CVE Alerts for Openclaw

CVE Alerts is an Openclaw Skills workflow that monitors CVE feeds, matches them to your stack, and alerts only on net-new risks.

markjr
v0.1.0
Jul 11, 2026
0
634
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install cve-alerts

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install cve-alerts using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is CVE Alerts?

CVE Alerts is an Openclaw Skills automation for continuously scanning public vulnerability feeds and surfacing only the CVEs that matter to your products, packages, vendors, and internal services. It combines watchlist matching, severity filtering, and suppression logic so your security signal stays actionable and low-noise.

Built for repeatable operations, it stores local state to avoid duplicate notifications, generates a static dashboard for review, and can deliver alerts immediately, as a daily digest, or dashboard-only. That makes Openclaw Skills a strong fit for teams that need lightweight vulnerability monitoring without deploying a full SIEM.

CVE Alerts Use Cases

  • Use Openclaw Skills to monitor CVE feeds for the packages, vendors, and services in your stack.
  • Trigger alerts when new vulnerabilities match your watchlist for technologies like Node.js, Express, Nginx, or PostgreSQL.
  • Suppress known false positives with exact CVE IDs, keywords, regex patterns, and temporary exclusions.
  • Enforce severity thresholds so only critical, high, medium, or low-priority issues reach your workflow.
  • Maintain a static dashboard for security review when you do not want email notifications.
  • Run recurring scans on cron, systemd, or the OpenClaw scheduler for continuous coverage.

How CVE Alerts Works

  1. Load configuration and local state from ~/.config/cve-alerts and the configured dataDir.
  2. Fetch RSS or JSON vulnerability feeds from the CVE sources you have enabled.
  3. Filter incoming items by minSeverity so low-value results are removed early.
  4. Match each vulnerability against the watchlist using case-insensitive partial matching.
  5. Apply suppression rules from cves, keywords, patterns, and temporary expiry-based entries.
  6. Persist seen items so the scanner stays idempotent and only reacts to net-new matches.
  7. Refresh the dashboard output and send alerts according to alertPolicy.
  8. Repeat the scan on a schedule using cron, systemd, or the OpenClaw scheduler.

CVE Alerts Setup

  1. Create the config and state directories.
mkdir -p ~/.config/cve-alerts
mkdir -p ~/.local/share/cve-alerts
  1. Create ~/.config/cve-alerts/config.json with your feed URLs, watchlist terms, alert destination, severity threshold, alert policy, and dataDir.

  2. If you need false-positive control, create ~/.config/cve-alerts/suppressions.json and define exact CVE suppressions, keyword filters, regex patterns, and temporary expirations.

  3. Verify that the agent can reach external RSS or JSON feeds and that the local state directory is writable.

  4. Run the scanner manually to confirm that feed ingestion and matching work as expected.

node scripts/cve-scanner.mjs
  1. Configure recurring execution with cron, systemd timers, or the OpenClaw scheduler for hourly or daily scans.

  2. If you want notifications, configure SMTP and/or Telegram credentials in your deployment. If you prefer a quiet setup, use dashboard-only mode.

  3. Rebuild the static dashboard whenever you want to refresh the HTML view.

node scripts/generate-dashboard.mjs

CVE Alerts Data Schema & Taxonomy

Layer Location Purpose Key metadata
Config ~/.config/cve-alerts/config.json Defines the scanning behavior and routing rules feeds, watchlist, alertEmail, alertPolicy, minSeverity, dataDir
Suppressions ~/.config/cve-alerts/suppressions.json Removes known false positives from the alert stream cves, keywords, patterns, temporary, expires
Local state dataDir such as ~/.local/share/cve-alerts Stores seen items and deduplication state net-new CVEs, scan history, last-run markers, notification status
Dashboard output Generated static HTML Presents current matches for human review grouped matches, severity buckets, alert mode

Metadata taxonomy

  • Feed metadata: source URL, feed format, fetch time
  • Vulnerability metadata: CVE ID, title, summary, CVSS score, severity bucket
  • Matching metadata: matched watchlist term, case-insensitive partial match, affected product or package
  • Suppression metadata: suppression type, reason, temporary expiry date
  • Alert metadata: delivery channel, alert policy, last-alerted timestamp, deduplication flag

CVE Alerts Advanced Features

  • RSS and JSON feed ingestion for multiple vulnerability sources
  • Case-insensitive partial watchlist matching for products, packages, vendors, and internal names
  • Multi-layer suppression rules using exact CVE IDs, keywords, regex patterns, and temporary expirations
  • Severity thresholds from low through critical for flexible triage
  • Idempotent scanning that alerts only on net-new matches
  • Immediate email, daily digest, or dashboard-only alert modes
  • Static dashboard generation for lightweight security review
  • Scheduled execution via cron, systemd timers, or the OpenClaw scheduler
  • Optional SMTP or Telegram notification delivery when you want push alerts beyond the dashboard

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*