Releases: nimitt-IN/bitscorecowork
Release list
v0.5.0 — the IFSCA / GIFT City track, and CSCRF at its current thresholds
GIFT City was missing, and its absence was silent
An entity licensed by IFSCA files with the Authority, not with the RBI, SEBI or IRDAI. An IFSC licence displaces the mainland regulator, however mainland the business looks — so a GIFT City banking unit does not go on the DAKSH clock, and a GIFT City fund does not take a CSCRF category.
Before this release, incident-notify asked "commercial bank, NBFC, intermediary or insurer?". A GIFT City banking unit answered "bank" and received a DAKSH draft under RBI/DoS/2026-27/410, an instrument that does not bind it. Nothing about that draft looked wrong, which is what made it worth fixing first. The skill now asks where the entity is licensed before asking what it does.
The Guidelines (IFSCA-CSD0MSC/13/2025-DCS, 10 March 2025, in force 1 April 2025) are carried in both references, read from the published PDF and quoted verbatim.
| Step | Deadline | From |
|---|---|---|
Particulars to cyber-incidents@ifsca.gov.in, copied to the CISO, IFSCA |
6 hours | Detection |
| Interim report | 3 days | Detection |
| Mitigation measures taken | 7 days | Detection |
| Root cause analysis | 30 days | Detection |
Two things are true of nothing else in these references. The clock runs from detection, not from "noticing or being brought to notice" — so where CERT-In also binds, the two are not necessarily running from the same moment. And the seven-day step is a deadline on the fix, not on a filing: no other Indian cyber instrument puts a clock on remediation, which means the incident file stays open for a month rather than a day.
Also carried: the four para 21 exemptions (branches, group-only GICs, REs under ten employees, foreign universities) with their para 22 conditions, the 90-day annual certification an exempt RE still owes, and the fact that the exemptions expire on 10 March 2028. CERT-In binds an exempt RE either way.
regmap maps to the five components and flags that para 11's express six-monthly third-party review is the clearest cadence obligation in any of these instruments — one a dated portfolio pack evidences directly. tabletop runs the tail, the only clock set here that outlives the first day.
SEBI CSCRF, at its current thresholds
New reference reference/cscrf-categories.md. The plugin previously cited the August 2024 circular alone while grading obligations by a category it gave no way to determine.
The criteria were replaced in April 2025 and again in August 2025 — replaced, not adjusted. Portfolio Managers and Merchant Bankers were re-categorised in both rounds; the proprietary/client-based split for stock brokers no longer exists; KRAs moved from MII-par to Qualified; AIFs and VCFs are now assessed at manager level. Because SEBI fixes a category each April on the previous year's data and holds it all year, a firm can be correctly categorised and still be working to a superseded table — which does not look like an error from the inside.
The file also records that MIIs, KRAs and QRTAs were excluded from both compliance extensions, so the 31 August 2025 deadline everyone quotes never applied to them.
Four accuracy fixes
- The reference over-claimed about itself.
incident-reporting-map.mdsaid "every row in this file is now Primary" while NCIIPC and the superseded RBI 2023 Master Direction both still read Secondary — and its change note still marked IRDAI Secondary after the IRDAI section had been re-verified in the same release. The header now names the two Secondary sections and says why each one is. - Urban Co-operative Banks were described as excluded from RBI 410. They are not. 410 covers "banking companies (other than Small Finance Banks, Payments Banks, and Local Area Banks)". UCBs are Primary Co-operative Banks and were never inside the definition to be carved out of it — they file under 437 because 437 is addressed to them. Local Area Banks, which were carved out, have no instrument in the family at all.
- The NBFC outsourcing instrument is now named: RBI/DOR/2025-26/363 of 28 November 2025, alongside 171 for commercial banks, with its scope and scale-based grading.
quantifyandpeer-indexgained the published figures they were reasoning without. Bitsight's band-to-band breach multiples (Intermediate 1.5–2× Advanced, Basic 2–3× Intermediate, ≤400 5× more likely than ≥700) now anchor the likelihood modifier, with an explicit instruction not to use the unsupported "50% less likely" figure that circulates. Global rules §3 gains the mean rating (720), the ten-point rounding rule, and the distribution fact that matters most to a benchmarking deck: about 60% of rated entities are Advanced — the modal band, not an achievement.
entity-scope gained its argument
SEBI's CDSL order of 20 July 2026: a ₹1 crore penalty where an internet-facing ADFS server was never classified as a critical asset, and so fell outside the testing and monitoring that would have found it. The disaster recovery site was encrypted too. An inventory error is not one control failing — it is every control silently skipping one host.
Keeping this current
Each reference now ends with a provenance block naming the bitscore.in registry it mirrors and the date it was verified, and the README carries the working rule: when a regulatory fact moves on either side the other is the counterpart to check, re-verify at source rather than copying across, stamp the date you actually read it, and review quarterly.
Upgrading
Releases before 0.5.0 carry no IFSCA track at all, so a GIFT City entity is routed to the RBI, SEBI or IRDAI — the resulting draft is filed with the wrong authority while the clock that does bind the entity runs out. They also cite SEBI CSCRF at its August 2024 thresholds.
Sixteen skills, 15 read-only tools, five bundled references. Install bitscorecowork-0.5.0.plugin below, or point at the bitscorecowork/ directory as a local plugin.
v0.4.2 — SEBI LODR closed out at source
0.4.1 left SEBI LODR Reg. 30(6) as the one unverified row in reference/incident-reporting-map.md. It is now Primary, read from the consolidated text (last amended 14 July 2026) — and it was wrong in both directions. With this release every instrument in that reference has been read at source.
⚠️ A cyber incident is twelve hours, not twenty-four
| Limb of Reg. 30(6) | Deadline | Applies to |
|---|---|---|
| (i) | thirty minutes from closure of the meeting (three hours under an after-hours proviso) | Events decided at a board meeting |
| (ii) | twelve hours from occurrence | Event emanating from within the listed entity |
| (iii) | twenty-four hours from occurrence | Event not emanating from within |
A ransomware event, data breach, customer-data leak or IT outage originates within the entity, so it is limb (ii) — twelve hours. The twenty-four-hour figure everyone quotes, and that every earlier release of this plugin carried, is limb (iii), for events arising outside the entity. Quoting it puts the disclosure twelve hours late. On a twelve-hour limb it can also fall due before some of the technical filings, which is not how the sequence is usually taught.
0.4.1 additionally attributed twelve hours to board decisions; they are thirty minutes. Both limbs were wrong, in opposite directions.
The seventy-two-hour figure is much narrower than reported. It is not a general limb: it applies only to non-tax litigation or dispute claims under Schedule III Part A Para B(8), and only where the relevant information is maintained in the entity's structured digital database under the PIT Regulations, 2015. Not available for a cyber incident.
Two provisions the plugin never carried
Reg. 27(2)(ba) — "Details of cyber security incidents or breaches or loss of data or documents shall be disclosed along with the report mentioned in clause (a) of sub-regulation (2)" — the quarterly corporate governance report, with no materiality test. An incident correctly judged immaterial for Reg. 30 can still be reportable here, and the obligation outlives the incident, so it belongs on the post-incident checklist rather than the first-day matrix.
Reg. 21(4) — the Risk Management Committee's role must "specifically cover cyber security".
Also recorded: cyber incidents are not named in Schedule III — they reach Reg. 30 through the materiality test, not as a listed event; the nearest express entry is Part A Para B(6), disruption of operations due to natural calamity, force majeure, strikes or lockouts. And late disclosure must carry an explanation for the delay.
regmap
- Now asks whether the entity is listed — whatever framework was chosen. LODR reaches every listed entity in any sector, including one with no financial-sector regulator at all, and a SEBI-regulated entity that is also listed sits in both LODR and CSCRF. The skill previously never asked.
- A new LODR section in
regulatory-map.mdin which two of three rows read "Bitsight evidences nothing" — that is the correct output, not a gap to be filled. - New guardrails: a rating change is neither an incident nor a disclosable event and must never be mapped onto Reg. 27(2)(ba) or Reg. 30(6) merely because both mention incidents; and never opine on materiality, which under Reg. 30(4) is the authorised KMP's determination on advice.
Propagated to incident-notify, tabletop (LODR becomes a hard twelve-hour inject), HELP_GUIDE.md and both READMEs.
Also fixed
A stale claim left in the plugin README by 0.4.1, describing NBFCs as sitting under the 2023 IT Governance Master Direction. Surfaced by this sweep.
Retrieval note — what defeated the 0.4.1 attempt
SEBI serves its regulations through a PDF viewer iframe, so the page HTML carries no regulation text and both WebFetch and curl return an 8.5KB shell. The consolidated PDF is the iframe src: sebi.gov.in/sebi_data/attachdocs/jul-2026/1784630770711.pdf. Recorded in the reference so it doesn't cost anyone the same detour.
Carried forward from 0.4.1
The seven parallel RBI Directions (410 · 419 · 428 · 437 · 456 · 461 · 470, one per entity class, six hours to DAKSH, different paragraph in each); DPDP breach duties not in force until 13 May 2027; IRDAI's 24-hour step does not exist in the 2026 Guidelines; CSCRF is three filings, not one; and entity-scope's origin_subsidiary — a Bitsight asset total is a row count, not a host count.
Install
Download bitscorecowork-0.4.2.plugin below and add it in Claude, or point at the bitscorecowork/ directory as a local plugin. The bitsight MCP server starts automatically — no npm install, no configuration.
v0.4.1 — four regulatory corrections, verified at source
A correctness release. No new skills, no new tools — every clock in reference/incident-reporting-map.md was re-verified against the published text, and four were wrong in ways that would have misrouted a live filing. Three of the four were introduced or left standing by v0.4.0, so upgrading is worthwhile for anyone using incident-notify, tabletop or regmap.
⚠️ DPDP breach obligations are not in force
v0.4.0 presented the DPDP intimations as live clocks. They are not.
Rule 1(4) of G.S.R. 846(E), verbatim: "Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication of this Gazette." Rule 7 is in that tranche — it commences 13 May 2027. Separately, G.S.R. 843(E) (a different notification of the same date, easily confused with the Rules) commences Act section 8 on the same day. Only the Board-establishing sections took effect in November 2025.
incident-notify no longer drafts DPDP intimations as live filings; tabletop runs them as clearly labelled rehearsal injects. Both failure directions are called out — inventing an obligation that isn't running, and leaving a client unprepared for one that is coming.
The two-dates trap is documented alongside: G.S.R. 846(E) is dated 13 November 2025; the 14th is only the e-gazette upload stamp (CG-DL-E-14112025), and the eighteen-month clock runs from the 13th.
RBI — seven instruments, not one
v0.4.0 described RBI/DoS/2026-27/410 as the 2026 instrument and routed every other regulated entity to the 2023 IT Governance Master Direction. There are seven parallel Directions, all issued 31 July 2026, one per entity class — same six-hour DAKSH clock, different reporting paragraph in each:
| Entity class | Reference | Id | Reporting para |
|---|---|---|---|
| Commercial Banks | RBI/DoS/2026-27/410 | 13643 | 182 |
| Small Finance Banks | RBI/DoS/2026-27/419 | 13634 | 181 |
| Payments Banks | RBI/DoS/2026-27/428 | 13625 | 181 |
| Urban Co-operative Banks | RBI/DoS/2026-27/437 | 13616 | 88 |
| All India Financial Institutions | RBI/DoS/2026-27/456 | 13597 | 177 |
| Non-Banking Financial Companies | RBI/DoS/2026-27/461 | 13592 | Ch. IV 28 / Ch. V 141 |
| Credit Information Companies | RBI/DoS/2026-27/470 | 13583 | 177 |
NBFC scope was wrong in both directions. 461 binds every RBI-registered NBFC, graded by chapter — and Base Layer below ₹500 crore (Ch. III) carries no DAKSH clause at all, only CERT-In's six hours. Regional Rural Banks and Local Area Banks have no instrument in this family. A parallel Digital Payment Security Controls family issued the same day is a different set of instruments and must not be cited interchangeably.
Corrected in incident-reporting-map.md, regulatory-map.md, bitscore-global-rules.md, regmap/SKILL.md and HELP_GUIDE.md.
IRDAI — the 24-hour step does not exist
The 2026 Guidelines (IRDAI/GA&HR/CIR/MISC/51/4/2026, 6 April 2026, Version 2.0) replaced the 2023 text that v0.4.0 cited. §3.6, verbatim: "Organization shall mandatorily report cyber incidents to Cert-In within 6 hours of noticing or being brought to notice about such incidents with a copy to IRDAI and other concerned regulators / authorities." Nothing further — a full-text search of all 175 pages returns no 24-hour incident obligation. The old second step was a 2023 carry-over.
Entity scope is wider than the usual shorthand: insurers including FRBs, brokers, corporate agents, web aggregators, TPAs, IMFs, insurance repositories, ISNP, corporate surveyors, MISPs, CSCs and the IIB.
Two practical traps are recorded: IRDAI's document page for the 2023 Guidelines is still live with no superseded notice, and the 2026 circular is a scanned image with no extractable text, with the Guidelines distributed inside an Annexure B ZIP.
SEBI CSCRF — three filings, not one
Now Primary, from circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 August 2024):
| What | When | Where |
|---|---|---|
| Initial notification | 6 hours | mkt_incidents@sebi.gov.in and CERT-In |
| Necessary details | 24 hours | SEBI Incident Reporting Portal |
| Brokers / DPs — extra leg | 6 hours | Stock Exchanges / Depositories |
| All other incidents | 24 hours | SEBI, CERT-In, NCIIPC as applicable |
Triggered by "noticing/ detecting … or being brought to notice" — the same three-limbed trigger as CERT-In, not detection alone. Classification thresholds are in Annexure-O, and the circular states that failure to report an incident the RE knew about may draw "appropriate regulatory action".
SEBI LODR — marked unverified, deliberately
Verification was attempted and failed: SEBI serves the consolidated regulations through a client-rendered page whose text cannot be retrieved, and the LODR FAQ does not restate the limits. Rather than quote 12/24 hours with false confidence, the row is explicitly flagged as unverified and points at the current consolidated version (last amended 14 July 2026). It is the only Secondary row left in the file, and the change note names it as the outstanding item.
entity-scope — origin_subsidiary, and why asset counts mislead
Assets carry origin_subsidiary, naming the entity an attribution was inherited through — undocumented until now, and the field that explains estate size. The same IP is returned once per subsidiary it maps through. Verified live: one address appearing six times in a single page, whole pages running 100 rows to 18 unique hosts.
A Bitsight asset total is a row count, not a host count. The reference now requires deduplication before any total is quoted, notes that hosted_by is routinely null, and adds RDAP lookups as the checkable registry fallback a dispute submission needs. entity-scope must also state sample size and offsets when an estate is too large to page fully.
Also fixes the attribution taxonomy count, which said "eight" in three places and "nine" in two.
Housekeeping
Five superseded .plugin bundles removed from the repo root and the historical release sections pruned from both READMEs — the current version only. Earlier bundles remain downloadable from their own releases. Version bumped across plugin.json, server/package.json, both READMEs and all 16 skill frontmatters, and the bundle rebuilt so the shipped artifact matches source.
Verification
Read directly on 13 August 2026: all seven RBI Directions at rbi.org.in; the IRDAI 2026 circular and the Guidelines inside the Annexure B ZIP; SEBI CSCRF circular 2024/113; both DPDP gazette notifications (G.S.R. 846(E) and 843(E)). RDAP lookups against ARIN and RIPE for the attribution work.
Install
Download bitscorecowork-0.4.1.plugin below and add it in Claude, or point at the bitscorecowork/ directory as a local plugin. The bitsight MCP server starts automatically — no npm install, no configuration.
v0.4.0 — six new skills, sixteen in total
Takes BitScoreCoWork from ten skills to sixteen. No new MCP tools — every new skill is built on the existing 15 read-only ones.
The first ten skills all answer some version of "what does Bitsight say?". These six answer questions the platform raises but doesn't close.
The six skills
entity-scope — "those IPs aren't ours", the first objection in every ratings deployment and the one that stalls the most pilots. Pages the full observed footprint, categorises every asset against a nine-part taxonomy in the new reference/attribution-patterns.md, and produces a signed-off inventory plus a dispute submission. It pushes back where the claim doesn't hold: an acquired entity's estate is the group's estate, and a cloud PaaS hostname proves nothing about who deployed the workload. Because Bitsight exposes no dispute endpoint and this plugin is read-only, it states plainly that a disputed asset is not a removed asset.
incident-notify — the time-bound Indian notifications an incident triggers, drafted against the new reference/incident-reporting-map.md. Every clock carries its reference number, issue date, source URL and a Primary/Secondary marker recording whether the published text was read directly. The CERT-In directions (No. 20(3)/2022 — 20 Annexure I categories, six hours from noticing, 180-day logs held within Indian jurisdiction, §70B(7)) and the RBI 2026 Directions (Ch. V §Z.1 ¶182 — six hours to DAKSH) were read at source; SEBI, IRDAI, DPDP and NCIIPC are marked for confirmation before filing.
Two corrections are baked in. "RBI 2–6 hours for banks and NBFCs" conflates instruments that no longer travel together — commercial banks file under the 2026 Directions to DAKSH, NBFCs under the 2023 IT Governance Master Direction and only in the Top, Upper and Middle Layers. And SEBI LODR Reg. 30: any listed entity owes exchange disclosure within 24 hours in parallel, routinely forgotten while the six-hour clocks run.
tabletop — a board crisis simulation seeded from the real attack surface, with the regulatory clocks running as injects. Every artefact carries EXERCISE — NOT A REAL INCIDENT in the header, the footer, and inside the body of any simulated notification.
peer-index — sector benchmarking that refuses to pass a portfolio cohort off as the sector. Bitsight's industry percentiles carry the statistical claim; any named cohort is reported with n and its selection basis; peers are anonymised by default.
watchtower — the delta since a dated snapshot it writes to the working folder. Now the one file any skill persists by design, sanctioned in global rules §8.
assurance-pack — answers inbound customer questionnaires from your own evidence. Never writes "compliant", and never attaches itemised findings.
Live verification — 4 August 2026
16 checks passed, 0 failed, 0 gated by entitlement. Three findings changed the code:
bitsight_get_alertsdeclared a severity enum that matched nothing. It advertisedINFO/WARN/DANGER/MATERIAL; the endpoint returnsCRITICALandINCREASE, and all four declared values matched zero alerts. Since an unmatched severity returns 200-empty rather than erroring, a filtered pull was indistinguishable from a quiet period — and would have letvendor-briefreport a clean 90 days on a vendor that had alerts. Enum constraint removed;watchtower,vendor-briefandboardpacknow read severity off the response.hosted_bybeats hostname pattern-matching — every asset names its hosting organisation directly.- Multi-company attribution held as a signal but not with the assumed meaning. 42 of 100 findings carried it, yet most named variants of one organisation (per-cloud entities, several suffixed
DUPLICATE); one domain was attributed to eleven such entities. Hence the ninth category, entity overlap — a portfolio-hygiene item for the account team, explicitly not a dispute.
Upgrading
Drop-in. No configuration changes, no new tools, no npm install. If you monitor alerts, note the severity correction above — a filter that looked clean on 0.3.1 may not have been.
© 2026 BitScore Cybertech LLP. "Bitsight" is a registered trademark of Bitsight Technologies, Inc.; this plugin is an independent integration and is not published by Bitsight.
v0.3.1 — the RBI outsourcing track is separate from the cyber Directions
Ten skills, 15 read-only tools. Re-verified against a live Bitsight subscription: 30 checks passed, 0 failed.
Install: download bitscorecowork-0.3.1.plugin below and add it in Claude, or point at the bitscorecowork/ directory as a local plugin. Node.js 18+, no npm install, no configuration.
The correction
0.3.0 described non-bank entities as remaining under "the IT governance Master Direction and the outsourcing norms". Read quickly, that implies the cybersecurity Directions of 31 July 2026 absorbed outsourcing governance for the banks they do cover. They did not — and the text says so outright.
Paragraph 126 scopes their third-party provisions to IT and cybersecurity arrangements falling outside the RBI (Commercial Banks – Managing Risks in Outsourcing) Directions, 2025 — RBI/DOR/2025-26/171, issued 28 November 2025, existing IT outsourcing agreements to comply by 10 April 2026. Those 2025 Directions are what actually repealed the 2023 Master Direction on Outsourcing of IT Services for commercial banks. NBFCs have a parallel 2025 instrument.
The cyber Directions preserve the outsourcing regime and carve around it. Two tracks, not a replacement:
| Track | Instrument | Covers |
|---|---|---|
| Outsourcing | Managing Risks in Outsourcing Directions, 2025 | Materiality, due diligence, audit rights reaching subcontractors, concentration, exit |
| Cybersecurity | Cybersecurity … Directions, 2026 | Board and IT governance, baseline controls, CSOC, IS Audit, DAKSH reporting |
What changed
regmap now asks which of the two a pack is actually about before mapping vendor oversight, and its RBI checklist separates the outsourcing artefacts — outsourcing register, materiality determinations, due-diligence files, concentration analysis, exit plans — from the Chapter IV ones.
regulatory-map.md carries the distinction in the RBI section, the cross-cutting third-party table and the orientation notes. Global rules §7 gains it as a standing rule, so all ten skills inherit it rather than regmap alone.
Why this is a release rather than a doc tweak
Both instruments are recent, both are RBI, both carry a third-party chapter. Mapping vendor due diligence to the wrong one produces a pack that reads correctly and cites the wrong authority — the failure mode that survives review and surfaces in front of a supervisor.
Upgrading
No functional change from 0.3.0 — the correction is entirely in skill and reference content, and the 0.3.0 server work (Critical Vulnerability Management slug resolution, severity_gte thresholds) is untouched. Upgrade if you build RBI evidence packs that touch vendor oversight. If you came from 0.2.1 or earlier, the 0.3.0 notes still apply and matter more: 0.2.1 could under-report vulnerability findings to zero.
v0.3.0 — RBI Directions 2026 in regmap, one name for the CVM risk vector
Ten skills, 15 read-only tools. Verified end to end against a live Bitsight subscription: 30 checks passed, 0 failed.
Install: download bitscorecowork-0.3.0.plugin below and add it in Claude, or point at the bitscorecowork/ directory as a local plugin. Node.js 18+, no npm install, no configuration.
regmap maps to the RBI Directions, 2026
The RBI issued the Reserve Bank of India (Commercial Banks – Cybersecurity, Technology: Risk, Resilience and Assurance Framework) Directions, 2026 — RBI/DoS/2026-27/410 — on 31 July 2026, in force immediately. They cover commercial banks other than SFBs, Payments Banks and Local Area Banks, and repeal the earlier cyber and IT-governance circulars for those banks. A pack built on the old mapping cites a superseded instrument.
The mapping reference gains a source-cited RBI section: coverage and non-coverage, the eight chapters, a risk-vector → chapter table with an explicit what this cannot show column, and the portfolio and vendor activities that evidence Chapter IV oversight. References are chapter-level by design — paragraph numbers get read off the published text rather than asserted from a plugin.
regmap now asks for your own material when RBI is the framework. Bitsight evidences the external surface of Chapter V, the detection outcomes Chapter VI's CSOC exists to produce, and third-party monitoring under Chapter IV. The rest — Board and IT Strategy Committee, CISO reporting line, CSOC staffing, VA/PT reports, DR drills and RTO/RPO, MFA enforcement, training, IS Audit, DAKSH submissions — sits in records only the bank has. So when RBI is chosen, and only then, the skill first asks which RBI instrument applies (it never rules on applicability itself), then invites you to hand over policies, audit findings, the outsourcing register, or an existing control mapping, with a chapter-by-chapter checklist.
Nothing is required. Decline and you get a Bitsight-only pack with more "not evidenced" rows and a coverage statement saying why. What you do supply is recorded, never assessed: RBI rows carry an evidence-source column — Bitsight-observed, client-supplied, not evidenced — so a reader can always tell which is which, and a supplied document never upgrades a Bitsight row.
Other frameworks are unchanged. NIST, ISO, SEBI, IRDAI, CERT-In and DPDP packs behave exactly as in 0.2.1.
One risk-vector name, one severity filter
Verified against the live API on 3 August 2026:
risk_vector sent |
Result |
|---|---|
critical_vulnerability_management |
HTTP 200, 0 findings |
patching_cadence |
HTTP 200, 210 findings |
not_a_real_vector |
HTTP 200, 0 findings |
…on a company Bitsight grades F on that vector. The product renamed in July 2026; the API did not. And an unrecognised slug is not rejected — it returns an empty set indistinguishable from a clean company. 0.2.1 documented both slugs and asked the model to retry, which left a silent failure mode open: a skill could report no vulnerability findings for an estate with hundreds.
The MCP server now owns the difference. Skills, prompts and outputs use exactly one name — critical_vulnerability_management — and the server resolves the wire slug, falls back automatically, and rewrites the legacy slug to the canonical one in rating_details, findings_risk_vector_counts and individual findings before any skill sees it. When Bitsight switches the API over, one constant changes.
Severity is filtered with severity_gte, everywhere, as a number. The API rejects severity=severe with HTTP 422. Thresholds verified against the categorical counts: 9 severe, 8 material and above, 6 moderate and above, 1 everything. All ten skills now name a floor suited to their output instead of pulling everything and discarding client-side, which truncates on a large estate. bitsight_get_findings_summary stays authoritative for categorical counts.
Also
serverInfo.version was stale at 0.2.0 since the 0.2.1 release; fixed.
Upgrading
Upgrade from 0.2.1 if you build RBI evidence packs, or if you rely on vulnerability-management findings — 0.2.1 could under-report them to zero. 0.2.0 and 0.1.1 bundles remain attached to their own releases so existing installs aren't stranded, but both predate the Critical Vulnerability Management methodology change and sequence remediation on advice that is now wrong.
v0.2.1 — Critical Vulnerability Management replaces Patching Cadence
Bitsight retired the Patching Cadence risk vector on 16 July 2026, replacing it with Critical Vulnerability Management at the same 20% weight. CVM grades on a severity-weighted average time-to-remediate, with findings living 90 days — a methodology change, not a rename.
The reason to upgrade
remediation-roadmap treated patching as slow process work and sequenced it into days 61–90. Under CVM that is backwards: remediating a Material or Severe vulnerability promptly is among the fastest ways to move a rating. Anyone running 0.2.0 is getting a roadmap that defers the single highest-leverage work to the last month.
The skill now puts Material/Severe CVM findings in days 0–30 alongside the configuration-class quick wins, names software currency and asset inventory hygiene as the genuinely slow programme work, and carries an explicit note on why CVM is the exception to "process-class vectors move slowly".
Also in this release
regmap's framework mapping table uses the new vector name, and its description reflects severity weighting rather than plain remediation speed. This table goes in front of auditors and supervisors, so a retired vector name there mattered more than elsewhere.mycompanyandvendor-briefupdated where they name the vector.bitsight_get_findings'srisk_vectorparameter documents both the newcritical_vulnerability_managementslug and the legacypatching_cadence, and retries with the other rather than reporting zero findings if one comes back empty.
Known open item
Bitsight's public API reference does not state which slug the findings endpoint accepts, and the knowledge base blocks automated fetches. The dual-slug handling above makes the plugin correct either way, but the hedge stays until it can be confirmed against a live subscription.
No changes to the skill or tool inventory: ten skills, 15 read-only tools.
v0.2.0 — five new skills, verified against the live Bitsight API
Takes BitScoreCoWork from five skills to ten, and fixes a token-handling defect that live testing exposed.
Every tool in this release was exercised against a real Bitsight subscription: 18 checks passed, 0 failed, 3 gated by subscription entitlement.
New skills
| Skill | Answers |
|---|---|
vendor-brief |
Should we sign with this vendor? → go / go-with-conditions / no-go, contract clauses, re-review date |
remediation-roadmap |
What do we fix, in what order? → 30/60/90-day plan with owners and effort |
cve-sweep |
Who's exposed to this CVE? → exposure table, evidence, triage order, outreach drafts |
regmap |
What do we show the auditor? → NIST CSF 2.0 / ISO 27001:2022 / Indian-regime evidence pack |
quantify |
What's it worth in money? → three scenarios with every assumption visible |
New MCP tools
Four, all read-only, all verified against live responses:
bitsight_get_industry_benchmark—GET /v1/industries[/{slug}]bitsight_list_threats—GET /v2/threatsbitsight_get_threat_companies—GET /v2/threats/{threat_guid}/companiesbitsight_get_threat_evidence—GET /v2/threats/{threat_guid}/companies/{company_guid}/evidence
The cve-sweep chain — CVE → threat GUID → affected companies → per-company evidence — was confirmed working end to end on a live CVE.
Fixed: 403 no longer misreported as a bad token
Bitsight returns 401 for an invalid token but 403 for a valid token whose subscription doesn't include an endpoint. v0.1.1 collapsed the two, so a 403 told you to re-paste a credential that was never the problem and abandoned the workflow.
Now the two are separated. On a 403 the skills continue without that data source, name the gap, substitute where an honest substitute exists (aggregating individual findings when findings/summaries is gated), and reduce stated confidence — instead of stopping. Global rules §4 covers the behaviour; all ten skills follow it.
Response-shape corrections
Live data contradicted four assumptions that would have produced wrong output:
- There is no top-level
ratingscalar on the company object — the current rating isratings[0].ratingfrom the newest-first history, with the portfolio row as fallback. industryis a display string; the slug for other calls is the separateindustry_slugfield.rating_detailsreturnsnullrather than 403 when unentitled, so vector grades are reported as unavailable rather than absent.- The portfolio response carries
summaries["my-company"]— the token owner's own GUID.mycompanynow resolves "our rating" from it instead of asking you for a GUID.
Two things to know before relying on an output
quantifyis not Bitsight Financial Quantification. FQ is a separate Bitsight product and isn't reachable through the Ratings API this plugin wraps.quantifyproduces an indicative, fully transparent estimate from your posture plus figures you supply, and discloses this before collecting any input. If you license FQ, use the platform's number for insurers and regulators.regmapproduces an evidence pack, not an assessment. It reports what is evidenced, partially evidenced, or not evidenced by this data — never "compliant". Framework references inreference/regulatory-map.mdare indicative and need a compliance read before reaching a customer's audit file.
remediation-roadmap deliberately refuses to quote rating-point gains: Bitsight's algorithm is neither public nor linear, so any such number would be invented.
Install
Add bitscorecowork-0.2.0.plugin in Claude, or point at the bitscorecowork/ directory. Node.js 18+, no npm install, no configuration. v0.1.1 remains available.
v0.1.1 — initial release
The original five-skill release, preserved so existing installs aren't stranded.
Skills: mycompany, myportfolio, boardpack, vapt-plan, security-test-plan
MCP tools: 11, all read-only
Consider upgrading to v0.2.0
Besides the five additional skills, v0.2.0 fixes a handling defect present in this version: an HTTP 403 from Bitsight is treated here as an authentication failure. Bitsight actually returns 403 for a valid token whose subscription doesn't include a given endpoint (findings/summaries, assets and insights are commonly gated). On this version that prompts you to re-paste a credential that was never the problem, and abandons the workflow.
Installed the same way: add bitscorecowork-0.1.1.plugin in Claude, or point at the bitscorecowork/ directory. Node.js 18+, no npm install.