case-bundle-builder - Build auditable vulnerability case bundles
Constructs a complete case-bundle.yaml from vulnerability, repository, and commit evidence while preserving sources and marking fields for review.
Tags
Updated: 2026-10-04vulnerability researchcase bundleOSVGHSAGit analysispatch analysisregression testingengineering evidence
Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Construct complete case bundles
- Query OSV and GHSA
- Resolve repositories and commits
- Preserve patch evidence
- Collect maintainer discussion
- Identify regression tests
- Populate eight schema sections
- Mark fields for review
Inputs
- CVE or GHSA identifier
- Repository URL
- Introduced commit
- Fixed commit
- Package name and ecosystem
- Advisory and discussion links
- Public PoC or report link
- Destination path
- Case identifier
- Reviewer identity
- Canonical schema
- Case bundle template
Outputs
- case-bundle.yaml
- Raw evidence files
- Patch diff artifact
- Normalized pre-bundle snippet
- Regression test records
- Human-review markers
Requirements
- Network access to OSV
- GitHub API access
- Git and repository access
- Canonical schema resources
- Case bundle template
- Human review of starred fields
