Developer tool
Trivy agent skills for Claude Code, Codex and other agents.
- skills
- 43
- official
- 4
- Type
- Developer tool
- Website
- trivy.dev
- Official GitHub
- aquasecurity
- Reviews
- See Trivy on Enlisted
Trivy skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
Official (4 skills)
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Guides Sourcegraph CLI patch, minor, and major releases. An agent skill from sourcegraph/src-cli. | sourcegraph/ | 359 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 2 | Scans a Power Pages site project for security issues in source code and dependencies. | microsoft/ | 967 | — | ~3.4k | Automated safety check: Notes | MIT | today |
| 3 | Scan a built container image with Trivy, classify fixable Go-module and base-image CVEs, apply dependency and Dockerfile fixes, and verify the result with file checks and an optional image rescan. | kubernetes-sigs/ | 294 | — | ~818 | Automated safety check: Pass | Apache-2.0 | today |
| 4 | Orchestrate end-to-end CVE remediation for the Linux CCM, CNM, and health-probe-proxy images on cloud-provider-azure master or a release-X.Y branch, including builds, repeated Trivy verification… | kubernetes-sigs/ | 294 | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | today |
Community
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 5 | Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning. | agentscope-ai/ | 35k | 6 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | 7 days ago |
| 6 | Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review. | trufflesecurity/ | 28k | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | today |
| 7 | Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines. | AgentSecOps/ | 219 | — | ~2.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 8 | Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify… | nvuillam/ | 248 | — | ~1.9k | Automated safety check: Notes | MIT | 3 days ago |
| 9 | 9.Dep Scan Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema. | epam/ | 504 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 10 | Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in… | malloydata/ | 116 | — | ~5.1k | Automated safety check: Pass | MIT | today |
| 11 | 11.Cloud Audit Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images | CommonHuman-Lab/ | 156 | — | ~1.1k | Automated safety check: Pass | Unknown | today |
| 12 | Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp… | cloudposse/ | 1.4k | — | ~5.1k | Automated safety check: Warn | Apache-2.0 | today |
| 13 | When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain | deonmenezes/ | 505 | — | ~510 | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 14 | 14.Docker Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and… | EliasOulkadi/ | 114 | — | ~3.8k | Automated safety check: Notes | MIT | 2 days ago |
| 15 | Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle… | axelixlabs/ | 147 | — | ~4.2k | Automated safety check: Pass | LGPL-3.0 | yesterday |
| 16 | Run or install repo security leak checks with BetterLeaks and Trivy. | instructa/ | 139 | — | ~557 | Automated safety check: Pass | No licence | 9 days ago |
| 17 | Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review. | Jeffallan/ | 12k | — | ~1.3k | Automated safety check: Pass | MIT | 4 days ago |
| 18 | Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults. | Aedelon/ | 120 | — | ~1.6k | Automated safety check: Notes | Unknown | 7 mo ago |
| 19 | Operate Syft, Grype, Trivy, Gitleaks, Retire.js, package-manager metadata, and build evidence for advanced software-supply-chain assessment. | cyberful/ | 134 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 20 | 20.Houndarr CI Houndarr's CI workflow reference and branch protection. An agent skill from av1155/houndarr. | av1155/ | 292 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 2 days ago |
| 21 | Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and… | hardw00t/ | 104 | — | ~2.8k | Automated safety check: Pass | No licence | 5 mo ago |
| 22 | 22.Sca Trivy Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license… | AgentSecOps/ | 219 | 2 repos | ~3.7k | Automated safety check: Pass | Unknown | 5 mo ago |
| 23 | Reduces container attack surface by building application images on Google distroless base images that ship only the application runtime - no shell, package manager, or OS utilities - using… | mukul975/ | 34k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 24 | Integrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 25 | Scores Kubernetes resource manifests with Kubesec to flag misconfiguration and privilege-escalation risk before deployment, mapping each finding back to the securityContext change that fixes it. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 26 | Configures the security features of the Harbor open-source container registry - integrated Trivy scanning, Cosign and Notary content trust policies, project-level RBAC, immutable tag and retention… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 27 | Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 28 | Scan container images for vulnerabilities using Trivy, Grype, and cloud-native tools. | sickn33/ | 47k | 1 repo | ~2.3k | Automated safety check: Pass | MIT | yesterday |
| 29 | Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 30 | Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed… | mukul975/ | 34k | — | ~818 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 31 | Handle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.). | hardisgroupcom/ | 400 | — | ~1.3k | Automated safety check: Notes | AGPL-3.0 | today |
| 32 | Scans a Docker image with Trivy for vulnerabilities in OS packages and language dependencies, misconfiguration, exposed secrets, and licence violations, emitting SARIF, CycloneDX, or SPDX output. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 33 | A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has… | ericrisco/ | 156 | — | ~2.8k | Automated safety check: Notes | MIT | today |
| 34 | Operate kubectl, kube-bench, Trivy, Prowler, and manifest/runtime evidence for advanced Kubernetes security assessment. | cyberful/ | 134 | — | ~898 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 35 | CI/CD pipeline security gate design guide. An agent skill from revfactory/harness-100. | revfactory/ | 1.3k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 36 | Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files. | benchflow-ai/ | 1.8k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 37 | 37.Vul Analyse 漏扫报告分析 Skill。输入主流厂商漏扫报告(绿盟/深信服/悬镜/明鉴/等保/奇安信/启明/华云安/长亭/Nessus/Trivy/Grype/Snyk/OpenVAS 等 Excel/HTML/JSON/XML/.nessus 格式),自动提取漏洞并去重,可选对接知识库 Provider(修复历史)和威胁情报 Provider(CVE 情报),生成 7… | infometa/ | 342 | — | ~3.9k | Automated safety check: Pass | No licence | today |
| 38 | Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit. | secondsky/ | 227 | — | ~799 | Automated safety check: Pass | MIT | 9 days ago |
| 39 | 39.Cve Analysis CVE(Common Vulnerabilities and Exposures) 분석 방법론, 의존성 취약점 스캔 도구 활용, CVSS 점수 해석, 취약점 우선순위 결정 가이드. | revfactory/ | 1.3k | — | ~853 | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 40 | CI/CD 파이프라인 보안 게이트 설계 가이드. An agent skill from revfactory/harness-100. | revfactory/ | 1.3k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 41 | Expert-level Container Security skill using Trivy, Snyk, and other tools for vulnerability scanning, compliance checking, and container hardening. | theneoai/ | 183 | — | ~4.6k | Automated safety check: Pass | MIT | 4 mo ago |
| 42 | Add container image scanning steps to existing Harness pipelines using Harness STO scanners. | harness/ | 115 | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | today |
| 43 | Add secret detection scanning steps to existing Harness pipelines using STO security scanners. | harness/ | 115 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | today |
Questions, answered from the data.
What is the best Trivy skill?
Release (official) from sourcegraph/src-cli ranks first of the 43 Trivy skills listed here, with the highest score: its repository has 359 GitHub stars, its SKILL.md loads about 1.9k tokens and it passes the automated safety check with no findings. Next come Scan Code and Fix Image Cves.
Is there an official Trivy skill?
4 of the 43 Trivy skills are official, published by the vendor's own GitHub organization: Release, Scan Code, Fix Image Cves and Remediate Image Cves.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.