Developer tool

Trivy agent skills for Claude Code, Codex and other agents.

Open-source scanner for vulnerabilities, misconfigurations and secrets in containers and code.
skills
43
official
4
Type
Developer tool
Website
trivy.dev
Official GitHub
aquasecurity
Reviews
See Trivy on Enlisted

Trivy skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Official (4 skills)

Official Trivy skills
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1
1.ReleaseOfficial

Guides Sourcegraph CLI patch, minor, and major releases. An agent skill from sourcegraph/src-cli.

sourcegraph/src-cli359—~1.9kAutomated safety check: PassApache-2.08 days ago
2
2.Scan CodeOfficial

Scans a Power Pages site project for security issues in source code and dependencies.

microsoft/power-platform-skills967—~3.4kAutomated safety check: NotesMITtoday
3
3.Fix Image CvesOfficial

Scan a built container image with Trivy, classify fixable Go-module and base-image CVEs, apply dependency and Dockerfile fixes, and verify the result with file checks and an optional image rescan.

kubernetes-sigs/cloud-provider-azure294—~818Automated safety check: PassApache-2.0today
4

Orchestrate end-to-end CVE remediation for the Linux CCM, CNM, and health-probe-proxy images on cloud-provider-azure master or a release-X.Y branch, including builds, repeated Trivy verification…

kubernetes-sigs/cloud-provider-azure294—~3.9kAutomated safety check: PassApache-2.0today

Community

Community Trivy skills
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
5

Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

agentscope-ai/QwenPaw35k6 repos~4.2kAutomated safety check: PassApache-2.07 days ago
6

Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

trufflesecurity/trufflehog28k—~1.3kAutomated safety check: PassAGPL-3.0today
7

Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

AgentSecOps/SecOpsAgentKit219—~2.3kAutomated safety check: PassUnknown5 mo ago
8

Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…

nvuillam/npm-groovy-lint248—~1.9kAutomated safety check: NotesMIT3 days ago
9

Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema.

epam/ai-dial-chat504—~1.2kAutomated safety check: PassApache-2.0today
10

Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…

malloydata/publisher116—~5.1kAutomated safety check: PassMITtoday
11

Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images

CommonHuman-Lab/nyxstrike156—~1.1kAutomated safety check: PassUnknowntoday
12

Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…

cloudposse/atmos1.4k—~5.1kAutomated safety check: WarnApache-2.0today
13

When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

deonmenezes/mantishack505—~510Automated safety check: PassApache-2.04 days ago
14

Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and…

EliasOulkadi/shokunin114—~3.8kAutomated safety check: NotesMIT2 days ago
15

Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…

axelixlabs/axelix147—~4.2kAutomated safety check: PassLGPL-3.0yesterday
16

Run or install repo security leak checks with BetterLeaks and Trivy.

instructa/agent-skills139—~557Automated safety check: PassNo licence9 days ago
17

Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

Jeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT4 days ago
18

Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults.

Aedelon/claude-code-blueprint120—~1.6kAutomated safety check: NotesUnknown7 mo ago
19

Operate Syft, Grype, Trivy, Gitleaks, Retire.js, package-manager metadata, and build evidence for advanced software-supply-chain assessment.

cyberful/cyberful134—~1.2kAutomated safety check: PassAGPL-3.01 mo ago
20

Houndarr's CI workflow reference and branch protection. An agent skill from av1155/houndarr.

av1155/houndarr292—~1.2kAutomated safety check: PassAGPL-3.02 days ago
21

Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

hardw00t/ai-security-arsenal104—~2.8kAutomated safety check: PassNo licence5 mo ago
22

Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

AgentSecOps/SecOpsAgentKit2192 repos~3.7kAutomated safety check: PassUnknown5 mo ago
23

Reduces container attack surface by building application images on Google distroless base images that ship only the application runtime - no shell, package manager, or OS utilities - using…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.01 mo ago
24

Integrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
25

Scores Kubernetes resource manifests with Kubesec to flag misconfiguration and privilege-escalation risk before deployment, mapping each finding back to the securityContext change that fixes it.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
26

Configures the security features of the Harbor open-source container registry - integrated Trivy scanning, Cosign and Notary content trust policies, project-level RBAC, immutable tag and retention…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.01 mo ago
27

Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
28

Scan container images for vulnerabilities using Trivy, Grype, and cloud-native tools.

sickn33/agentic-awesome-skills47k1 repo~2.3kAutomated safety check: PassMITyesterday
29

Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.01 mo ago
30

Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

mukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.01 mo ago
31

Handle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.).

hardisgroupcom/sfdx-hardis400—~1.3kAutomated safety check: NotesAGPL-3.0today
32

Scans a Docker image with Trivy for vulnerabilities in OS packages and language dependencies, misconfiguration, exposed secrets, and licence violations, emitting SARIF, CycloneDX, or SPDX output.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: WarnApache-2.01 mo ago
33

A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

ericrisco/rsc-harness156—~2.8kAutomated safety check: NotesMITtoday
34

Operate kubectl, kube-bench, Trivy, Prowler, and manifest/runtime evidence for advanced Kubernetes security assessment.

cyberful/cyberful134—~898Automated safety check: PassAGPL-3.01 mo ago
35

CI/CD pipeline security gate design guide. An agent skill from revfactory/harness-100.

revfactory/harness-1001.3k—~1.5kAutomated safety check: PassApache-2.06 mo ago
36

Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files.

benchflow-ai/skillsbench1.8k—~1.8kAutomated safety check: PassApache-2.02 mo ago
37

漏扫报告分析 Skill。输入主流厂商漏扫报告(绿盟/深信服/悬镜/明鉴/等保/奇安信/启明/华云安/长亭/Nessus/Trivy/Grype/Snyk/OpenVAS 等 Excel/HTML/JSON/XML/.nessus 格式),自动提取漏洞并去重,可选对接知识库 Provider(修复历史)和威胁情报 Provider(CVE 情报),生成 7…

infometa/workbuddyskills342—~3.9kAutomated safety check: PassNo licencetoday
38

Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit.

secondsky/claude-skills227—~799Automated safety check: PassMIT9 days ago
39

CVE(Common Vulnerabilities and Exposures) 분석 방법론, 의존성 취약점 스캔 도구 활용, CVSS 점수 해석, 취약점 우선순위 결정 가이드.

revfactory/harness-1001.3k—~853Automated safety check: PassApache-2.06 mo ago
40

CI/CD 파이프라인 보안 게이트 설계 가이드. An agent skill from revfactory/harness-100.

revfactory/harness-1001.3k—~1.1kAutomated safety check: PassApache-2.06 mo ago
41

Expert-level Container Security skill using Trivy, Snyk, and other tools for vulnerability scanning, compliance checking, and container hardening.

theneoai/awesome-skills183—~4.6kAutomated safety check: PassMIT4 mo ago
42

Add container image scanning steps to existing Harness pipelines using Harness STO scanners.

harness/harness-skills115—~4.3kAutomated safety check: PassApache-2.0today
43

Add secret detection scanning steps to existing Harness pipelines using STO security scanners.

harness/harness-skills115—~2.8kAutomated safety check: PassApache-2.0today

Questions, answered from the data.

What is the best Trivy skill?

Release (official) from sourcegraph/src-cli ranks first of the 43 Trivy skills listed here, with the highest score: its repository has 359 GitHub stars, its SKILL.md loads about 1.9k tokens and it passes the automated safety check with no findings. Next come Scan Code and Fix Image Cves.

Is there an official Trivy skill?

4 of the 43 Trivy skills are official, published by the vendor's own GitHub organization: Release, Scan Code, Fix Image Cves and Remediate Image Cves.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.