Guides automated vulnerability scanning of dependencies, code and containers with Trivy, Snyk, npm audit and Bandit.
- What it does
- This skill provides instructions and command examples for detecting security vulnerabilities across dependencies, source code and container images. It covers npm audit, Snyk, Safety, Trivy image and filesystem scans, Bandit for Python, and a GitHub Actions workflow that runs these scanners as CI security gates. It also includes a Node.js snippet that runs scans and exits non-zero when critical vulnerabilities are found, plus best practices for failing builds and tracking findings.
- When to use it
- Use it when setting up CI/CD security gates, running pre-deployment audits, or meeting compliance requirements. It also fits when you need to detect CVEs, find outdated packages, check license compliance, or generate SBOMs and troubleshoot related errors.
- Requirements
- Requires the relevant scanning tools to be installed and available, such as Trivy, Snyk, npm audit, Safety, Bandit or OWASP Dependency-Check, plus Node.js for the included snippet. Snyk needs a SNYK_TOKEN secret in CI, and network access is needed to fetch vulnerability data. The skill ships instructions only, with no scripts.