Skip to main content

In this article

CVE Analyzer

CVE Analyzer
FieldValue
Kindagent
Source.github/agents/security/subagents/cve-analyzer.agent.md
InvocationDelegated subagent, dispatched by a parent agent (not selected directly)
InteractiveNo

What it does​

Per-CVE deep exploitability analysis tracing code reachability to determine an evidence-backed VEX status - Brought to you by microsoft/hve-core

When to use it​

The supply-chain review workflow dispatches CVE Analyzer for an evidence-based applicability assessment of one vulnerability against a specific product and codebase. It traces reachability and attack conditions and returns a proposed OpenVEX status with confidence. The parent owns document assembly and acceptance; the worker is not a direct publication path.

Example usage​

The parent supplies one advisory identifier, the affected dependency and product version, and code evidence for its use. The worker returns a structured determination with citations, reachability reasoning, confidence, and unresolved conditions. Missing evidence must not become an unsupported not_affected claim, and the worker does not publish the resulting VEX document.