vuln-research

vuln-research is an agent for Claude Code from ihudak/ihudak-claude-plugins. It costs 102 tokens per session (791 once invoked), scanned A, original, MIT.

A read-only research agent for fixing software vulnerabilities identified by CVE numbers. CVE is a public identifier for a known security flaw; the agent uses the NVD, a public vulnerability database, and checks the repository's installed libraries.

In plain words
What is it for?
Use it to look up CVE details, find affected packages in supported build files, determine current versions, and resolve a minimum safe version.
Why use it?
It replaces manual lookup and package inspection when deciding whether a vulnerability affects the repository. It also identifies the minimum version that is outside the vulnerable range when possible.

Agent for Claude Code

Written for Claude Code: ${CLAUDE_PLUGIN_ROOT} variable.

Runs only inside its plugin — its command needs a path that Claude Code sets for a plugin’s own hooks and for nothing else. Install the plugin, not this.

Part of the dev-workflows plugin — 5 commands, 12 agents, 1 hook shipped together

Good fit Use it to look up CVE details, find affected packages in supported build files, determine current versions, and resolve a minimum safe version.

Compare 6 agents from other repositories ↓
Install

Getting it into your agent

This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.

Claude Code
/plugin marketplace add ihudak/ihudak-claude-plugins
Claude Code
/plugin install dev-workflows

Made for: Claude Code.

Or install dev-workflows, the plugin that ships this one along with the rest of its 5 commands, 12 agents, 1 hook.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for vuln-research

README.md
[![agentmods](https://agentmods.dev/badge/agents/ihudak/ihudak-claude-plugins/vuln-research/github.svg)](https://agentmods.dev/agents/ihudak/ihudak-claude-plugins/vuln-research)
Your own site
<a href="https://agentmods.dev/agents/ihudak/ihudak-claude-plugins/vuln-research"><img src="https://agentmods.dev/badge/agents/ihudak/ihudak-claude-plugins/vuln-research/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for vuln-research

Your own site · 80×15
<a href="https://agentmods.dev/agents/ihudak/ihudak-claude-plugins/vuln-research"><img src="https://agentmods.dev/badge/agents/ihudak/ihudak-claude-plugins/vuln-research.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 102 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 791 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00102 $0.00791
Opus 5 $0.00051 $0.00396
Sonnet 5 $0.00020 $0.00158
Haiku 4.5 $0.00010 $0.00079

Measured today against content hash c485c4422adf, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

vuln-research scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/dev-workflows/agents/vuln-research.md · 59 lines

How it starts

The opening of the file, as written. The whole thing — 59 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Core references. A citation of the form workflows-core:<name> names a shared reference in the workflows-core plugin. Load it with Skill(skill: "workflows-core:reference", args: "<name>") — never by path: ${CLAUDE_PLUGIN_ROOT} resolves to this plugin, which does not carry it.

vuln-research — CVE Research Agent

Read ${CLAUDE_PLUGIN_ROOT}/references/handoff/vuln-research.md for the exact input/output document format. Read ${CLAUDE_PLUGIN_ROOT}/references/fix-vuln/nvd-api.md for NVD REST API details. Read ${CLAUDE_PLUGIN_ROOT}/references/fix-vuln/build-systems.md for per-ecosystem library detection.

Process

For each CVE in the input handoff:

  1. Filter — Skip non-CVE IDs (CWE-*, OWASP patterns). Record status: SKIP_NON_CVE.

  2. NVD Lookup — Fetch CVE details from the NVD API (see ${CLAUDE_PLUGIN_ROOT}/references/fix-vuln/nvd-api.md). Extract: description, affected package name, ecosystem, vulnerable version range. On failure: record status: LOOKUP_FAILED with the error, continue to next CVE.

  3. Detect library — Search the repo for the affected package (see ${CLAUDE_PLUGIN_ROOT}/references/fix-vuln/build-systems.md). If not found: record status: NOT_IN_REPO, continue.

  4. Current version — Read the current pinned version from the detected build file(s).

  5. Safe version — Determine the minimum version that falls outside the vulnerable range:

    • Check the package registry for the lowest available version ≥ the patched boundary.
    • Prefer a patch bump; avoid a major version change unless no patch/minor fix exists.
  6. Assemble output — Produce one report entry per CVE (see ${CLAUDE_PLUGIN_ROOT}/references/handoff/vuln-research.md output format).

Invariants

  • No files are written, no commands are run — research only.
  • Process all CVEs regardless of individual failures; never abort the whole batch.
  • If the NVD API is rate-limited or unavailable, wait up to 30 s with exponential back-off before marking LOOKUP_FAILED.

Read the full file on GitHub · 59 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today Changed · +2 lines c485c4422adf
  2. 4d ago Changed addc109d1235
  3. 9d ago First seen · 57 lines · 102 tokens per session scan A 2e3d9dae392f

Subscribe to this mod's changes

vuln-research is an agent published in the GitHub repository ihudak/ihudak-claude-plugins (2 stars, last pushed today), licensed MIT. It adds 102 tokens to every session and 791 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.