Agent skill · security · mvanhorn
pp-nvd
Search the U.S. National Vulnerability Database for CVEs, CVSS scores, affected versions, and severity ratings — by keyword, product (CPE name), CVE ID, or date range. Trigger phrases: `look up CVE`, `CVSS score for`, `vulnerabilities in <product>`, `use nvd`.
Why this skill is useful
Provides specific commands for querying the National Vulnerability Database that the AI wouldn't generate on its own.
What it needs
Requires nvd-pp-cli installed locally. About 4k tokens when loaded. Last updated 2026-08-06. 1,890 stars on the source repository.
What this skill does
Nvd — Printing Press CLI Prerequisites: Install the CLI This skill drives the nvd-pp-cli binary. You must verify the CLI is installed before invoking any command from this skill. If it is missing, install it first: 1. Install via the Printing Press installer. It defaults binaries to $HOME/.local/bin on macOS/Linux and %LOCALAPPDATA%\Programs\PrintingPress\bin on Windows: 2. Verify: nvd-pp-cli --version 3. Ensure the reported install directory is on $PATH for the agent/runtime that will invoke this skill. If the npx install fails (no Node, offline, etc.), fall back to a direct Go install (requires Go 1.26.6 or newer): If --version reports "command not found" after install, the runtime cannot see the binary directory on $PATH. Do not proceed with skill commands until verification succeeds. When Not to Use This CLI Do not activate this CLI for requests that require creating, updating, deleting, publishing, commenting, upvoting, inviting, ordering, sending messages, booking, purchasing, or changing remote state. This printed CLI exposes read-only commands for inspection, export, sync, and analysis. Command Reference json — Manage json nvd-pp-cli json search-cpes — Search Common Platform Enumeration names to find exact product identifiers for vulnerability lookups. nvd-pp-cli json search-cves — Search vulnerabilities by keyword, CVE ID, CPE name, publication date, or CVSS severity. Finding the right command When you know what you want to do but not which command does it, ask the CLI directly: which resolves a natural-language capability query to the best matching command from this CLI's curated feature index. Exit code 0 means at least one match; exit code 2 means no confident match — fall back to --help or use a narrower query. Auth Setup No authentication required. Run nvd-pp-cli doctor to verify setup. Agent Mode Add --agent to any command. Expands to: --json --compact --no-input --no-color --yes. …
How to use it
Reference it in AdaL, Claude Code, Cursor or any coding agent — nothing to install:
@skills mvanhorn/nvd