- name
- vulnerability-scanner
- description
- Automated vulnerability scanning with OpenVAS + BlackArch tools, enriched with CVE-MCP data. Full network, web app, and container scans with prioritized remediation reports.
- homepage
- https://github.com/nousresearch/argus
- metadata
- {"openclaw":{"requires":{"bins":"[Truncated]","mcps":"[Truncated]","optional_bins":"[Truncated]"},"os":["linux"]}}
# Vulnerability Scanner
Automated vulnerability scanning pipeline using OpenVAS/Greenbone for network-level scanning, BlackArch tools for targeted assessments, and CVE-MCP for real-time vulnerability intelligence enrichment. Produces prioritized remediation reports with CVSS scoring and exploitability analysis.
Runs on ARGUS infrastructure with 39 BlackArch tools available and MCP bridge to CVE-MCP, pentester-mcp, and aynops.
## Prerequisites
- **ARGUS host** with BlackArch tools installed (39 tools available)
- **OpenVAS/GVM** running (default: `https://localhost:9392`)
- **CVE-MCP** available on localhost for CVE enrichment
- **pentester-mcp** available on localhost for exploit validation
- **aynops** available on localhost for scan orchestration
- `curl`, `jq` on PATH
- `gvm-cli`, `nmap`, `nikto` from BlackArch
## Infrastructure
This skill runs on ARGUS infrastructure:
| Component | Location | Purpose |
|-----------|----------|---------|
| OpenVAS/GVM | `localhost:9392` | Network vulnerability scanning |
| CVE-MCP | localhost MCP | CVE data enrichment + CVSS scoring |
| pentester-mcp | localhost MCP | Exploit validation + PoC lookup |
| aynops | localhost MCP | Scan orchestration + domain recon |
| BlackArch tools | `/usr/share/` | 39 security tools (nmap, nikto, zap, metasploit, etc.) |
## Core Commands
### Quick Network Scan (Nmap + CVE Enrichment)
Run a targeted Nmap scan and enrich findings with CVE data:
```bash
TARGET="192.168.1.0/24"
SCAN_ID="scan-$(date +%Y%m%d-%H%M%S)"
OUTDIR="/tmp/vuln-scans/$SCAN_ID"
mkdir -p "$OUTDIR"
echo "=== Phase 1: Nmap Service Discovery ==="
nmap -sV -sC -O -oA "$OUTDIR/nmap" "$TARGET" 2>&1 | tee "$OUTDIR/nmap-output.txt"
echo ""
echo "=== Phase 2: Extract Service Versions ==="
grep -E "open|filtered" "$OUTDIR/nmap-output.txt" | awk '{print $1, $2, $3}' > "$OUTDIR/services.txt"
cat "$OUTDIR/services.txt"
echo ""
echo "=== Phase 3: CVE Enrichment via CVE-MCP ==="
while IFS= read -r line; do
service=$(echo "$line" | awk '{print $3}')
version=$(echo "$line" | awk '{print $4}')
echo "--- $service $version ---"
curl -s -X POST "http://localhost:8765/cve-mcp/search" \
-H "Content-Type: application/json" \
-d "{\"product\": \"$service\", \"version\": \"$version\"}" | \
jq '{cve_id: .id, cvss: .cvss_score, summary: .description[:120]}' \
2>/dev/null || echo " (CVE-MCP query failed for $service)"
done < "$OUTDIR/services.txt" > "$OUTDIR/cve-enrichment.txt"
```
### Full OpenVAS Scan
Launch a full authenticated GVM scan:
```bash
TARGET="192.168.1.100"
TASK_NAME="vuln-scan-$(date +%Y%m%d-%H%M%S)"
# Create target
TARGET_ID=$(gvm-cli --gmp-username admin --gmp-password "$GVM_PASSWORD" socket \
--xml "<create_target><name>$TASK_NAME-target</name><hosts>$TARGET</hosts></create_target>" | \
grep -oP 'id="\K[^"]+')
echo "Target created: $TARGET_ID"
# Create task with Full and Fast config
TASK_ID=$(gvm-cli --gmp-username admin --gmp-password "$GVM_PASSWORD" socket \
--xml "<create_task><name>$TASK_NAME</name><config id='daba56c8-73ec-11df-a475-002264764cea'/><target id='$TARGET_ID'/></create_task>" | \
grep -oP 'id="\K[^"]+')
echo "Task created: $TASK_ID"
# Start scan
gvm-cli --gmp-username admin --gmp-password "$GVM_PASSWORD" socket \
--xml "<start_task task_id='$TASK_ID'/>"
echo "Scan started. Monitor with: gvm-cli socket --xml '<get_tasks task_id=\"$TASK_ID\"/>'"
```
### OpenVAS Report Generation
Generate and prioritize a report:
```bash
TASK_ID="your-task-id"
REPORT_ID=$(gvm-cli --gmp-username admin --gmp-password "$GVM_PASSWORD" socket \
--xml "<get_tasks task_id='$TASK_ID'/>" | \
grep -oP 'last_report id="\K[^"]+')
# Get results in XML
gvm-cli --gmp-username admin --gmp-password "$GVM_PASSWORD" socket \
--xml "<get_results filter='report_id=$REPORT_ID'/>" > /tmp/openvas-results.xml
# Parse and prioritize
echo "=== Critical (CVSS >= 9.0) ==="
grep -E "CVSS.*(9\.|10\.)" /tmp/openvas-results.xml | head -20
echo ""
echo "=== High (CVSS 7.0-8.9) ==="
grep -E "CVSS.*[78]\." /tmp/openvas-results.xml | head -20
echo ""
echo "=== Medium & Low ==="
grep -E "CVSS.*[4-6]\." /tmp/openvas-results.xml | head -20
```
### Web Application Scan (Nikto + ZAP)
```bash
TARGET_URL="https://example.com"
SCAN_DIR="/tmp/vuln-scans/web-$(date +%Y%m%d-%H%M%S)"
mkdir -p "$SCAN_DIR"
# Nikto — quick scan
echo "=== Nikto Web Server Scan ==="
nikto -h "$TARGET_URL" -o "$SCAN_DIR/nikto.html" -Format html 2>&1 | \
grep -E "OSVDB|CVE|vulnerab" | tee "$SCAN_DIR/nikto-findings.txt"
# OWASP ZAP — deeper scan (if available)
if command -v zap-cli &>/dev/null; then
echo ""
echo "=== OWASP ZAP Active Scan ==="
zap-cli quick-scan --self-contained --start-options '-config api.disablekey=true' \
"$TARGET_URL" 2>&1 | tee "$SCAN_DIR/zap-output.txt"
# Extract alerts
zap-cli alerts --alert-level High 2>&1 | tee "$SCAN_DIR/zap-high.txt"
fi
echo "Results in: $SCAN_DIR"
```
### Container Image Scanning (Trivy)
```bash
IMAGE="nginx:latest"
echo "=== Trivy Container Scan ==="
trivy image --severity HIGH,CRITICAL --format json \
--output "/tmp/vuln-scans/trivy-$(date +%Y%m%d-%H%M%S).json" \
"$IMAGE" 2>&1
# Filter critical findings
trivy image --severity CRITICAL "$IMAGE" 2>&1 | grep -A5 "CRITICAL"
```
### CVE Intelligence Enrichment
Query CVE-MCP for specific vulnerability intelligence:
```bash
CVE="CVE-2024-3094" # Example: xz backdoor
echo "=== CVE Intelligence: $CVE ==="
curl -s -X POST "http://localhost:8765/cve-mcp/lookup" \
-H "Content-Type: application/json" \
-d "{\"cve_id\": \"$CVE\"}" | jq '{
id: .id,
cvss: .cvss_score,
vector: .cvss_vector,
published: .published_date,
exploit_available: .exploit_maturity,
kev: .cisa_kev,
affected: .affected_products[:5],
summary: .description[:200]
}'
```
### Batch CVE Search by Product
Search for all CVEs affecting a specific product+version:
```bash
PRODUCT="openssl"
VERSION="3.0.0"
curl -s -X POST "http://localhost:8765/cve-mcp/search" \
-H "Content-Type: application/json" \
-d "{\"product\": \"$PRODUCT\", \"version\": \"$VERSION\"}" | \
jq '.[] | {
id: .id,
cvss: .cvss_score,
severity: .severity,
exploit: .exploit_available,
fixed_in: .fixed_version
}' | head -50
```
### System Hardening Scan (Lynis)
```bash
echo "=== Lynis System Audit ==="
sudo lynis audit system --quick 2>&1 | tee "/tmp/vuln-scans/lynis-$(hostname)-$(date +%Y%m%d).txt"
# Extract hardening index
grep "Hardening index" /tmp/vuln-scans/lynis-*.txt | tail -1
# Show warnings
grep "WARNING" /tmp/vuln-scans/lynis-*.txt | head -30
# Show suggestions
grep "Suggestion" /tmp/vuln-scans/lynis-*.txt | head -30
```
## Usage Patterns
### Full Security Assessment
When the user requests a comprehensive security assessment of a target:
1. **Discovery** — Nmap service scan + OS fingerprinting
2. **CVE Enrichment** — Cross-reference discovered services against CVE-MCP
3. **Network Scan** — OpenVAS deep scan with authenticated checks
4. **Web Scan** — Nikto + ZAP for web application vulnerabilities
5. **Container Scan** — Trivy for any container images in scope
6. **System Audit** — Lynis for host-level hardening check
7. **Report** — Generate prioritized report with CVSS, exploitability, remediation steps
### CI/CD Security Gate
Integrate scan results into deployment pipelines:
1. Run container/image scan (Trivy)
2. Run dependency scan (OWASP Dependency Check)
3. Block deployment if CRITICAL findings with known exploits
4. Flag HIGH findings for security review
5. Generate SBOM (Software Bill of Materials)
### Weekly Vulnerability Sweep
Automated weekly scan for infrastructure:
1. Run Nmap discovery on defined subnets
2. Compare against previous week's results (new open ports = alert)
3. Refresh CVE intelligence via CVE-MCP
4. Flag newly published CVEs affecting discovered services
5. Generate delta report (new findings since last sweep)
### Exploit Validation
When a vulnerability is found, validate exploitability via pentester-mcp:
```bash
CVE="CVE-2024-XXXX"
SERVICE="apache"
VERSION="2.4.49"
echo "=== Exploit Validation: $CVE ==="
curl -s -X POST "http://localhost:8765/pentester-mcp/check-exploit" \
-H "Content-Type: application/json" \
-d "{\"cve\": \"$CVE\", \"service\": {\"name\": \"$SERVICE\", \"version\": \"$VERSION\"}}" | \
jq '{
exploitable: .exploit_available,
metasploit_module: .msf_module,
exploitdb_id: .edb_id,
poc_available: .poc_url != null,
confidence: .confidence
}'
```
## Pricing Tiers
### Free (Basic)
- Single-target Nmap scan with CVE enrichment (up to 5 hosts)
- Nikto web scan (1 URL)
- Manual CVE lookup (up to 10 queries/day)
- Text-only findings export
### Premium ($9.99/report)
- Full OpenVAS authenticated scan (unlimited hosts)
- OWASP ZAP active web scan
- CVE-MCP enrichment with CVSS scoring
- Priority remediation report (PDF)
- Exploit validation via pentester-mcp
- Historical comparison (delta from previous scan)
- 30-day report storage
### Enterprise ($49/month)
- Scheduled weekly scans with alerting
- CI/CD pipeline integration (webhook)
- Team dashboard access
- SBOM generation
- SLA-backed response: critical findings within 4 hours
- Custom scan policies and compliance templates
## Configuration
| Variable | Default | Description |
|----------|---------|-------------|
| `GVM_HOST` | `localhost` | OpenVAS/GVM server host |
| `GVM_PORT` | `9392` | GVM management port |
| `GVM_USERNAME` | `admin` | GVM admin username |
| `GVM_PASSWORD` | (required) | GVM admin password |
| `CVE_MCP_URL` | `http://localhost:8765/cve-mcp` | CVE-MCP endpoint |
| `PENTEST_MCP_URL` | `http://localhost:8765/pentester-mcp` | Pentest MCP endpoint |
Auf GitHub ansehen