Daily security advisory and CVE watch for your stack

By General Input

Every morning, scan the web for new vulnerabilities and breaking changes affecting your packages, file high severity issues in Linear, and post a digest to Slack.

Integrations

  • Tavily
  • Linear
  • Slack Bot

Type

Agentic Task

Categories

  • Engineering

Build me an agent workflow that runs every day at 9am and watches the web for new security advisories, CVEs, breaking changes, and major release notes affecting the packages and frameworks my team depends on.

Configurable inputs at the top of the workflow:

- A list of tracked packages / frameworks (e.g. react, django, postgres, openssl). Start with a sensible default list but make it easy to edit. - The Linear team and project where security tickets should be filed. - The Slack channel that should receive the daily digest. - A severity threshold for filing tickets (default: high and critical).

For each tracked package, use Tavily Search to find items published in the last 24 hours. Run a few focused queries per package and bias to recent results with a 1 day time range. Useful query shapes:

- "<package> CVE OR vulnerability OR security advisory" - "<package> breaking change OR major release notes" - Optionally include site filters like site:nvd.nist.gov, site:github.com/advisories, or the project's official changelog.

For every finding, have the agent grade it on: - Severity (critical, high, medium, low), using CVSS where available and qualitative judgment otherwise. - Relevance to the user's stack (does this actually affect the package and version range we use, or is it a different ecosystem with the same name).

For anything that meets the severity threshold AND is relevant, call Linear Create Issue in the configured team/project. The issue body should include: a clear title (CVE id or advisory id plus package name), a short summary of the vulnerability and how it could affect us, the CVE identifier, severity, source link, publish date, and a suggested next action (upgrade to version X, apply patch, monitor, etc).

Before filing, dedupe against Linear: use List Issues or Search Issues to look at issues in the configured project created in the past seven days. Match on CVE id in the title or description, and also fuzzy-match on package + advisory title. If a matching issue already exists, do NOT file a new one, and mark the finding as a duplicate in the digest instead.

After processing every package, ALWAYS call Slack Send a Message (via the Slack Bot integration) to post a single digest into the configured engineering channel, even on quiet days when nothing was found. The digest should include: - Which packages were scanned. - Total findings and a count by severity. - A short bullet for each high / critical finding with the source link. - A list of new Linear issues filed (with links). - A list of suppressed duplicates with links to the existing Linear issues.

Format the Slack digest using Slack mrkdwn (e.g. *bold*, <url|text>) so links and section headers render cleanly. Keep it scannable — one section per severity bucket, then a 'New tickets' section, then a 'Duplicates skipped' section.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them