Skip to content

mappedsky/github-security-investigations

v1.3.1

Reusable Agent Plugin workflows for GitHub organization security posture and repository CVE reachability.

repo-cve-reachability

Judge whether already-identified CVEs are reachable in a repository's own code, by reading its source through the external GitHub MCP tools. Takes the finding list produced by the repository CVE findings review.

Read SKILL.md at the source

Pinned to revision 9f52dbffa85b, so it is the text this page describes rather than whatever the author pushed since.

Pre-approved tools experimental

Experimental field. Support varies between clients, so this list is what the author declared, not what your client will enforce.

  • mcp__seizu__sandbox__delegate
  • mcp__seizu__github_security__repo_dependencies
  • mcp__github__list_branches
  • mcp__github__get_file_contents
  • mcp__github__search_code
  • mcp__github__list_commits
  • mcp__github__get_commit
  • mcp__deps__depsdev_find_dependency_path
  • mcp__deps__depsdev_get_requirements

Files

Every link opens the file at its source, pinned to the revision this page describes.