osv
Installation
SKILL.md
osv - Open Source Vulnerabilities Scanner
The osv module provides an interface for the OSV project, enabling users to scan local projects, identify vulnerable dependencies, and retrieve detailed vulnerability information.
When to Activate
- When the user wants to perform a security audit on their project dependencies (npm, pip, etc.).
- When querying detailed information for a specific vulnerability ID (e.g.,
osv-2020-111). - When generating security reports in the SARIF format for integration with CI/CD pipelines.
- When searching for vulnerabilities related to specific software packages and versions.
Core Principles & Rules
- Comprehensive Scanning: Use
sarifto generate standardized security reports. - Eco-System Aware: Supports multiple ecosystems including npm, pypi, and more.
- Search Integration: Uses AI or DuckDuckGo to summarize vulnerability details from the web.