Skip to main content
Skills / CVE Impact Analyzer

CVE Impact Analyzer

Contributed

Determines whether a CVE affects an environment using existing software inventory data from prior scans — no new scan required.

Authorbking34
Invocationnatural language — triggers on 'are we vulnerable to CVE-...', 'which assets are affected by...', 'do we have [software] installed'
LicenseMIT
AddedJul 16, 2026

Compatible Platforms

Claude Code

Integrations

NVDTenableTenable Hexa AI MCP

Tags

cvevulnerability-managementtenablesoftware-inventoryexposure-analysis

A Claude Code skill that determines CVE exposure across your environment using existing Tenable scan data — no new scan required.

What it does

Given a CVE ID, this skill looks up the affected software and version range, searches your Tenable software inventory from prior credentialed scans, compares installed versions against the vulnerable range, and produces a structured impact assessment with per-asset exposure status — confirmed vulnerable, likely vulnerable, patched, or not detected.

How it works

The skill queries the Tenable Hexa MCP to search software inventory built from prior credentialed scans (via enumeration plugins 20811, 22869, 12634, 97993, 83991, 152741). It matches installed software versions against the CVE’s affected range, cross-references any existing Tenable detection plugin findings, and outputs a prioritized asset list with confidence assessment and recommended next steps.