trivy-vulnerability-scanner
Installation
SKILL.md
Trivy Vulnerability Scanner
Trigger / When to Use
Use this skill when the user asks to scan a codebase, container image, Linux root filesystem, Kubernetes cluster, SBOM, or repository for CVEs, misconfigurations, exposed secrets, or license risks with Trivy.
Good trigger phrases:
- "scan this Docker image for CVEs"
- "run Trivy on this repo"
- "check Kubernetes manifests for vulnerabilities"
- "generate a SARIF vulnerability report"
- "scan a Linux rootfs or container filesystem"
- "fail CI on critical fixable CVEs"