vex Skill
OpenVEX v0.2.0 specification reference plus VEX management playbooks - Brought to you by microsoft/hve-core. Published by microsoft in hve-core.
Decision snapshot
Is this a fit?
Security review, Data analysis, Includes SKILL.md, Reusable instructions
Compatibility not yet detected.
Permission behavior not yet detected.
Copy skill directory
2 months ago · MIT license
No specific cautions were detected. Review the source and requested permissions before installing.
What is vex Skill?
OpenVEX v0.2.0 specification reference plus VEX management playbooks - Brought to you by microsoft/hve-core. Published by microsoft in hve-core. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.
Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement. See how SkillIndex evaluates profiles.
Key capabilities
- Includes SKILL.md support
- Reusable instructions support
- Security review
- Data analysis
- Security review use cases
- Data analysis use cases
Declared skill metadata
- Declared license: Apache-2.0 AND CC-BY-4.0
- Source file: .github/skills/security/vex/SKILL.md
These fields retain source and confidence evidence from the indexed SKILL.md.
Compatibility and setup
- Install or run with Copy skill directory
When to use vex Skill
- Use it for security review.
- Use it for data analysis.
Built with
Editorial notes
Source
- Creator: microsoft
- Repository: microsoft/hve-core
- Skill file: .github/skills/security/vex/SKILL.md
What it does
OpenVEX v0.2.0 specification reference plus VEX management playbooks - Brought to you by microsoft/hve-core.
Skill instructions
VEX skill This skill is the entrypoint for VEX operations in hve-core. It combines the OpenVEX v0.2.0 specification reference with reusable management playbooks for implementing, reviewing, and validating VEX documents. The normative reference material below remains the authoritative source for schema, status logic, and public-source guidance. VEX management playbooks Detection, drafting, and attestation are workflow-owned automation. This skill supplies the reusable procedures, mutation rules, and review criteria. The CVE Analyzer subagent performs the per-CVE exploitability analysis that feeds those workflows. Implement VEX in a target project Use this playbook when standing up VEX in a target project. Scaffold the VEX document under security/vex, wire the vex-detect and vex-draft workflows, reference the PR-body scaffold in assets/pr-body-scaffold.yml, connect the dedicated reusable VEX attestation workflow for provenance and OpenVEX-over-SBOM attestation, and set CODEOWNERS on the
Verified compatibility and discovery
Frequently asked questions
What is vex?
vex is a open-source AI agent skill with Copy skill directory. OpenVEX v0.2.0 specification reference plus VEX management playbooks - Brought to you by microsoft/hve-core.
Who is vex best for?
vex is best for reusing agent instructions, scripts, and references, security review workflows, data analysis workflows.
How do I install vex?
Install or run vex using Copy skill directory. Check vex for the latest setup command.
Is vex actively maintained?
vex may need a closer maintenance check before production use.
Project health auto-fetched from the source repository.
Maintain this resource?
Review this source-backed profile, send a correction with evidence, or link to it from your documentation. Claims verify your relationship to the project; profile facts still require source evidence and editorial review.