Blackpoint Vulnerability Management — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Blackpoint Vulnerability Management (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
CompassOne exposes four exposure lenses against a tenant's assets: host-level vulnerabilities, scan history, dark-web leaks, and internet-facing external exposures. This skill covers all four and how to combine them into a prioritized remediation view.
| Tool | Purpose |
|---|---|
blackpoint_vulnerabilities_list | Host-level vulnerability findings |
blackpoint_vulnerabilities_scans_list | Vulnerability scan history and status |
blackpoint_vulnerabilities_darkweb_list | Dark-web exposures (leaked data) |
blackpoint_vulnerabilities_external_list | Internet-facing external exposures |
blackpoint_vulnerabilities_list accepts:
tenant_id, asset_id — scopeseverity — low, medium, high, criticalstatus — open, fixed, ignored, false_positivecve_id — pivot on a specific CVEpatch_available — is a fix published?exploit_available — is it weaponized in the wild?The fix-now cohort is the intersection: severity in {high, critical}, status: open, exploit_available: true, patch_available: true — a known, weaponized, fixable problem that has not been fixed.
blackpoint_vulnerabilities_darkweb_list exposure types: credentials, documents, data_breach, malware.
blackpoint_vulnerabilities_external_list exposure types: open_port, vulnerable_service, certificate_issue, misconfiguration.
blackpoint_vulnerabilities_scans_list status values: pending, running, completed, failed.
blackpoint_vulnerabilities_scans_list — if the lastcompleted scan is stale or recent scans failed, say so; it caps confidence in everything below.
blackpoint_vulnerabilities_list for the tenant.separately with a compensating-controls note.
blackpoint_vulnerabilities_darkweb_list for the tenant.credentials exposures, recommend forced password resets andan MFA enforcement check.
data_breach and malware exposures for follow-up.blackpoint_vulnerabilities_external_list for the tenant.vulnerable_service andopen_port on management ports as highest priority.
certificate_issue findings for a complete edge view.checking scan recency first; old data misleads the reader.
they need compensating controls, not a patch ticket.
the MCP cannot mark findings fixed.
availability change the priority order materially.
tell complementary stories.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.