← NightVisionCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to NightVision
Snapshot Sep 30, 2026 · 23:13 UTC · version 0.2.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "scan-triage",
"description": "Guide for agents to help users interpret and act on NightVision DAST scan results. Use when reading SARIF/CSV findings, explaining vulnerabilities, locating vulnerable code, validating findings with curl, prioritizing by severity, suggesting remediations, or marking false positives.",
"included_files": [
{
"relative_path": "references/vulnerability-guide.md",
"size_in_bytes": 5680
}
],
"skill_md_contents": "---\nname: scan-triage\ndescription: Guide for agents to help users interpret and act on NightVision DAST scan results. Use when reading SARIF/CSV findings, explaining vulnerabilities, locating vulnerable code, validating findings with curl, prioritizing by severity, suggesting remediations, or marking false positives.\nallowed-tools: Bash, Read, Grep\n---\n\n# NightVision Scan Triage\n\nUse this skill when helping users understand and act on NightVision scan results. NightVision produces findings from two scanning engines — ZAP (active and passive rules) and Nuclei (CVE and misconfiguration templates) — and exports them as SARIF or CSV.\n\n## Agent workflow\n\nWhen a user asks for help with scan results:\n\n1. **Check prerequisites** — verify the NightVision CLI is available (`nightvision --help`) if you need to export results\n2. **Locate the results** — look for `results.sarif` or `results.csv` in the repo, or ask the user for the scan ID to export them\n3. **Read and parse the findings** — use the Read tool for SARIF (JSON) files; CSV is tabular (see formats below)\n4. **Explain each finding** — for each, present: severity, finding name, affected endpoint (method + path), one-line explanation, and suggested remediation\n5. **Locate the vulnerable code** — use Code Traceback annotations in SARIF to find the exact file and line, then use Read/Grep to show the code in context\n6. **Help the user validate** — construct curl commands to reproduce the finding\n7. **Suggest remediation** — provide concrete fix patterns for the vulnerability class (see [references/vulnerability-guide.md](references/vulnerability-guide.md))\n8. **Help prioritize** — triage by severity and exploitability\n\n**Related skills:** Use `scan-configuration` for setting up scans, `ci-cd-integration` for pipeline setup, `api-discovery` for spec extraction.\n\n## Exporting results\n\nIf the user doesn't know their scan ID, list recent scans to find it:\n\n```bash\nnightvision scan list -p my-project\n```\n\nIf the user has a scan ID but no exported file:\n\n```bash\n# SARIF with Code Traceback (API targets — provide the spec used for the scan)\nnightvision export sarif -s \"$SCAN_ID\" --swagger-file openapi-spec.yml -o results.sarif\n\n# SARIF without Code Traceback (WEB targets, or when no spec is available)\nnightvision export sarif -s \"$SCAN_ID\" -o results.sarif\n\n# CSV (flat, good for quick overview)\nnightvision export csv -s \"$SCAN_ID\" -o results.csv\n```\n\n`--swagger-file` is optional. When provided, SARIF output includes Code Traceback source annotations (file/line mappings). When omitted, the SARIF is still valid but won't contain source code locations.\n\n## Reading SARIF files\n\nSARIF (Static Analysis Results Interchange Format) is JSON. Key structure:\n\n```\nruns[0].tool.driver.rules[] — vulnerability type definitions\nruns[0].results[] — individual finding instances\n .ruleId — maps to rules[] for description\n .level — \"error\" (high), \"warning\" (medium), \"note\" (low/info)\n .message.text — human-readable finding summary\n .locations[].physicalLocation — file path and line (Code Traceback)\n .properties — NightVision-specific metadata\n```\n\nThe agent should read the SARIF JSON, iterate over `results[]`, and explain each finding using the corresponding `rules[]` entry.\n\n### Code Traceback in SARIF\n\nWhen API Discovery generated the OpenAPI spec, it annotated endpoints with source file paths and line numbers. These appear in SARIF as `physicalLocation` entries, letting the agent navigate directly to the vulnerable code:\n\n```json\n\"locations\": [{\n \"physicalLocation\": {\n \"artifactLocation\": { \"uri\": \"src/main/java/api/UserController.java\" },\n \"region\": { \"startLine\": 42 }\n }\n}]\n```\n\nThe agent should read that file and show the user the vulnerable code in context.\n\n## Reading CSV files\n\nCSV columns: `finding_name`, `kind_id`, `id`, `url`, `path`, `method`, `parameter`, `payload`, `evidence`, `severity`, `ai_explanation`\n\nKey fields for triage:\n- **finding_name** + **severity** — what it is and how serious\n- **url** + **path** + **method** — which endpoint was vulnerable\n- **parameter** + **payload** — how NightVision exploited it\n- **evidence** — proof from the server response\n- **ai_explanation** — NightVision's AI-generated explanation\n\n## Severity levels\n\n| Severity | Meaning | Agent action |\n|----------|---------|-------------|\n| High | Exploitable, significant impact (data breach, RCE, auth bypass) | Fix immediately, explain the attack scenario |\n| Medium | Exploitable but lower impact, or requires specific conditions | Fix soon, explain the risk |\n| Low | Minor issues, information leaks, best practice violations | Fix when convenient, explain the hygiene benefit |\n| Informational | Observations, not directly exploitable | Mention if relevant, don't alarm |\n\n## Validating findings with curl\n\nNightVision's web UI provides a \"Validate with curl\" button. The agent can construct equivalent curl commands from the SARIF/CSV data:\n\n```bash\n# From CSV fields: method, url, parameter, payload\ncurl -X POST \"https://api.example.com/login\" \\\n -d \"username=admin' OR '1'='1&password=test\" \\\n -v\n```\n\nThe response should contain the evidence that confirms the vulnerability. Show the user the relevant part of the response.\n\n## Common vulnerability types and remediations\n\nSee [references/vulnerability-guide.md](references/vulnerability-guide.md) for a reference of common finding types, what they mean, and how to fix them.\n\n### Quick reference for the most frequent findings\n\n**SQL Injection** (CWE-89) — User input reaches a SQL query without parameterization.\n- Fix: Use parameterized queries / prepared statements. Never concatenate user input into SQL.\n\n**Cross-Site Scripting / XSS** (CWE-79) — User input is reflected in HTML without encoding.\n- Fix: Encode output for the context (HTML entity encoding, JavaScript escaping). Use framework auto-escaping.\n\n**Server-Side Request Forgery / SSRF** (CWE-918) — User input controls a server-side HTTP request target.\n- Fix: Validate and allowlist target URLs. Block internal/private IP ranges.\n\n**Remote Code Execution / RCE** (CWE-94) — User input is executed as code on the server.\n- Fix: Never pass user input to eval, exec, or system commands. Use allowlists for permitted operations.\n\n**Path Traversal** (CWE-22) — User input accesses files outside intended directories.\n- Fix: Canonicalize paths, validate against an allowlist, use chroot or sandboxed file access.\n\n**Broken Authentication** (CWE-287) — Authentication mechanisms can be bypassed or exploited.\n- Fix: Use established auth libraries. Enforce strong password policies, MFA, and session management.\n\n## Helping the user decide: real vs. false positive\n\nGuide the user through this decision:\n\n1. **Validate with curl** — does the attack actually work when replayed?\n2. **Check the evidence** — does the server response confirm exploitation?\n3. **Review the code** — is the vulnerable pattern actually reachable in production?\n4. **Consider the context** — is this a test endpoint, internal-only, or behind additional access controls?\n\nIf the finding is a false positive, the user can mark it in the NightVision web UI (app.nightvision.net) under the scan results. Status options: **Open**, **False Positive**, **Resolved**.\n\n## NightVision scanning engines\n\n**ZAP Active Rules** — Sends attack payloads to test for exploitable vulnerabilities. Covers SQL injection variants, XSS types, RCE, SSTI, Log4Shell, JWT attacks, directory traversal, and more.\n\n**ZAP Passive Rules** — Analyzes responses without attacking. Detects missing security headers, cookie misconfigurations, information leaks, CSRF token absence, credential exposure.\n\n**Nuclei Templates** — Template-based detection of known CVEs and misconfigurations.\n\nSpecific rules can be disabled per scan with `--disable-zap-active-alerts <ids>` or `--disable-nuclei-folders <paths>`, or entire engines with `--no-zap` / `--no-nuclei`.\n"
}SHA-256: 77f7506cee8a86da3ebcf046af9b1b13abbac9ecca8130ec5bda2e00b9da3bdf