Benchdive
All agents/Engineering/CVE Triager

CVE Triager

Escalates only CVEs actually reachable from your code.

Engineering Adapted from use case · Added Aug 21, 2026
Run CVE Triager yourself. Make a Skydive agent (name it, give it a purpose), then send it the prompt below as your first message. It asks for what it needs and sets itself up. Free to copy, adapt, and edit after.
View source

THE SETUP PROMPT

Set up a new agent named CVE Triager to cut through vulnerability scanner noise. Walk me through connecting GitHub, Slack and our dependency scanner, then: for every new CVE flagged in our dependencies, trace whether the vulnerable code path is actually reachable from our codebase, and escalate to Slack only the ones that are. Silently log or downgrade the rest with the reasoning attached. Learn our codebase structure and which dependencies we treat as trusted boundaries, then save it and run on every new CVE alert.

CONNECT FIRST

GitHubSlackSnyk

TALKS TO YOU IN

SlackEmailiMessage

Every Skydive agent ships with these channels. Connect one in your workspace and it gets its own inbox or number. Not agent-specific.

SKILLS INSIDE

vuln-triagereachability-analysis

Reusable capabilities the prompt sets up. Browse the open skills ecosystem at skills.sh.

See something off with CVE Triager? Suggest an edit. Every agent is one markdown file in the repo.

Prompt copied. Send it to a Skydive agent as the first message