Crawler Summary

cybersecurity-threat-triage answer-first brief

Multi-agent cybersecurity intelligence and dynamic vulnerability triage using CrewAI, Groq, Exa, NVD, CISA KEV, and Streamlit. Multi-Agent Cybersecurity Intelligence & Dynamic Threat Triage System A Python cybersecurity project that combines installed-software vulnerability discovery, threat-intelligence enrichment, multi-agent analysis, and dynamic risk prioritization in a Streamlit dashboard. It supports two workflows: - **Manual CVE analysis:** provide a CVE ID to investigate its vulnerability details, threat evidence, and risk. - **Autom Capability contract not published. No trust telemetry is available yet. Last updated 10/9/2026.

Freshness

Last checked 10/9/2026

Best For

cybersecurity-threat-triage is best for crewai, multi-agent workflows where OpenClaw compatibility matters.

Not Ideal For

Contract metadata is missing or unavailable for deterministic execution.

Evidence Sources Checked

editorial-content, GITHUB REPOS, runtime-metrics, public facts pack

Claim this agent
Agent DossierGITHUB REPOSSafety: 66/100

cybersecurity-threat-triage

Multi-agent cybersecurity intelligence and dynamic vulnerability triage using CrewAI, Groq, Exa, NVD, CISA KEV, and Streamlit. Multi-Agent Cybersecurity Intelligence & Dynamic Threat Triage System A Python cybersecurity project that combines installed-software vulnerability discovery, threat-intelligence enrichment, multi-agent analysis, and dynamic risk prioritization in a Streamlit dashboard. It supports two workflows: - **Manual CVE analysis:** provide a CVE ID to investigate its vulnerability details, threat evidence, and risk. - **Autom

OpenClawself-declared

Public facts

4

Change events

1

Artifacts

0

Freshness

Oct 9, 2026

Verifiededitorial-contentNo verified compatibility signals

Capability contract not published. No trust telemetry is available yet. Last updated 10/9/2026.

Trust evidence available

Trust score

Unknown

Compatibility

OpenClaw

Freshness

Oct 9, 2026

Vendor

Nakshatragupta826 Ctrl

Artifacts

0

Benchmarks

0

Last release

Unpublished

Executive Summary

Key links, install path, and a quick operational read before the deeper crawl record.

Verifiededitorial-content

Summary

Capability contract not published. No trust telemetry is available yet. Last updated 10/9/2026.

Setup snapshot

  1. 1

    Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.

  2. 2

    Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Evidence Ledger

Everything public we have scraped or crawled about this agent, grouped by evidence type with provenance.

Verifiededitorial-content
Vendor (1)

Vendor

Nakshatragupta826 Ctrl

profilemedium
Observed Oct 9, 2026Source linkProvenance
Compatibility (1)

Protocol compatibility

OpenClaw

contractmedium
Observed Oct 9, 2026Source linkProvenance
Security (1)

Handshake status

UNKNOWN

trustmedium
Observed unknownSource linkProvenance
Integration (1)

Crawlable docs

6 indexed pages on the official domain

search_documentmedium
Observed Apr 15, 2026Source linkProvenance

Release & Crawl Timeline

Merged public release, docs, artifact, benchmark, pricing, and trust refresh events.

Self-declaredagent-index

Artifacts Archive

Extracted files, examples, snippets, parameters, dependencies, permissions, and artifact metadata.

Self-declaredGITHUB REPOS

Extracted files

0

Examples

6

Snippets

0

Languages

python

Executable Examples

text

CVE ID entered by user
        |
        v
Vulnerability details and threat evidence
        |
        v
Threat Intelligence Analyst
        |
        v
Risk Assessment Agent
        |
        v
Reflection Agent
        |
        v
Dynamic risk fusion and priority
        |
        v
SQLite database and dashboard

text

Windows installed-software inventory
        |
        v
Normalize product name and version
        |
        v
Map to vendor/product identifiers
        |
        v
Compare installed version with NVD affected-version configurations
        |
        v
Only matching CVEs proceed to deeper triage
        |
        v
Threat evidence + agents + risk fusion
        |
        v
Save results and show dashboard activity

text

final-system/
├── dashboard.py
├── scanner.py
├── pipeline.py
├── risk_fusion.py
├── config.py
├── db.py
├── agents.py
├── crew.py
├── requirements.txt
├── tools/
│   ├── product_normalizer.py
│   ├── software_inventory.py
│   └── vulnerability_discovery.py
├── .env.example
├── .gitignore
└── README.md

powershell

git clone https://github.com/<your-github-username>/<your-repository-name>.git
cd <your-repository-name>

powershell

py -3.11 -m venv .venv
.\.venv\Scripts\Activate.ps1

powershell

.\.venv\Scripts\python.exe --version

Docs & README

Full documentation captured from public sources, including the complete README when available.

Self-declaredGITHUB REPOS

Docs source

GITHUB REPOS

Editorial quality

ready

Multi-agent cybersecurity intelligence and dynamic vulnerability triage using CrewAI, Groq, Exa, NVD, CISA KEV, and Streamlit. Multi-Agent Cybersecurity Intelligence & Dynamic Threat Triage System A Python cybersecurity project that combines installed-software vulnerability discovery, threat-intelligence enrichment, multi-agent analysis, and dynamic risk prioritization in a Streamlit dashboard. It supports two workflows: - **Manual CVE analysis:** provide a CVE ID to investigate its vulnerability details, threat evidence, and risk. - **Autom

Full README

Multi-Agent Cybersecurity Intelligence & Dynamic Threat Triage System

A Python cybersecurity project that combines installed-software vulnerability discovery, threat-intelligence enrichment, multi-agent analysis, and dynamic risk prioritization in a Streamlit dashboard.

It supports two workflows:

  • Manual CVE analysis: provide a CVE ID to investigate its vulnerability details, threat evidence, and risk.
  • Automatic software scanning: inventory supported software on a Windows endpoint, compare installed versions with local NVD vulnerability data, and send matching CVEs into the deeper triage pipeline.

Status: Core workflows have been implemented and tested in the development environment. Detection depends on product coverage, the freshness and completeness of local vulnerability feeds, upstream data quality, and availability of external services. This is an educational/defensive project, not a replacement for a commercial vulnerability-management platform.

Features

  • Windows installed-software inventory using uninstall-registry entries.
  • Product and version normalization.
  • Version-aware matching against local NVD JSON feeds.
  • NVD feed caching to reduce repeated loading during a scan session.
  • Threat-intelligence enrichment using Exa and the project's vulnerability-data integrations.
  • CISA Known Exploited Vulnerabilities (KEV) evidence where available.
  • Three-agent triage workflow:
    1. Threat Intelligence Analyst — summarizes vulnerability and exploitation evidence.
    2. Risk Assessment Agent — assesses severity and dynamic risk factors.
    3. Reflection Agent — reviews the analysis for consistency and completeness.
  • Dynamic risk fusion combining base CVSS severity with exploit-maturity and evidence-recency signals.
  • P0–P3 priority classification.
  • SQLite persistence for scan and triage records.
  • Streamlit dashboard for software scanning, manual CVE analysis, activity logs, and results.
  • Scheduled automatic scanning while the dashboard session remains active.
  • Evaluation support for a labelled CVE set.

How it works

Manual CVE analysis

CVE ID entered by user
        |
        v
Vulnerability details and threat evidence
        |
        v
Threat Intelligence Analyst
        |
        v
Risk Assessment Agent
        |
        v
Reflection Agent
        |
        v
Dynamic risk fusion and priority
        |
        v
SQLite database and dashboard

Manual mode answers: “Given this CVE, what is its current threat context and risk?”

Automatic software scanning

Windows installed-software inventory
        |
        v
Normalize product name and version
        |
        v
Map to vendor/product identifiers
        |
        v
Compare installed version with NVD affected-version configurations
        |
        v
Only matching CVEs proceed to deeper triage
        |
        v
Threat evidence + agents + risk fusion
        |
        v
Save results and show dashboard activity

Automatic mode answers: “Given the software installed on this endpoint, which known vulnerabilities may affect those versions?”

A result such as 0 new CVE(s) triaged means that the scan did not add any new matching CVEs to triage during that pass. It does not prove that the machine is free of all vulnerabilities; coverage and feed limitations apply.

Technology stack

  • Python 3.11 (tested development version)
  • Streamlit
  • CrewAI
  • Groq through LiteLLM
  • Exa threat-intelligence search
  • National Vulnerability Database (NVD) JSON feeds
  • CISA KEV evidence where available
  • SQLite
  • Windows registry for installed-software inventory

Repository layout

Main modules in the current development setup include:

final-system/
├── dashboard.py
├── scanner.py
├── pipeline.py
├── risk_fusion.py
├── config.py
├── db.py
├── agents.py
├── crew.py
├── requirements.txt
├── tools/
│   ├── product_normalizer.py
│   ├── software_inventory.py
│   └── vulnerability_discovery.py
├── .env.example
├── .gitignore
└── README.md

Adjust this diagram if the files in your repository differ.

Requirements

  • Windows 10/11 is the intended endpoint-scanning environment.
  • Python 3.11
  • Git
  • Internet access for external threat-intelligence and LLM integrations.
  • API credentials for the providers enabled in your configuration.

The dashboard or analysis components may run elsewhere, but installed-software discovery is Windows-specific.

Setup

1. Clone the repository

Replace the placeholders with your GitHub username and repository name:

git clone https://github.com/<your-github-username>/<your-repository-name>.git
cd <your-repository-name>

2. Create and activate a virtual environment

py -3.11 -m venv .venv
.\.venv\Scripts\Activate.ps1

If PowerShell blocks activation, use the virtual environment's Python directly:

.\.venv\Scripts\python.exe --version

3. Install dependencies

python -m pip install --upgrade pip
pip install -r requirements.txt

4. Configure API keys

If .env.example is included, create a local .env:

Copy-Item .env.example .env

The development setup uses these variables:

GROQ_API_KEY=your_groq_api_key
EXA_API_KEY=your_exa_api_key

Use real values only in your local .env. Never commit .env, API keys, tokens, or credentials. If a secret was ever committed, revoke or rotate it; deleting it in a later commit does not remove it from Git history.

If config.py or an integration requires other variables, add their names (never their values) to .env.example and document them.

5. Prepare NVD feeds

The scanner uses local NVD JSON feeds for version-aware matching. The development setup used compressed feeds for 2025 and 2026. Obtain the required feeds from the official source and place them at the paths expected by tools/vulnerability_discovery.py.

Official source: NVD Data Feeds

Large feed files are intentionally excluded from Git. Check tools/vulnerability_discovery.py for the exact filenames and paths expected by your local code.

6. Run the dashboard

From the repository root:

streamlit run dashboard.py

Open the local URL printed by Streamlit, usually http://localhost:8501.

Scheduled automatic scanning requires the dashboard session to remain active.

7. Run a one-time software scan

python scanner.py --once

This runs a single installed-software scan using the configured local feeds and integrations.

Risk fusion

The risk-fusion module combines a vulnerability's base CVSS score with dynamic signals, including exploit maturity and the age of threat evidence. The current implementation applies evidence-age decay, caps the fused score at 10, and maps the result to a priority band.

The fused score is a project-specific prioritization aid; it is not an official CVSS score. Check risk_fusion.py for the current weights and P0–P3 thresholds.

Evaluation

The development evaluation used a labelled set of 40 CVEs and reported:

| Metric | Result | |---|---:| | Accuracy | 87.5% | | Precision | 85.7% | | Recall | 90.0% | | F1 score | 87.8% |

These figures describe that particular evaluation set and its labels; they are not a guarantee of real-world detection performance. If publishing these metrics, document the dataset selection, labelling method, test script, and limitations.

Security and limitations

  • This is a student/research project, not a certified vulnerability scanner.
  • Coverage is limited to supported products and version formats.
  • A clean scan does not prove that an endpoint is secure.
  • NVD feed freshness and affected-version configurations influence detection.
  • External API failures, rate limits, and model responses can affect analysis.
  • AI-generated summaries may be incomplete or incorrect. Verify important findings against vendor advisories and trusted primary sources.
  • Do not use the generated priority as the sole basis for production remediation decisions.
  • Test only on systems you own or are explicitly authorized to assess.

Troubleshooting

No matching vulnerabilities detected

Check that the application and version appear in inventory, the product is supported by tools/product_normalizer.py, the expected NVD feeds are present, and the CVE's affected-version configuration includes the installed version. A CVE can exist in NVD without affecting the installed version.

API-key or LLM errors

Check that .env exists, its variable names match config.py, and the credentials are valid. Never paste keys into issues, screenshots, or public logs.

Missing NVD feed files

Check the filenames and paths expected by tools/vulnerability_discovery.py, then download the feeds from the official NVD source.

Dashboard changes do not appear

Stop Streamlit with Ctrl+C in the terminal and restart:

streamlit run dashboard.py

Possible future improvements

  • Broaden software and package-manager coverage.
  • Add scheduled feed refresh and feed-integrity checks.
  • Add unit and integration tests for affected-version matching.
  • Add evidence-linked remediation reports.
  • Improve audit logging and scan error reporting.
  • Evaluate on a larger, independently labelled CVE dataset.
  • Include evidence provenance and confidence in agent outputs.
  • Add packaging and deployment guidance for controlled environments.

Contributing

Issues and pull requests are welcome. Do not include secrets, personal data, or sensitive endpoint details in reports. Provide reproducible test cases with environment-specific details redacted.

License

No license has been selected yet. Until a license is added, assume the repository is all rights reserved by default. Before publishing publicly, choose a license and add a LICENSE file. MIT is a common permissive choice for student projects, but only use it if you have the right to license all included code and assets.

Contract & API

Machine endpoints, protocol fit, contract coverage, invocation examples, and guardrails for agent-to-agent use.

MissingGITHUB REPOS

Contract coverage

Status

missing

Auth

None

Streaming

No

Data region

Unspecified

Protocol support

OpenClaw: self-declared

Requires: none

Forbidden: none

Guardrails

Operational confidence: low

No positive guardrails captured.
Invocation examples
curl -s "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/contract"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/trust"

Reliability & Benchmarks

Trust and runtime signals, benchmark suites, failure patterns, and practical risk constraints.

Missingruntime-metrics

Trust signals

Handshake

UNKNOWN

Confidence

unknown

Attempts 30d

unknown

Fallback rate

unknown

Runtime metrics

Observed P50

unknown

Observed P95

unknown

Rate limit

unknown

Estimated cost

unknown

Do not use if

Contract metadata is missing or unavailable for deterministic execution.
No benchmark suites or observed failure patterns are available.

Media & Demo

Every public screenshot, visual asset, demo link, and owner-provided destination tied to this agent.

Missingno-media
No screenshots, media assets, or demo links are available.

Related Agents

Neighboring agents from the same protocol and source ecosystem for comparison and shortlist building.

Self-declaredprotocol-neighbors
Github ReposUpdated 0h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW
Machine Appendix

Contract JSON

{
  "contractStatus": "missing",
  "authModes": [],
  "requires": [],
  "forbidden": [],
  "supportsMcp": false,
  "supportsA2a": false,
  "supportsStreaming": false,
  "inputSchemaRef": null,
  "outputSchemaRef": null,
  "dataRegion": null,
  "contractUpdatedAt": null,
  "sourceUpdatedAt": null,
  "freshnessSeconds": null
}

Invocation Guide

{
  "preferredApi": {
    "snapshotUrl": "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/snapshot",
    "contractUrl": "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/contract",
    "trustUrl": "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/trust"
  },
  "curlExamples": [
    "curl -s \"https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/snapshot\"",
    "curl -s \"https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/contract\"",
    "curl -s \"https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/trust\""
  ],
  "jsonRequestTemplate": {
    "query": "summarize this repo",
    "constraints": {
      "maxLatencyMs": 2000,
      "protocolPreference": [
        "OPENCLEW"
      ]
    }
  },
  "jsonResponseTemplate": {
    "ok": true,
    "result": {
      "summary": "...",
      "confidence": 0.9
    },
    "meta": {
      "source": "GITHUB_REPOS",
      "generatedAt": "2026-10-09T19:31:01.264Z"
    }
  },
  "retryPolicy": {
    "maxAttempts": 3,
    "backoffMs": [
      500,
      1500,
      3500
    ],
    "retryableConditions": [
      "HTTP_429",
      "HTTP_503",
      "NETWORK_TIMEOUT"
    ]
  }
}

Trust JSON

{
  "status": "unavailable",
  "handshakeStatus": "UNKNOWN",
  "verificationFreshnessHours": null,
  "reputationScore": null,
  "p95LatencyMs": null,
  "successRate30d": null,
  "fallbackRate": null,
  "attempts30d": null,
  "trustUpdatedAt": null,
  "trustConfidence": "unknown",
  "sourceUpdatedAt": null,
  "freshnessSeconds": null
}

Capability Matrix

{
  "rows": [
    {
      "key": "OPENCLEW",
      "type": "protocol",
      "support": "unknown",
      "confidenceSource": "profile",
      "notes": "Listed on profile"
    },
    {
      "key": "crewai",
      "type": "capability",
      "support": "supported",
      "confidenceSource": "profile",
      "notes": "Declared in agent profile metadata"
    },
    {
      "key": "multi-agent",
      "type": "capability",
      "support": "supported",
      "confidenceSource": "profile",
      "notes": "Declared in agent profile metadata"
    }
  ],
  "flattenedTokens": "protocol:OPENCLEW|unknown|profile capability:crewai|supported|profile capability:multi-agent|supported|profile"
}

Facts JSON

[
  {
    "factKey": "vendor",
    "category": "vendor",
    "label": "Vendor",
    "value": "Nakshatragupta826 Ctrl",
    "href": "https://github.com/nakshatragupta826-ctrl/cybersecurity-threat-triage",
    "sourceUrl": "https://github.com/nakshatragupta826-ctrl/cybersecurity-threat-triage",
    "sourceType": "profile",
    "confidence": "medium",
    "observedAt": "2026-10-09T10:46:31.318Z",
    "isPublic": true
  },
  {
    "factKey": "protocols",
    "category": "compatibility",
    "label": "Protocol compatibility",
    "value": "OpenClaw",
    "href": "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/contract",
    "sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/contract",
    "sourceType": "contract",
    "confidence": "medium",
    "observedAt": "2026-10-09T10:46:31.318Z",
    "isPublic": true
  },
  {
    "factKey": "docs_crawl",
    "category": "integration",
    "label": "Crawlable docs",
    "value": "6 indexed pages on the official domain",
    "href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
    "sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
    "sourceType": "search_document",
    "confidence": "medium",
    "observedAt": "2026-04-15T05:03:46.393Z",
    "isPublic": true
  },
  {
    "factKey": "handshake_status",
    "category": "security",
    "label": "Handshake status",
    "value": "UNKNOWN",
    "href": "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/trust",
    "sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-nakshatragupta826-ctrl-cybersecurity-threat-triage/trust",
    "sourceType": "trust",
    "confidence": "medium",
    "observedAt": null,
    "isPublic": true
  }
]

Change Events JSON

[
  {
    "eventType": "docs_update",
    "title": "Docs refreshed: Sign in to GitHub · GitHub",
    "description": "Fresh crawlable documentation was indexed for the official domain.",
    "href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
    "sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
    "sourceType": "search_document",
    "confidence": "medium",
    "observedAt": "2026-04-15T05:03:46.393Z",
    "isPublic": true
  }
]

Sponsored

Ads related to cybersecurity-threat-triage and adjacent AI workflows.