Method
KEV/EPSS/CVSS/NVD Prioritization Connector
How should a vulnerability be prioritized using authoritative-source fields?
Field scoring contract
| Field | Type | Role | Direction | Scored |
|---|---|---|---|---|
| CVE/advisory | text | context | context | no |
| KEV / exploitation status | select | risk_driver | higher_is_worse | yes |
| EPSS percentile 0-100 | number | risk_driver | higher_is_worse | yes |
| CVSS base score | number | risk_driver | higher_is_worse | yes |
| Exposure | select | risk_driver | higher_is_worse | yes |
| Asset criticality | select | risk_driver | higher_is_worse | yes |
| Patchability | select | risk_driver | higher_is_worse | yes |
Limits
- Preliminary output
- Human review required
- Not certification
- Context text is not averaged into numeric scores.
- Outputs require source/evidence review before decisions.