kev-triage

kev-triage is a skill for Claude Code, Codex from cruxible-ai/cruxible. It costs 32 tokens per session (1,490 once invoked), scanned A, original, Apache-2.0.

Instructions for making evidence-based proposals in a KEV triage system. KEV refers to CISA's catalogue of known exploited security vulnerabilities.

In plain words
What is it for?
Use it to inspect vulnerability-triage status, review pending groups, prepare daily summaries, and propose changes for a reviewer.
Why use it?
It separates findings from reviewer decisions and sets boundaries for evidence, permissions, waivers, and remediation proposals.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Use it to inspect vulnerability-triage status, review pending groups, prepare daily summaries, and propose changes for a reviewer.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/cruxible-ai/cruxible/kev-triage
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add cruxible-ai/cruxible --skill kev-triage
Clone the repo
git clone --depth 1 https://github.com/cruxible-ai/cruxible

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for kev-triage

README.md
[![agentmods](https://agentmods.dev/badge/skills/cruxible-ai/cruxible/kev-triage/github.svg)](https://agentmods.dev/skills/cruxible-ai/cruxible/kev-triage)
Your own site
<a href="https://agentmods.dev/skills/cruxible-ai/cruxible/kev-triage"><img src="https://agentmods.dev/badge/skills/cruxible-ai/cruxible/kev-triage/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for kev-triage

Your own site · 80×15
<a href="https://agentmods.dev/skills/cruxible-ai/cruxible/kev-triage"><img src="https://agentmods.dev/badge/skills/cruxible-ai/cruxible/kev-triage.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 32 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,490 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00032 $0.01490
Opus 5 $0.00016 $0.00745
Sonnet 5 $0.00006 $0.00298
Haiku 4.5 $0.00003 $0.00149

Measured 12d ago against content hash 908af69a7de5, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

kev-triage scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

kits/kev-triage/skills/kev-triage/SKILL.md · 157 lines

How it starts

The opening of the file, as written. The whole thing — 157 lines — stays where its author put it; the contents beside it link to each section on GitHub.

KEV Security Triage

Use this skill when operating an already-onboarded KEV triage local. Keep this as the judgment layer only. Command syntax belongs in command help; query and relationship catalogs belong in generated config views and generated README blocks.

Operating Rule

The agent proposes; a reviewer resolves. Do not resolve groups unless the user explicitly asks you to act as that reviewer for this run. Use cruxible group propose for reviewable changes and cruxible group resolve only when that reviewer role has been delegated.

Before proposing, confirm the active instance with cruxible context show, check the current counts through the stats surface, and inspect pending review work with cruxible group list. For a specific read surface, inspect required params with cruxible query describe instead of copying query names into this skill.

If the daemon refuses a write or permission check, surface the exact error and stop. Do not retry with broader authority unless the user explicitly asks for operator maintenance.

Evidence Boundary

Scanner findings, EDR detections, SIEM alerts, reports, postmortems, tickets, and review packets are evidence references in this kit. They are never graph entities. Preserve them through artifacts, provider outputs, workflow traces, tri-state signal evidence, receipts, proposal-member evidence refs, and evidence rationale.

When evidence says a host was affected, remediated, excepted, or covered by a control, use it to support or challenge the relevant governed relationship surface. Do not turn the source record itself into an entity.

control_mitigates_class is curated local state. If report evidence shows the mapping is missing, stale, too broad, or too narrow, report a data/config authoring issue instead of proposing that relationship as governed review work.

Do not attach numeric confidence to governed proposals or accepted relationships. This kit uses declared tri-state signals only: support, unsure, or contradict, plus evidence text and thesis facts. Provider scores may inform signal mapping; they should not be copied into proposal properties.

Read the full file on GitHub · 157 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 157 lines · 32 tokens per session scan A 908af69a7de5

Subscribe to this mod's changes

kev-triage is a skill published in the GitHub repository cruxible-ai/cruxible (17 stars, last pushed today), licensed Apache-2.0. It adds 32 tokens to every session and 1,490 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

rijksmuseum-mcp-plus

Research workflows for the Rijksmuseum MCP+ server, addressing Dutch arts, crafts, and history across the museum's holdings. Capabilities include keyword, structured, and semantic text search, AI-driven image analysis, geospatial queries, collection statistics, Iconclass-driven iconographic discovery, AAM/CMOA-aligned…

kintopp/rijksmuseum-mcp-plus · 136 tokens

en-quire

Instructions for using en-quire MCP tools to read, search, edit, and manage markdown and YAML documents. Use this skill whenever working with .md, .mdx, .yaml, or .yml files — SOPs, skill files, session memory, codex articles, specs, and configuration files. Covers section-addressed editing, structural search, YAML…

nullproof-studio/en-quire · 115 tokens

code-graph

Query the Code Graph knowledge graph for this codebase. Use when the user asks about code structure, call relationships, dependencies, blast radius, or wants to run SPARQL queries against the project graph. Requires the backend and MCP server to be running.

valarpirai/code-graph · 55 tokens

Agent Audit Trail

Append-only, hash-chained audit log for AI agents. Records agent actions, tool calls, decisions, and external writes with provenance, timestamps, and sha256 chain integrity. Designed for compliance with EU AI Act Article 12 automatic event recording requirements for high-risk AI systems.

lxyeternal/MalSkillBench · 59 tokens

governance-hotl

OpenMesha governance — fail-closed policy, HOTL for irreversible actions, audit log inspection. Use when reviewing denials, escalations, or audit trails.

ANAMIZED/OpenMesha · 39 tokens

governance-audit

Inspect Server OS policy decisions, capability grants, and the audit log.

ANAMIZED/Server-OS · 20 tokens