CVE Alerts is an Openclaw Skills workflow that monitors CVE feeds, matches them to your stack, and alerts only on net-new risks.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install cve-alerts
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install cve-alerts using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
CVE Alerts is an Openclaw Skills automation for continuously scanning public vulnerability feeds and surfacing only the CVEs that matter to your products, packages, vendors, and internal services. It combines watchlist matching, severity filtering, and suppression logic so your security signal stays actionable and low-noise.
Built for repeatable operations, it stores local state to avoid duplicate notifications, generates a static dashboard for review, and can deliver alerts immediately, as a daily digest, or dashboard-only. That makes Openclaw Skills a strong fit for teams that need lightweight vulnerability monitoring without deploying a full SIEM.
~/.config/cve-alerts and the configured dataDir.minSeverity so low-value results are removed early.cves, keywords, patterns, and temporary expiry-based entries.alertPolicy.mkdir -p ~/.config/cve-alerts
mkdir -p ~/.local/share/cve-alerts
Create ~/.config/cve-alerts/config.json with your feed URLs, watchlist terms, alert destination, severity threshold, alert policy, and dataDir.
If you need false-positive control, create ~/.config/cve-alerts/suppressions.json and define exact CVE suppressions, keyword filters, regex patterns, and temporary expirations.
Verify that the agent can reach external RSS or JSON feeds and that the local state directory is writable.
Run the scanner manually to confirm that feed ingestion and matching work as expected.
node scripts/cve-scanner.mjs
Configure recurring execution with cron, systemd timers, or the OpenClaw scheduler for hourly or daily scans.
If you want notifications, configure SMTP and/or Telegram credentials in your deployment. If you prefer a quiet setup, use dashboard-only mode.
Rebuild the static dashboard whenever you want to refresh the HTML view.
node scripts/generate-dashboard.mjs
| Layer | Location | Purpose | Key metadata |
|---|---|---|---|
| Config | ~/.config/cve-alerts/config.json |
Defines the scanning behavior and routing rules | feeds, watchlist, alertEmail, alertPolicy, minSeverity, dataDir |
| Suppressions | ~/.config/cve-alerts/suppressions.json |
Removes known false positives from the alert stream | cves, keywords, patterns, temporary, expires |
| Local state | dataDir such as ~/.local/share/cve-alerts |
Stores seen items and deduplication state | net-new CVEs, scan history, last-run markers, notification status |
| Dashboard output | Generated static HTML | Presents current matches for human review | grouped matches, severity buckets, alert mode |
Metadata taxonomy
Loading
sofagent-loop turns one prompt into a gated agent pipeline that writes code, audits changes, reviews results, and returns control to a human.

A utility skill for automating Feishu file uploads, message delivery, and collaborative cloud document creation.

Gmail Lead Desk turns Gmail into an AISA-powered sales and support inbox workflow for Openclaw Skills, with OAuth connect, unread lead triage, thread summaries, safe draft replies, and archiving.

A legal OSINT profiling skill that turns minimal public identifiers into a confidence-scored, 12-dimensional person profile.

A specialized AI skill that calls the ZCM Open API to automate tender file analysis, bid document generation, and compliance auditing.

An AI bidding assistant skill that calls the Zhaocaimao API to analyze tenders, generate Word bidding documents, and perform compliance checks.








































