ingest-cwe-taxonomies Skill
Ingest the official MITRE CWE database and generate per-domain security audit taxonomies for PromptKit. Use this skill when the user wants to update CWE taxonomies, ingest a new CWE version, or regenerate domain mappings from the CWE corpus. Published by microsoft in PromptKit.
Decision snapshot
Is this a fit?
Database workflows, Security review, Data analysis, Includes SKILL.md
Compatibility not yet detected.
Permission behavior not yet detected.
Copy skill directory
1 month ago · MIT license
No specific cautions were detected. Review the source and requested permissions before installing.
What is ingest-cwe-taxonomies Skill?
Ingest the official MITRE CWE database and generate per-domain security audit taxonomies for PromptKit. Use this skill when the user wants to update CWE taxonomies, ingest a new CWE version, or regenerate domain mappings from the CWE corpus. Published by microsoft in PromptKit. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.
Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement. See how SkillIndex evaluates profiles.
Key capabilities
- Includes SKILL.md support
- Reusable instructions support
- Database workflows
- Security review
- Data analysis
- Database workflows use cases
- Security review use cases
Declared skill metadata
- Source file: .github/skills/ingest-cwe-taxonomies/SKILL.md
These fields retain source and confidence evidence from the indexed SKILL.md.
Compatibility and setup
- Install or run with Copy skill directory
When to use ingest-cwe-taxonomies Skill
- Use it for database workflows.
- Use it for security review.
- Use it for data analysis.
Built with
Editorial notes
Source
- Creator: microsoft
- Repository: microsoft/PromptKit
- Skill file: .github/skills/ingest-cwe-taxonomies/SKILL.md
What it does
Ingest the official MITRE CWE database and generate per-domain security audit taxonomies for PromptKit. Use this skill when the user wants to update CWE taxonomies, ingest a new CWE version, or regenerate domain mappings from the CWE corpus.
Skill instructions
<!-- Generated by PromptKit — edit with care -- You must read and execute the prompt file at .github/prompts/ingest-cwe-taxonomies.prompt.md. Treat it as the complete, self-contained instruction set for the CWE ingestion pipeline. Inputs - CWE source: A local path to a CWE XML file, or latest to download the current release from https://cwe.mitre.org/data/xml/cweclatest.xml.zip. - Any overrides to the domain registry or mapping rules the user specifies. Output - Per-domain taxonomy files at taxonomies/cwe-<domain.md (13 domains) - Normalized CWE data at data/cwe/<version/ - Updated manifest.yaml with new taxonomy entries - Reusable ingestion script at scripts/ingest-cwe.py - Diff report if a previous CWE version exists Workflow 1. Read .github/prompts/ingest-cwe-taxonomies.prompt.md before doing anything else. 2. Ask the user for the CWE source (path or latest). 3. Follow all six phases defined in the prompt file: Acquisition, Normalization, Domain Mapping, Taxonomy Generation, IntegraVerified compatibility and discovery
Frequently asked questions
What is ingest-cwe-taxonomies?
ingest-cwe-taxonomies is a open-source AI agent skill with Copy skill directory. Ingest the official MITRE CWE database and generate per-domain security audit taxonomies for PromptKit.
Who is ingest-cwe-taxonomies best for?
ingest-cwe-taxonomies is best for reusing agent instructions, scripts, and references, database workflows, security review workflows, data analysis workflows.
How do I install ingest-cwe-taxonomies?
Install or run ingest-cwe-taxonomies using Copy skill directory. Check ingest-cwe-taxonomies for the latest setup command.
Is ingest-cwe-taxonomies actively maintained?
ingest-cwe-taxonomies may need a closer maintenance check before production use.
Project health auto-fetched from the source repository.
Maintain this resource?
Review this source-backed profile, send a correction with evidence, or link to it from your documentation. Claims verify your relationship to the project; profile facts still require source evidence and editorial review.