Veille CVE ciblée (skill nAIvigate)
Skill : A reusable method: instructions, procedures, sometimes scripts or templates · requires claude-code
Filters vulnerability bulletins against your actual estate and sorts them into 72 h, 30 days, to plan.
Goes from 47 bulletins read to the 4 that concern you, with the source of every line.
Security reflects where data goes, requested permissions and incidents on record at the verification date. It is not a guarantee of zero risk: check the deployment mode and the connections you enable.
What it does, concretely
Vulnerability watch drowns in volume: every week, dozens of CERT, NVD and vendor bulletins of which a handful actually affect the organisation. This skill takes a list of product + version pairs (never machines or addresses) and a bulletin source, pasted or searched over the period, then keeps only the matches.
Each retained vulnerability is qualified: CVSS score, known exploitation (KEV catalogue, vendor notice), available fix, your exposure. Ranking crosses exploitation and exposure rather than score alone, giving three blocks: act within 72 h, within 30 days, plan. What is discarded is counted, never silently dropped.
The bulletin ends with a 'what this bulletin does not know' section: unconfirmed versions, vendors with no source found. It helps prioritise; the patching decision and testing stay with the team.
What it offers
- ·Input: product + version + exposure inventory (internal, perimeter, SaaS), no hosts or addresses.
- ·Accepted sources: pasted text, a period to search, or specific CVEs to qualify.
- ·Per-line qualification: CVSS, known exploitation, fix, exposure, action, source.
- ·Three urgency blocks crossing exploitation and exposure, plus the count of discarded bulletins.
- ·'Version to confirm' flag whenever a match is not certain.
In practice
- Price
- Free
- Commercial use
- Commercial use: yes
- Available on
- claude, claude-code
- Host
- claude-code
- Licence
- MIT
- FR interface
- Yes
Security and data
- Rating
- Security: nothing to flag
- Your data
- Data stays local
- Maintenance
- Active
Links and repository checked on 19 September 2026 · added on 19 September 2026