions are welcome. Start with CONTRIBUTING.md, review the Code of Conduct, and open an issue before a large behavioral change.

Do not submit secrets, weaponized exploits, or non-public vulnerability information.

Project status

CVE Skill Forge is a public alpha. Interfaces and generated schemas may change before 1.0.0. See Releases for published versions.

License

Licensed under the MIT License. See NOTICE for attribution and third-party data considerations.