Optimize AI Reports with OMV-Critic: Enhance CNA Acceptance
Regular price
£24.99
Regular price
£24.99
Sale price
Unit price/ per
SAVE
Sold out
Optimize AI Reports with OMV-Critic: Enhance CNA Acceptance
OMV-Critic is an AI agent skill designed to perform a pre-submission review of vulnerability reports. It evaluates and provides feedback on Evidence.v1 findings, along with optional ThreatMap.v1 and Verification.v1 sidecars, enhancing the likelihood of acceptance by CNAs.
What this skill does
Performs an adversarial review of the submitted findings using the `.omv/findings/ .yaml` format and its local schema reference, `contracts/evidence.v1.yaml`.
Reads ThreatMap and Verification sidecars if available, utilizing `contracts/threat-map.v1.yaml` and `contracts/verification.v1.yaml` as schema references.
Validates findings and verifications through tools like `omv findings validate` and `omv verification validate`.
Assesses the quality of arguments and structurally validates the submitted data.
Evaluates the likelihood of acceptance by generating a `reject_risk` rating (low, medium, or high).
Provides recommendations for appropriate `researcher_goal`, including VulDB, CVE, GHSA, or advisory alignment.
For medium or high rejection risk, identifies possible CNA rejection reasons and suggests actionable improvements.
Who it is for
This skill is intended for developers and development teams utilizing AI coding agents such as Claude Code, Cursor, and Codex, who need support in refining and submitting vulnerability reports.
Use cases
Developers preparing vulnerability reports for submission to CNAs.
Teams seeking to improve accuracy and acceptance odds of vulnerability findings.
Organizations wishing to standardize their reporting process for security findings.
Technical details
Integrates with AI coding agents like Claude Code, Cursor, and Codex.
Operates within the context of .yaml structured documentation with predefined schema references.
Employs validation tools and assessment frameworks specific to the OMV ecosystem.
For authorised security testing, defensive research, and educational use only.
Source & Licence
This package is built on open-source work published by bx33661 (bx33661/oh-my-vul) and distributed under MIT. The original licence text and copyright notice are included in your download.
Personal and commercial use, modification and redistribution are permitted, provided the original copyright and licence notice are retained.
Your purchase covers curation, licence verification, packaging, documentation and instant delivery. It does not grant exclusive rights to the underlying open-source code, which remains available under its original licence.
Delivery & Support
Delivery: instant — a secure download link is emailed to you as soon as payment is confirmed.
Format: ZIP archive containing the skill files, documentation and the original licence.
Updates: updates are included only where stated on this page.
Refunds
This is a digital product delivered immediately after purchase. By completing your order you request immediate delivery and acknowledge that, once the download has been accessed, the statutory right to cancel no longer applies to the extent permitted by law. Refund requests are handled in accordance with our published Refund Policy.
Claude, Codex, Gemini and Cursor are trademarks of their respective owners. MCP Cart is an independent marketplace and is not affiliated with, endorsed by, or sponsored by any of them. Compatibility references describe interoperability only.