Vulnerability Triage

Ranks your CVEs by severity and real-world exploitability, so you know what to patch first — factoring in which assets are affected and who owns them.

The Vulnerability Triage skill scores every candidate CVE on three dimensions: severity (CVSS), real-world exploitability (CISA KEV, EPSS, plus Lansweeper’s ransomware/threat-actor/botnet exploitation signals), and environment exposure (affected asset count, criticality, and EOL/unsupported platform status) pulled from Lansweeper’s live vulnerability data. It works from a pasted CVE list, an uploaded scanner export (Qualys, Nessus, Tenable, Rapid7), or nothing at all — querying the environment directly when no list is given. The output is a ranked top 10 with a plain-language rationale per CVE, with any score lacking real exposure data flagged explicitly. An optional Word write-up or Excel tracker can be generated afterward for change-board review or remediation tracking.

Why Vulnerability Triage Matters Here

Vulnerability backlogs sit at the intersection of two questions that get asked separately but need one answer:

  • IT perspective

    “What’s realistically going into this week’s patch window?”
    Exposure: how many devices does this touch, and are they servers or workstations?
    Sequencing: which fixes are patchable now versus sitting on EOL platforms with no fix coming?

  • Security perspective

    “Which of these are actually being exploited right now?”
    Exploitability: is this CVE on CISA’s KEV list, or linked to ransomware, threat actors, or botnets?
    Defensibility: can I justify to leadership why #1 outranks #7 on the list?

This skill produces a single, scored ranking both teams can work from.

Requirements

Lansweeper MCP

https://mcp.lansweeper.com/mcp

Lansweeper plan

Starter, Pro, Enterprise

LLM

Claude 3.5+, Gemini, ChatGPT, Copilot

Step by step setup guide

Step 1 — Download
Download the skill package for your platform by selecting Claude, ChatGPT, Gemini, or Copilot.

Step 2 — Install

  • Claude: install as a plugin/skill in Claude Desktop or Claude Code.
  • ChatGPT: install as an app (Settings > Apps & Connectors, Developer Mode).
  • Gemini (Antigravity): load the SKILL.md into your Antigravity agent’s skill folder.
  • Copilot: import it as a solution in Power Platform / Copilot Studio (Solutions > Import solution) — this creates the “Vulnerability Triage” agent.

Step 3 — Connect Lansweeper
All four need the Lansweeper MCP connector for exposure-scored results; without it, each falls back to public CVE data only.

  • Claude: connect the Lansweeper MCP connector and sign in.
  • ChatGPT: connect Lansweeper MCP — pick the EU or US endpoint based on your tenant.
  • Gemini (Antigravity): connect a Lansweeper MCP connector separately — Gemini doesn’t ship one built in.
  • Copilot: connect the Lansweeper MCP connector under the agent’s Tools.

Step 4 — Provide a vulnerability list
Paste a list of CVE IDs, or upload a vulnerability scanner export (Qualys, Nessus, Tenable, Rapid7, Lansweeper). This step is required on all four platforms right now — a broad, listless ask doesn’t reliably trigger the skill yet.

Step 5 — Ask

  • Claude: “what should we patch first?”
  • ChatGPT: trigger with $vulnerability-triage, or a plain ask like “rank these CVEs.”
  • Gemini (Antigravity): “prioritize these vulnerabilities.”
  • Copilot: “what should we patch first?” in the agent’s chat.