Vulnerability Exploitability Scan
Independent PiSkill directory guide. The original prompt remains hosted by Microsoft HVE Core.
What does this prompt do?
Scans dependency and vulnerability evidence to determine which findings need exploitability analysis rather than treating every advisory as equally actionable.
Primary use case
Identify vulnerabilities that require a VEX decision.
Expected output
A scoped list of candidate vulnerabilities with supporting evidence.
Inputs or variables
- dependency inventory
- vulnerability data
- product context
Related prompts
Secure Supply Chain Plan from PRD
Derives software-supply-chain controls from product requirements, covering dependencies, provenance, builds, artifacts, releases, ownership, and verification.
Incident Response Plan
Structures an incident response workflow around evidence collection, containment, recovery and follow-up actions.
LLM Security Review
Reviews an LLM or agent solution for prompt injection, unsafe tool access, data exposure, trust-boundary failures, weak validation, and operational controls.
Responsible AI Evidence Capture
Captures responsible-AI requirements, stakeholders, harms, controls, evidence, ownership, and unresolved questions in a consistent planning artifact.
Responsible AI Plan from PRD
Turns a product requirements document into a responsible-AI plan covering likely harms, mitigations, validation, monitoring, governance, and accountable owners.
Responsible AI Plan from Security Plan
Extends an existing security plan with model-specific harms, misuse, data, evaluation, transparency, monitoring, and governance requirements.