Favicon of vex

vex Skill

AI Agent SkillPowerShellOpen source

OpenVEX v0.2.0 specification reference plus VEX management playbooks - Brought to you by microsoft/hve-core. Published by microsoft in hve-core.

Decision snapshot

Is this a fit?

Best for

Security review, Data analysis, Includes SKILL.md, Reusable instructions

Works with

Compatibility not yet detected.

Access

Permission behavior not yet detected.

Setup

Copy skill directory

Project health

2 months ago · MIT license

Considerations

No specific cautions were detected. Review the source and requested permissions before installing.

What is vex Skill?

OpenVEX v0.2.0 specification reference plus VEX management playbooks - Brought to you by microsoft/hve-core. Published by microsoft in hve-core. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.

Trust signal
95/100
Maintenance signal
90/100
Adoption signal
77/100

Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement. See how SkillIndex evaluates profiles.

Key capabilities

  • Includes SKILL.md support
  • Reusable instructions support
  • Security review
  • Data analysis
  • Security review use cases
  • Data analysis use cases

Declared skill metadata

  • Declared license: Apache-2.0 AND CC-BY-4.0
  • Source file: .github/skills/security/vex/SKILL.md

These fields retain source and confidence evidence from the indexed SKILL.md.

Compatibility and setup

Copy skill directory
  • Install or run with Copy skill directory

When to use vex Skill

  • Use it for security review.
  • Use it for data analysis.

Built with

PowerShellCopy skill directory

Editorial notes

Source

  • Creator: microsoft
  • Repository: microsoft/hve-core
  • Skill file: .github/skills/security/vex/SKILL.md

What it does

OpenVEX v0.2.0 specification reference plus VEX management playbooks - Brought to you by microsoft/hve-core.

Skill instructions

VEX skill This skill is the entrypoint for VEX operations in hve-core. It combines the OpenVEX v0.2.0 specification reference with reusable management playbooks for implementing, reviewing, and validating VEX documents. The normative reference material below remains the authoritative source for schema, status logic, and public-source guidance. VEX management playbooks Detection, drafting, and attestation are workflow-owned automation. This skill supplies the reusable procedures, mutation rules, and review criteria. The CVE Analyzer subagent performs the per-CVE exploitability analysis that feeds those workflows. Implement VEX in a target project Use this playbook when standing up VEX in a target project. Scaffold the VEX document under security/vex, wire the vex-detect and vex-draft workflows, reference the PR-body scaffold in assets/pr-body-scaffold.yml, connect the dedicated reusable VEX attestation workflow for provenance and OpenVEX-over-SBOM attestation, and set CODEOWNERS on the

Verified compatibility and discovery

Frequently asked questions

What is vex?

vex is a open-source AI agent skill with Copy skill directory. OpenVEX v0.2.0 specification reference plus VEX management playbooks - Brought to you by microsoft/hve-core.

Who is vex best for?

vex is best for reusing agent instructions, scripts, and references, security review workflows, data analysis workflows.

How do I install vex?

Install or run vex using Copy skill directory. Check vex for the latest setup command.

Is vex actively maintained?

vex may need a closer maintenance check before production use.

Share:

Stars
1,263
Forks
229
Last commit
2 months ago
Last verified
Aug 27, 2026
Metadata fetched
Aug 27, 2026
Repository age
10 months
License
MIT

Project health auto-fetched from the source repository.

Maintain this resource?

Review this source-backed profile, send a correction with evidence, or link to it from your documentation. Claims verify your relationship to the project; profile facts still require source evidence and editorial review.

Alternatives to vex