Advisory Mining -- Finding Incomplete Fixes

SkillDatabases & data

Mine GitHub Security Advisories and CVE databases for incomplete fixes, finding variant vulnerabilities in patched code or similar patterns in related packages.

Use Advisory Mining -- Finding Incomplete Fixes in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Advisory Mining -- Finding Incomplete Fixes and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Advisory Mining -- Finding Incomplete Fixes skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Advisory Mining -- Finding Incomplete FixesStart free

What this skill tells your AI

The instructions your AI receives, as published by byamb4/find-cve-agent in skills/advisory-mining/SKILL.md and read by Ahel’s review.

When to Use

Looking for high-acceptance-rate findings. Incomplete fix variants have ~95% acceptance rate because:

  1. The vulnerability class is already acknowledged
  2. The fix proves the maintainer cares about security
  3. The variant proves the fix was insufficient

Process

Step 1: Find Recent Advisories

# GitHub Advisory API -- recent npm advisories
gh api graphql -f query='
{
  securityAdvisories(first: 20, orderBy: {field: PUBLISHED_AT, direction: DESC}, ecosystem: NPM) {
    nodes {
      ghsaId
      summary
      severity
      publishedAt
      vulnerabilities(first: 5) {
        nodes {
          package { name ecosystem }
          vulnerableVersionRange
          firstPatchedVersion { identifier }
        }
      }
    }
  }
}'

# Search by keyword
gh api "/advisories?ecosystem=npm&keyword=injection&per_page=20"
gh api "/advisories?ecosystem=pip&keyword=traversal&per_page=20"

Step 2: Read the Patch Diff

For each advisory:

  1. Find the fix commit (linked in the advisory or CHANGELOG)
  2. Read the diff carefully
  3. Ask: what did they fix? What did they NOT fix?
# Find security-related commits
git log --oneline --all | grep -i "security\|fix\|vuln\|CVE\|patch\|sanitize"

# Read the patch
git show <commit_hash>
git diff <before_commit>..<fix_commit>

Step 3: Check for Incomplete Fix Patterns

Common incomplete fixes:

What Was FixedWhat Was Missed
../ blocked..\ not blocked (Windows)
__proto__ filteredconstructor.prototype not filtered
One regex fixedSimilar regex in same file not fixed
One function fixedWrapper function calls it differently
Parsing fixedSerialization has same bug
Validation addedCan be bypassed with encoding
One entry point fixedOther entry points not covered
Input sanitizedError messages leak unsanitized data

Step 4: Search for Same Pattern in Other Packages

If the vulnerability is in a common pattern (e.g., path.join without validation), search for it in similar packages:

# Use grep.app to find same pattern across repos
# See cross-pollination skill for details

Step 5: Verify the Variant

Apply the fp-check skill to verify the variant is real before submitting.

NVD API

# Search NVD for CVEs by keyword
curl "https://services.nvd.nist.gov/rest/json/cves/2.0?keywordSearch=xml+parser+javascript"

# Search by CPE
curl "https://services.nvd.nist.gov/rest/json/cves/2.0?cpeName=cpe:2.3:a:vendor:product:*"

CVSS Guidance

Variant findings typically get:

  • Same CVSS as original if the variant has same impact
  • Higher CVSS if the variant bypasses the fix AND adds new impact
  • Lower CVSS if the variant has additional prerequisites

References

Signals

GitHub stars
53
Forks
10
Last commit
Mar 2026
Advanced
Item type
skill
Key
advisory-mining
Source
github.com/byamb4/find-cve-agent