In this article
CVE Analyzer
| Field | Value |
|---|---|
| Kind | agent |
| Source | .github/agents/security/subagents/cve-analyzer.agent.md |
| Invocation | Delegated subagent, dispatched by a parent agent (not selected directly) |
| Interactive | No |
What it does
Per-CVE deep exploitability analysis tracing code reachability to determine an evidence-backed VEX status - Brought to you by microsoft/hve-core
When to use it
The supply-chain review workflow dispatches CVE Analyzer for an evidence-based applicability assessment of one vulnerability against a specific product and codebase. It traces reachability and attack conditions and returns a proposed OpenVEX status with confidence. The parent owns document assembly and acceptance; the worker is not a direct publication path.
Example usage
The parent supplies one advisory identifier, the affected dependency and product version, and code evidence for its use. The worker returns a structured determination with citations, reachability reasoning, confidence, and unresolved conditions. Missing evidence must not become an unsupported not_affected claim, and the worker does not publish the resulting VEX document.