Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Vulnerability Management

ASecurity

Subdomain routing agent for Vulnerability Management and Attack Surface Management. Covers VM programs, scanner operations, risk scoring (CVSS/EPSS/VPR), remediation workflows, SLA tracking, CNAPP platforms, and EASM tools. WHEN: \"vulnerability management\", \"vuln scan\", \"CVE\", \"CVSS\", \"EPSS\", \"patch prioritization\", \"attack surface\", \"EASM\", \"CNAPP\", \"CSPM\", \"exposure management\". Do NOT use for platform-specific questions -- use the `qualys`, `tenable`, `rapid7`, `snyk`...

4 stars
0 votes
0 copies
0 views
Added 9/24/2026
securitygoawsazureapici/cdsecurity

Works with

api

Security Analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned 9/24/2026

$npx -y skills add chrishuffman5/domain-expert --skill vulnerability-management --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Vulnerability Management?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Vulnerability Management
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-vulnerability-management/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-vulnerability-management)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: vulnerability-management
description: "Subdomain routing agent for Vulnerability Management and Attack Surface Management. Covers VM programs, scanner operations, risk scoring (CVSS/EPSS/VPR), remediation workflows, SLA tracking, CNAPP platforms, and EASM tools. WHEN: \"vulnerability management\", \"vuln scan\", \"CVE\", \"CVSS\", \"EPSS\", \"patch prioritization\", \"attack surface\", \"EASM\", \"CNAPP\", \"CSPM\", \"exposure management\". Do NOT use for platform-specific questions -- use the `qualys`, `tenable`, `rapid7`, `snyk`, or `asm` skill."
license: MIT
---

# Vulnerability Management & Attack Surface Management

This skill covers all vulnerability management (VM) and attack surface management (ASM) disciplines. It provides deep expertise in VM program design, risk-based prioritization, scanner operations, remediation workflows, and cloud security posture. Read the relevant sibling skill for platform implementation details.

## When to Use This Skill vs. a Technology Skill

**Use this skill when the question is cross-tool or programmatic:**
- "How should I design our VM program?"
- "What is the right SLA for critical vulnerabilities?"
- "Compare Tenable vs. Qualys vs. Rapid7"
- "How does CVSS differ from EPSS for prioritization?"
- "What is the difference between CSPM, CWPP, and CNAPP?"
- "Should we use an agent-based or agentless scanner?"
- "How do we measure our attack surface?"

**Read a sibling skill when the question is platform-specific:**
- "Configure a Nessus credentialed scan" --> `tenable`
- "Set up Qualys Cloud Agent" --> `qualys`
- "InsightVM Active Risk Score configuration" --> `rapid7`
- "Snyk CI/CD integration" --> `snyk`
- "Wiz Security Graph query" --> `wiz`
- "Prisma Cloud policy suppression" --> `prisma-cloud`
- "Orca SideScanning setup" --> `orca`
- "Defender for Cloud recommendations" --> `defender-cloud`
- "AWS Security Hub findings" --> `aws-security-hub`
- "Attack surface discovery, Falcon Surface / Xpanse / EASM" --> `asm`

## How to Approach Tasks

When you receive a request:

1. **Classify** the request:
   - **Program design** -- Load `references/concepts.md` for VM fundamentals
   - **Scanner operations** -- Read the appropriate sibling skill
   - **Risk prioritization** -- Apply CVSS + EPSS + threat intelligence context
   - **Remediation management** -- Address SLAs, ticketing integration, exceptions
   - **Cloud security posture** -- Read the CNAPP sibling skill (Wiz, Prisma Cloud, Orca, Defender for Cloud)
   - **Attack surface discovery** -- Read `asm`
   - **Developer security** -- Read `snyk`

2. **Gather context** -- Environment type (cloud/on-prem/hybrid), regulatory requirements, asset inventory size, team maturity, existing tooling, remediation ownership (security vs. IT)

3. **Analyze** -- Apply risk-based prioritization. Not all critical CVEs are equally dangerous. Context (exploitability, asset criticality, exposure) changes the priority order.

4. **Recommend** -- Provide actionable guidance with trade-offs. A mature VM program is a continuous process, not a quarterly scan.

5. **Qualify** -- State coverage gaps, measurement limitations, and conditions where recommendations change.

## Core Concepts

### Risk Scoring Comparison

| Score | Source | What It Measures | Best Used For |
|---|---|---|---|
| **CVSS v3.1** | NVD/vendor | Technical severity (exploitability + impact) | Baseline severity classification |
| **CVSS v4.0** | FIRST | Refined severity + supplemental metrics | New and updated CVE scoring |
| **EPSS** | FIRST | Probability of exploitation in next 30 days | Prioritizing likely-to-be-exploited vulns |
| **CISA KEV** | CISA | Known exploited in the wild (binary: yes/no) | Immediate action -- KEV = patch now |
| **VPR** (Tenable) | Tenable | Threat-intelligence-enriched severity (1-10) | Tenable-specific prioritization |
| **Active Risk** (Rapid7) | Rapid7 | CVSS + threat intel + asset context | Rapid7-specific prioritization |
| **TruRisk** (Qualys) | Qualys | Risk score combining detection confidence + threat | Qualys-specific risk quantification |

**Prioritization framework:**
1. **Immediate (24-48h):** CISA KEV entries on internet-facing or critical systems
2. **Critical SLA (7 days):** CVSS >= 9.0 AND EPSS >= 0.1 AND asset is exposed
3. **High SLA (30 days):** CVSS >= 7.0 with active threat activity
4. **Standard SLA (90 days):** CVSS >= 4.0, no active exploitation evidence
5. **Accept/Schedule (180 days+):** Low severity, compensating controls in place

### Scan Coverage Model

| Method | Best For | Limitations |
|---|---|---|
| **Credentialed network scan** | Deep OS-level detection, missing patches, config audits | Requires credentials management, network access |
| **Uncredentialed network scan** | External perspective, network-exposed services | Misses 40-60% of vulns (no auth to OS/apps) |
| **Agent-based** | Remote/cloud assets, always-on assessment, no network scan required | Agent deployment and maintenance overhead |
| **Agentless (API/snapshot)** | Cloud-native assets, fast deployment, no agent overhead | Point-in-time, may miss ephemeral workloads |
| **Container image scanning** | CI/CD integration, shift-left, image layers | Does not catch runtime misconfigs |
| **DAST/IAST** | Running web application vulnerabilities | Requires running application, scope definition |

### Cloud Security Platform Categories

| Category | Description | Primary Tools |
|---|---|---|
| **CSPM** | Cloud Security Posture Management -- misconfiguration detection, compliance | Wiz, Prisma Cloud, Defender for Cloud, AWS Security Hub |
| **CWPP** | Cloud Workload Protection -- runtime protection for VMs, containers, serverless | Prisma Cloud, Defender for Cloud, Wiz Defend |
| **CIEM** | Cloud Identity Entitlement Management -- overprivileged identities, permissions | Wiz, Prisma Cloud, Defender for Cloud |
| **CNAPP** | Cloud Native Application Protection Platform -- unified CSPM+CWPP+CIEM | Wiz, Prisma Cloud, Orca, Defender for Cloud |
| **DSPM** | Data Security Posture Management -- sensitive data discovery and protection | Wiz, Prisma Cloud |
| **AI-SPM** | AI Security Posture Management -- LLM/AI risk visibility | Wiz, Prisma Cloud |

### VM Program Maturity Model

**Level 1 - Ad Hoc:**
- Periodic scans (quarterly or less)
- No SLAs, no formal remediation tracking
- Single scanner type, uncredentialed or partially credentialed

**Level 2 - Repeatable:**
- Weekly/monthly authenticated scans
- Defined SLAs (even if not consistently met)
- Remediation tracked in scanner or spreadsheet
- Critical/High prioritization in place

**Level 3 - Defined:**
- Continuous scanning / agent-based coverage
- Formal SLAs tied to policy, exceptions process
- ITSM integration (ServiceNow, Jira) for remediation tickets
- Metrics and reporting to management

**Level 4 - Managed:**
- Risk-based prioritization (EPSS/KEV, asset criticality)
- Coverage measurement and gap identification
- Remediation verification/re-scan workflow
- Attack surface management integrated
- SLA compliance > 80% tracked

**Level 5 - Optimized:**
- Threat intelligence-enriched prioritization
- Full CNAPP + developer security (shift-left) integration
- Exposure management (not just vuln management)
- SLA compliance > 95%, exception governance
- Business-aligned risk communication

## Technology Routing

| Request Pattern | Route To |
|---|---|
| Tenable, Nessus, Tenable.io, Tenable One, VPR | `tenable` |
| Qualys, VMDR, QQL, TruRisk, TotalCloud | `qualys` |
| Rapid7, InsightVM, Active Risk, Remediation Hub | `rapid7` |
| Snyk Code, Snyk Open Source, Snyk Container, Snyk IaC | `snyk` |
| Wiz, Security Graph, CNAPP, agentless cloud | `wiz` |
| Prisma Cloud, Cortex Cloud, Bridgecrew | `prisma-cloud` |
| Orca Security, SideScanning | `orca` |
| Microsoft Defender for Cloud, CSPM Azure | `defender-cloud` |
| AWS Security Hub, GuardDuty, Inspector | `aws-security-hub` |
| External attack surface, EASM, internet exposure | `asm` |
| Falcon Surface, Xpanse, Defender EASM, Censys | `asm` |

## Common VM Program Anti-Patterns

1. **Scanning without credentials** -- Uncredentialed scans detect 40-60% fewer vulns. Always use authenticated/credentialed scanning for internal assets.

2. **CVSS-only prioritization** -- A CVSS 9.8 with no public exploit and on an isolated internal host is lower risk than a CVSS 7.5 with a KEV entry on an internet-facing server. Layer EPSS and KEV.

3. **No asset criticality weighting** -- Prioritizing a critical CVE on a dev laptop the same as on a production payment server misallocates remediation effort.

4. **Coverage gaps** -- Cloud workloads, containers, and remote/cloud assets often lack scanner coverage. Agent-based or agentless cloud scanning fills these gaps.

5. **Treating VM as a security-only problem** -- Remediation is owned by IT/dev/cloud teams. VM programs fail without SLA accountability and ITSM integration.

6. **Ignoring attack surface expansion** -- VM programs focus on known assets. Unknown internet-exposed assets (shadow IT, forgotten dev environments, acquired companies) are often the actual attack path.

7. **No re-scan verification** -- Closing tickets on remediation reports without re-scanning leads to a false sense of closure. Verify fixes with targeted rescans.

## Exposure Management vs. Vulnerability Management

Traditional VM focuses on known assets + CVE detection. Modern exposure management (Gartner CTEM) expands the scope:

| Dimension | Vulnerability Management | Exposure Management (CTEM) |
|---|---|---|
| **Scope** | Known assets, CVEs | Known + unknown assets, misconfigs, identity risks, data exposure |
| **Approach** | Find-fix-report cycle | Continuous assessment, attack path analysis |
| **Prioritization** | CVSS + patch availability | Business impact + likelihood of exploitation by real attacker |
| **Output** | Vuln list, patch status | Risk reduction metrics, attack path elimination |
| **Tools** | Tenable, Qualys, Rapid7 | Tenable One, Wiz, Xpanse + VM tools |

## Reference Files

Load these when you need deep foundational knowledge:

- `references/concepts.md` -- VM fundamentals: CVSS/EPSS/KEV scoring, scan types, remediation workflows, SLA frameworks, compliance mapping. Read for "how does X work" or program design questions.

Attribution

chrishuffman5chrishuffman5
View sourceSee grades on GitHubMore from chrishuffman5 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Springboot Security

Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。

2456590 votes

Security Review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

2456590 votes

Paperclip Evals

Choose, inspect, validate, and report Paperclip Runner or Product E2E evaluations while preserving evidence, provenance, cost, and failure classification.

953190 votes

Paperclip Task Bridge

Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.

953190 votes

Summarize Status

Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.

953190 votes
View all in security →