From cybersecurity-skills
Prioritize a validated or plausible vulnerability using actual asset exposure and impact. Use when affected versions, deployment reachability, attacker prerequisites, privileges, sensitive data, exploit maturity, CISA KEV status, vendor guidance, mitigations, detection, business criticality, CVSS, and remediation urgency must be combined without relying on a severity score alone.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cybersecurity-skills:assess-exposure-and-impactThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Translate a technical finding into asset-specific risk and action. Treat CVSS as one technical severity input and current exploitation intelligence as another; neither replaces deployed context.
Translate a technical finding into asset-specific risk and action. Treat CVSS as one technical severity input and current exploitation intelligence as another; neither replaces deployed context.
Read references/exposure-impact-model.md for the decision factors.
Return affected assets, exposure path, impact, current exploitation context, mitigations, priority/rationale, action owner/deadline, and residual uncertainty.
npx claudepluginhub gaelic-ghost/socket --plugin cybersecurity-skillsCreates, edits, and verifies skills using a test-driven development approach with pressure scenarios and subagents.