Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Vulnerability Management

ASecurity

Run a full vulnerability management lifecycle — discovery, prioritization, remediation SLAs, and continuous measurement.

2 stars
0 votes
0 copies
0 views
Added 9/29/2026
ai-agentsrustgoshellsecurity

Security Analysis

A100/100

Scanned 9/29/2026

$npx -y skills add aicodedecode/awesome-muse-skills --skill vulnerability-management --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Vulnerability Management?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Vulnerability Management
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-vulnerability-management/badge)](https://www.skillsdirectory.com/skills/aicodedecode-vulnerability-management)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: vulnerability-management
description: Run a full vulnerability management lifecycle — discovery, prioritization, remediation SLAs, and continuous measurement.
category: security
---

## Overview

Vulnerability management is the ongoing discipline of finding weaknesses across your estate, deciding which matter, getting them fixed on time, and proving it. It is not "run a scanner monthly" — it is a lifecycle: **discover → assess → prioritize → remediate → verify → report**. Done well, it is the highest-ROI security program most organizations run.

This skill covers building that lifecycle: asset coverage, risk-based prioritization, SLA design, exception handling, and metrics that show progress instead of scanner noise.

Vulnerability management is where security theory meets organizational reality: it succeeds or fails on asset ownership, engineering relationships, and the credibility of prioritization. The program's currency is trust — every false-priority escalation and every unactionable finding spends it. Spend it where the risk actually is.

## When to use

- Standing up or maturing a vuln-management program from ad-hoc scanning.
- Drowning in scanner findings and needing risk-based prioritization.
- Setting remediation SLAs and holding teams accountable without burning trust.
- Preparing for audits that ask for evidence of timely remediation.
- Responding to a critical CVE (Log4Shell-style) with a coordinated find-and-fix.

## Core concepts

- **You cannot scan what you cannot see:** asset inventory (including cloud, containers, SaaS, shadow IT) is step zero. Unscanned assets are unmeasured risk.
- **CVSS ≠ risk:** CVSS measures vulnerability severity in a vacuum. Real prioritization adds exploitability (is there a public exploit? CISA KEV?), asset criticality, and exposure (internet-facing?).
- **Risk-based prioritization:** a medium CVE with a public exploit on an internet-facing payment server beats a critical CVE with no exploit path on an isolated test box. Say this out loud, often.
- **SLAs by severity:** e.g., critical 7–15 days, high 30 days, medium 90 days. SLAs must be agreed with engineering, not imposed.
- **Exceptions with expiry:** accepted risks need an owner, a business justification, compensating controls, and an expiry date. Permanent exceptions are just ignored vulnerabilities.
- **Verify, don't trust:** closure requires re-scan or evidence of the fix, not a ticket marked "done."

- **Exposure windows.** Track time from CVE publication to remediation on internet-facing assets separately — that window is the attacker's opportunity and your key risk metric.
- **Compensating controls as first aid.** When patching is blocked, document the WAF rule, network isolation, or config change reducing exposure — with an expiry tied to the real fix.
- **Vulnerability intelligence sources.** Beyond scanners: vendor advisories, CISA KEV, and threat-intel feeds for your stack. Correlate, do not just aggregate.

## Practical workflow

1. **Inventory and coverage:** enumerate assets (hosts, cloud accounts, containers, apps, network gear). Map each to a scan source: agent-based, network scans, cloud posture, container registry, DAST/SAST for apps.
2. **Scan on cadence:** authenticated scans where possible (far richer results), plus continuous scanning for critical segments. Track scan coverage % as a KPI.
3. **Enrich and deduplicate:** merge findings across tools, attach asset context (owner, criticality, exposure), tag CISA KEV / exploited-in-the-wild items for fast-track.
4. **Prioritize:** sort by risk = severity × exploitability × exposure × asset criticality. Publish a weekly "top N that actually matter" list, not a 10,000-row CSV.
5. **Assign with SLAs:** route to asset owners with clear severity, evidence, remediation guidance, and due date. Provide the fix, not just the finding.
6. **Track and verify:** dashboard of SLA compliance, aging, and exceptions. Re-scan on closure. Escalate breaches of SLA through management, with data.
7. **Report trends:** mean time to remediate, % criticals within SLA, repeat offenders, coverage. Report risk reduction, not raw counts.

### Prioritization quick rubric

- **P0 / Emergency:** CISA KEV or actively exploited + internet-facing + critical asset → hours to days.
- **Critical:** CVSS 9+ on exposed critical asset → 7–15 days.
- **High:** exploitable path exists → 30 days.
- **Medium/Low:** defense-in-depth items → 90 days / next cycle.

### Sustaining the practice

- Publish the weekly risk-burn-down to engineering leadership — visibility drives action
- Review scanner coverage and credential health monthly
- Re-validate prioritization logic quarterly against actual exploitation trends
- Celebrate teams with strong remediation records; make security a team sport

### Metrics that prove it works

- SLA compliance % by severity band, trended monthly
- Mean time to remediate critical/high findings
- Scan coverage % of the asset inventory (authenticated coverage separately)
- Exception count and average exception age

## Common pitfalls

- **Scanning without authentication.** Unauthenticated scans miss most host findings. Authenticated scanning is worth the credential-management effort.
- **CVSS-only prioritization.** Teams fix easy 9.8s on test boxes while exploited 7.5s on prod burn. Add exploit intel and exposure.
- **No asset owners.** Findings with no owner rot. Every asset needs a named accountable owner.
- **SLAs nobody agreed to.** Imposed deadlines get ignored. Negotiate, publish, then enforce evenly.
- **Counting findings instead of risk.** "We closed 5,000 findings" means little if the top 20 risks are untouched. Report risk burned down.
- **Ignoring the exception graveyard.** Review exceptions quarterly; expired or unjustified ones go back into the queue.
- **Accepting unauthenticated scans as coverage.** They miss the majority of host findings. Authenticated scanning is worth the credential-management overhead.
- **Patch delays without formal risk acceptance.** "Waiting for the maintenance window" repeated for six months is an undocumented exception. Formalize it or fix it.
- **Scanning production aggressively without coordination.** Unthrottled scans can degrade fragile services. Schedule, throttle, and coordinate with service owners.
- **Counting scanner plugins instead of risk.** 'We run 100k checks' impresses nobody if the top risks age past SLA. Report risk reduced, not checks run.

Attribution

aicodedecodeaicodedecode
View sourceSee grades on GitHubMore from aicodedecode →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →