Agent skill

Managing Vulnerabilities

by ancoleman in ancoleman/ai-design-components

Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines.

MITAuto-check passedSecurity

Install Managing Vulnerabilities

skills CLI
$ npx skills add ancoleman/ai-design-components --skill managing-vulnerabilities -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ancoleman/ai-design-components managing-vulnerabilities --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/managing-vulnerabilities .claude/skills/managing-vulnerabilities && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
managing-vulnerabilities
GitHub stars
526
Token cost
~3.8k tokens
SKILL.md length
988 words
Files
15 (incl. scripts, references)
Skills in repo
75
Repo updated
First seen
Licence
MIT

At a glance

Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines.

  • Building DevSecOps workflows
  • SKILL.md covers When to Use This Skill, Multi-Layer Scanning Strategy, SBOM Generation and Vulnerability Prioritization, plus 7 more sections
  • Runs Shell and Python scripts from its folder; calls trivy and gitleaks
  • Ensuring compliance

What it does

Managing Vulnerabilities is an agent skill from ancoleman/ai-design-components. Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines. Use when building DevSecOps workflows, ensuring compliance, or establishing security gates for container deployments.

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 20 other files, including scripts and reference files (for example `examples/ci-cd/github-actions-multi-stage.yml`, `examples/prioritization/epss-integration.py` and `examples/prioritization/kev-checker.py`).

It sits in Security, covering Supply chain security, Prioritization frameworks and CI/CD. It works with Snyk. The repository describes itself as: Comprehensive UI/UX and Backend component design skills for AI-assisted development with Claude. The licence is MIT.

When your agent uses it

  • Building DevSecOps workflows
  • Ensuring compliance
  • Establishing security gates for container deployments

Example prompts

  • “/managing-vulnerabilities”

Requirements

  • Python 3
  • A Bash shell
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 76551b7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell and Python), which the agent can run.

    Shell commands in SKILL.md call:

    • trivy
    • gitleaks

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Managing Vulnerabilities loads about 3.8k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 76 tokens; SKILL.md has 988 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~22k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ancoleman/ai-design-components at commit 76551b7, republished under its MIT licence (© ancoleman). 988 words, ~3,755 tokens.

Download SKILL.mdSave it as .claude/skills/managing-vulnerabilities/SKILL.md (or your agent's skills folder). This skill also uses 14 other files; get the full folder from GitHub.
name
managing-vulnerabilities
description
Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines. Use when building DevSecOps workflows, ensuring compliance, or establishing security gates for container deployments.

Vulnerability Management

Implement comprehensive vulnerability detection and remediation workflows across containers, source code, dependencies, and running applications. This skill covers multi-layer scanning strategies, SBOM generation (CycloneDX and SPDX), risk-based prioritization using CVSS/EPSS/KEV, and CI/CD security gate patterns.

When to Use This Skill

Invoke this skill when:

  • Building security scanning into CI/CD pipelines
  • Generating Software Bills of Materials (SBOMs) for compliance
  • Prioritizing vulnerability remediation using risk-based approaches
  • Implementing security gates (fail builds on critical vulnerabilities)
  • Scanning container images before deployment
  • Detecting secrets, misconfigurations, or code vulnerabilities
  • Establishing DevSecOps practices and automation
  • Meeting regulatory requirements (SBOM mandates, Executive Order 14028)

Multi-Layer Scanning Strategy

Vulnerability management requires scanning at multiple layers. Each layer detects different types of security issues.

Layer Overview

Container Image Scanning

  • Detects vulnerabilities in OS packages, language dependencies, and binaries
  • Tools: Trivy (comprehensive), Grype (accuracy-focused), Snyk Container (commercial)
  • When: Every container build, base image selection, registry admission control

SAST (Static Application Security Testing)

  • Analyzes source code for security flaws before runtime
  • Tools: Semgrep (fast, semantic), Snyk Code (developer-first), SonarQube (enterprise)
  • When: Every commit, PR checks, main branch protection

DAST (Dynamic Application Security Testing)

  • Tests running applications for vulnerabilities (black-box testing)
  • Tools: OWASP ZAP (open-source), StackHawk (CI/CD native), Burp Suite (manual + automated)
  • When: Staging environment testing, API validation, authentication testing

SCA (Software Composition Analysis)

  • Analyzes third-party dependencies for known vulnerabilities
  • Tools: Dependabot (GitHub native), Renovate (advanced), Snyk Open Source (commercial)
  • When: Every build, dependency updates, license audits

Secret Scanning

  • Prevents secrets from being committed to source code
  • Tools: Gitleaks (fast, configurable), TruffleHog (entropy detection), GitGuardian (commercial)
  • When: Pre-commit hooks, repository scanning, CI/CD artifact checks
Quick Tool Selection
Container Image → Trivy (default choice) OR Grype (accuracy focus)
Source Code → Semgrep (open-source) OR Snyk Code (commercial)
Running Application → OWASP ZAP (open-source) OR StackHawk (CI/CD native)
Dependencies → Dependabot (GitHub) OR Renovate (advanced automation)
Secrets → Gitleaks (open-source) OR GitGuardian (commercial)

For detailed tool selection guidance, see references/tool-selection.md.

SBOM Generation

Software Bills of Materials (SBOMs) provide a complete inventory of software components and dependencies. Required for compliance and security transparency.

CycloneDX vs. SPDX

CycloneDX (Recommended for DevSecOps)

  • Security-focused, OWASP-maintained
  • Native vulnerability references
  • Fast, lightweight (JSON/XML/ProtoBuf)
  • Best for: DevSecOps pipelines, vulnerability tracking

SPDX (Recommended for Legal/Compliance)

  • License compliance focus, ISO standard (ISO/IEC 5962:2021)
  • Comprehensive legal metadata
  • Government/defense preferred format
  • Best for: Legal teams, compliance audits, federal requirements
Generating SBOMs

With Trivy (CycloneDX or SPDX):

bash
# CycloneDX format (recommended for security)
trivy image --format cyclonedx --output sbom.json myapp:latest

# SPDX format (for compliance)
trivy image --format spdx-json --output sbom-spdx.json myapp:latest

# Scan SBOM (faster than re-scanning image)
trivy sbom sbom.json --severity HIGH,CRITICAL

With Syft (high accuracy):

bash
# Generate CycloneDX
syft myapp:latest -o cyclonedx-json=sbom.json

# Generate SPDX
syft myapp:latest -o spdx-json=sbom-spdx.json

# Pipe to Grype for scanning
syft myapp:latest -o json | grype

For comprehensive SBOM patterns and storage strategies, see references/sbom-guide.md.

Vulnerability Prioritization

Not all vulnerabilities require immediate action. Prioritize based on actual risk using CVSS, EPSS, and KEV.

Modern Risk-Based Prioritization

Step 1: Gather Metrics

MetricSourcePurpose
CVSS Base ScoreNVD, vendor advisoriesVulnerability severity (0-10)
EPSS ScoreFIRST.org APIExploitation probability (0-1)
KEV StatusCISA KEV CatalogActively exploited CVEs
Asset CriticalityInternal CMDBBusiness impact if compromised
ExposureNetwork topologyInternet-facing vs. internal

Step 2: Calculate Priority

Priority Score = (CVSS × 0.3) + (EPSS × 100 × 0.3) + (KEV × 50) + (Asset × 0.2) + (Exposure × 0.2)

KEV: 1 if in KEV catalog, 0 otherwise
Asset: 1 (Critical), 0.7 (High), 0.4 (Medium), 0.1 (Low)
Exposure: 1 (Internet-facing), 0.5 (Internal), 0.1 (Isolated)

Step 3: Apply SLA Tiers

PriorityCriteriaSLAAction
P0 - CriticalKEV + Internet-facing + Critical asset24 hoursEmergency patch immediately
P1 - HighCVSS ≥ 9.0 OR (CVSS ≥ 7.0 AND EPSS ≥ 0.1)7 daysPrioritize in sprint, patch ASAP
P2 - MediumCVSS 7.0-8.9 OR EPSS ≥ 0.0530 daysNormal sprint planning
P3 - LowCVSS 4.0-6.9, EPSS < 0.0590 daysBacklog, maintenance windows
P4 - InfoCVSS < 4.0No SLATrack, address opportunistically

Example: Log4Shell (CVE-2021-44228)

CVSS: 10.0
EPSS: 0.975 (97.5% exploitation probability)
KEV: Yes (CISA catalog)
Asset: Critical (payment API)
Exposure: Internet-facing

Priority Score = (10 × 0.3) + (97.5 × 0.3) + 50 + (1 × 0.2) + (1 × 0.2) = 82.65
Result: P0 - Critical (24-hour SLA)

For complete prioritization framework and automation scripts, see references/prioritization-framework.md.

CI/CD Integration Patterns

Multi-Stage Security Pipeline

Implement progressive security gates across pipeline stages:

Stage 1: Pre-Commit (Developer Workstation)

yaml
Tools: Secret scanning (Gitleaks), SAST (Semgrep)
Threshold: Block high-confidence secrets, critical SAST findings
Speed: < 10 seconds

Stage 2: Pull Request (CI Pipeline)

yaml
Tools: SAST, SCA, Secret scanning
Threshold: No Critical/High vulnerabilities, no secrets
Speed: < 5 minutes
Action: Block PR merge until fixed

Stage 3: Build (CI Pipeline)

yaml
Tools: Container scanning (Trivy), SBOM generation
Threshold: No Critical vulnerabilities in production dependencies
Artifacts: SBOM stored, scan results uploaded
Speed: < 2 minutes
Action: Fail build on Critical findings

Stage 4: Pre-Deployment (Staging)

yaml
Tools: DAST, Integration tests
Threshold: No Critical/High DAST findings
Speed: 10-30 minutes
Action: Gate deployment to production

Stage 5: Production (Runtime)

yaml
Tools: Continuous scanning, runtime monitoring
Threshold: Alert on new CVEs in deployed images
Action: Alert security team, plan patching
Example: GitHub Actions Multi-Stage Scan
yaml
name: Security Scan Pipeline

on: [push, pull_request]

jobs:
  secrets:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: trufflesecurity/trufflehog@main
        with:
          path: ./
          extra_args: --only-verified

  sast:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: semgrep/semgrep-action@v1
        with:
          config: p/security-audit

  container:
    runs-on: ubuntu-latest
    needs: [secrets, sast]
    steps:
      - uses: actions/checkout@v4
      - run: docker build -t myapp:${{ github.sha }} .

      - uses: aquasecurity/trivy-action@master
        with:
          image-ref: myapp:${{ github.sha }}
          format: sarif
          output: trivy-results.sarif
          severity: HIGH,CRITICAL
          exit-code: 1

      - name: Generate SBOM
        run: |
          trivy image --format cyclonedx \
            --output sbom.json myapp:${{ github.sha }}

      - uses: actions/upload-artifact@v3
        with:
          name: sbom
          path: sbom.json

For complete CI/CD patterns (GitLab CI, Jenkins, Azure Pipelines), see references/ci-cd-patterns.md.

Container Scanning with Trivy

Trivy is the recommended default for container scanning: comprehensive, fast, and CI/CD native.

Basic Usage
bash
# Scan container image
trivy image alpine:latest

# Scan with severity filter
trivy image --severity HIGH,CRITICAL alpine:latest

# Fail on findings (CI/CD)
trivy image --exit-code 1 --severity HIGH,CRITICAL myapp:latest

# Generate SBOM
trivy image --format cyclonedx --output sbom.json alpine:latest

# Scan filesystem
trivy fs /path/to/project

# Scan Kubernetes manifests
trivy config deployment.yaml
Configuration (.trivy.yaml)
yaml
severity: HIGH,CRITICAL
exit-code: 1
ignore-unfixed: true  # Only fail on fixable vulnerabilities
vuln-type: os,library
skip-dirs:
  - node_modules
  - vendor
ignorefile: .trivyignore
Ignoring False Positives (.trivyignore)
# False positive
CVE-2023-12345

# Accepted risk with justification
CVE-2023-67890  # Risk accepted: Not exploitable in our use case

# Development dependency (not in production)
CVE-2023-11111  # Dev dependency only
GitHub Actions Integration
yaml
- name: Trivy Scan
  uses: aquasecurity/trivy-action@master
  with:
    image-ref: myapp:${{ github.sha }}
    format: sarif
    output: trivy-results.sarif
    severity: HIGH,CRITICAL
    exit-code: 1

- name: Upload to GitHub Security
  uses: github/codeql-action/upload-sarif@v2
  if: always()
  with:
    sarif_file: trivy-results.sarif
Show full SKILL.md (395 more words)Show less

Alternative: Grype for Accuracy

Grype focuses on minimal false positives and works with Syft for SBOM generation.

Important: Use Grype v0.104.1 or later (credential disclosure CVE-2025-65965 patched in earlier versions).

Basic Usage
bash
# Scan container image
grype alpine:latest

# Scan with severity threshold
grype alpine:latest --fail-on high

# Scan SBOM (faster)
grype sbom:./sbom.json

# Syft + Grype workflow
syft alpine:latest -o json | grype --fail-on critical
When to Use Grype
  • Projects sensitive to false positives
  • SBOM-first workflows (generate with Syft, scan with Grype)
  • Need second opinion validation
  • Anchore ecosystem users

For complete tool comparisons and selection criteria, see references/tool-selection.md.

Security Gates and Thresholds

Progressive Threshold Strategy

Balance security and development velocity with progressive gates. Configure different thresholds for PR checks (fast, HIGH+CRITICAL), builds (comprehensive), and deployments (strict, CRITICAL only).

Policy-as-Code

Use OPA (Open Policy Agent) for automated policy enforcement. Create policies to deny Critical vulnerabilities, enforce KEV catalog checks, and implement environment-specific rules.

For complete policy patterns, baseline detection, and OPA examples, see references/policy-as-code.md.

Remediation Workflows

Automated Remediation

Set up automated workflows to scan daily, extract fixable vulnerabilities, update dependencies, and create remediation pull requests automatically.

SLA Tracking

Track vulnerability remediation against SLA targets (P0: 24 hours, P1: 7 days, P2: 30 days, P3: 90 days). Monitor overdue vulnerabilities and escalate as needed.

False Positive Management

Maintain suppression files (.trivyignore) with documented justifications, review dates, and approval tracking. Implement workflows for false positive triage and approval.

For complete remediation workflows, SLA trackers, and automation scripts, see references/remediation-workflows.md.

building-ci-pipelines

  • Add security stages to pipeline definitions
  • Configure artifacts for SBOM storage
  • Implement quality gates with vulnerability thresholds

secret-management

  • Integrate secret scanning (Gitleaks, TruffleHog)
  • Automate secret rotation on detection
  • Use pre-commit hooks for prevention

infrastructure-as-code

  • Scan Terraform and Kubernetes manifests with Trivy config
  • Detect misconfigurations before deployment
  • Enforce policy-as-code with OPA

security-hardening

  • Apply remediation guidance from scan results
  • Select secure base images
  • Implement security best practices

compliance-frameworks

  • Generate SBOMs for SOC2, ISO 27001 audits
  • Track vulnerability metrics for compliance reporting
  • Provide evidence for security controls

Quick Reference

Essential Commands
bash
# Trivy: Scan image with severity filter
trivy image --severity HIGH,CRITICAL myapp:latest

# Trivy: Generate SBOM
trivy image --format cyclonedx --output sbom.json myapp:latest

# Trivy: Scan SBOM
trivy sbom sbom.json

# Grype: Scan image
grype myapp:latest --fail-on high

# Syft + Grype: SBOM workflow
syft myapp:latest -o json | grype

# Gitleaks: Scan for secrets
gitleaks detect --source . --verbose
Common Patterns
bash
# CI/CD: Fail build on Critical
trivy image --exit-code 1 --severity CRITICAL myapp:latest

# Ignore unfixed vulnerabilities
trivy image --ignore-unfixed --severity HIGH,CRITICAL myapp:latest

# Scan only OS packages
trivy image --vuln-type os myapp:latest

# Skip specific directories
trivy fs --skip-dirs node_modules,vendor .

Progressive Disclosure

This skill provides foundational vulnerability management patterns. For deeper topics:

  • Tool Selection: references/tool-selection.md - Complete decision frameworks
  • SBOM Patterns: references/sbom-guide.md - Generation, storage, consumption
  • Prioritization: references/prioritization-framework.md - CVSS/EPSS/KEV automation
  • CI/CD Integration: references/ci-cd-patterns.md - GitLab CI, Jenkins, Azure Pipelines
  • Remediation: references/remediation-workflows.md - SLA tracking, false positives
  • Policy-as-Code: references/policy-as-code.md - OPA examples, security gates

Working Examples:

  • examples/trivy/ - Trivy scanning patterns
  • examples/grype/ - Grype + Syft workflows
  • examples/ci-cd/ - Complete pipeline configurations
  • examples/sbom/ - SBOM generation and management
  • examples/prioritization/ - EPSS and KEV integration scripts

Automation Scripts:

  • scripts/vulnerability-report.sh - Generate executive reports
  • scripts/sla-tracker.sh - Track remediation SLAs
  • scripts/false-positive-manager.sh - Manage suppression rules

© ancoleman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 14 other files (scripts, references) in skills/managing-vulnerabilities of ancoleman/ai-design-components.

  • SKILL.md
  • examples/ci-cd/github-actions-multi-stage.yml
  • examples/prioritization/epss-integration.py
  • examples/prioritization/kev-checker.py
  • examples/trivy/basic-scan.sh
  • examples/trivy/github-actions.yml
  • examples/trivy/sbom-generation.sh
  • outputs.yaml
  • references/ci-cd-patterns.md
  • references/policy-as-code.md
  • references/prioritization-framework.md
  • references/remediation-workflows.md
  • references/sbom-guide.md
  • references/tool-selection.md
  • scripts/vulnerability-report.sh

Open the folder on GitHubat commit 76551b7

Compare with similar skills

Managing Vulnerabilities next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Managing Vulnerabilities compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Managing Vulnerabilities this skillancoleman/ai-design-components526—~3.8kAutomated safety check: PassMIT
Vulnerability Scanningsecondsky/claude-skills227—~799Automated safety check: PassMIT
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence
CI/CD Pipeline Principlesirahardianto/awesome-agv157—~2.7kAutomated safety check: NotesMIT
Atmos CIcloudposse/atmos1.4k—~3.8kAutomated safety check: PassApache-2.0
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0

Similar skills

  • Vulnerability Scanning

    secondsky/claude-skills

    Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit.

    227 GitHub stars~799 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • CI/CD Pipeline Principles

    irahardianto/awesome-agv

    Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

    157 GitHub stars~2.7k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • Atmos CI

    cloudposse/atmos

    Atmos CI: Native CI with GitHub Actions containers, native outputs, SBOM workflow-artifact publication, collapsible log groups, affected/all matrix workflows, OIDC profiles, toolchain-aware jobs…

    1.4k GitHub stars~3.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Supply Chain Security

    zhaoxuya520/reverse-skill

    A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

    40k GitHub starsUsed in 4 repos~953 tokens
    SecurityAuto-check: warnings

More from ancoleman/ai-design-components

All 75 skills in this repo
  • Building AI Chat

    ancoleman/ai-design-components

    Builds AI chat interfaces and conversational UI with streaming responses, context management, and multi-modal support.

    526 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check passed
  • Building Forms

    ancoleman/ai-design-components

    Builds form components and data collection interfaces including contact forms, registration flows, checkout processes, surveys, and settings pages.

    526 GitHub stars~3.7k tokensUpdated 10 mo ago
    Auto-check passed
  • Building Tables

    ancoleman/ai-design-components

    Builds tables and data grids for displaying tabular information, from simple HTML tables to complex enterprise data grids.

    526 GitHub stars~1.8k tokensUpdated 10 mo ago
    Auto-check passed
  • Creating Dashboards

    ancoleman/ai-design-components

    Creates comprehensive dashboard and analytics interfaces that combine data visualization, KPI cards, real-time updates, and interactive layouts.

    526 GitHub stars~3.5k tokensUpdated 10 mo ago
    Auto-check passed
  • Designing Layouts

    ancoleman/ai-design-components

    Designs layout systems and responsive interfaces including grid systems, flexbox patterns, sidebar layouts, and responsive breakpoints.

    526 GitHub stars~1.7k tokensUpdated 10 mo ago
    Auto-check passed
  • Displaying Timelines

    ancoleman/ai-design-components

    Displays chronological events and activity through timelines, activity feeds, Gantt charts, and calendar interfaces.

    526 GitHub stars~2.7k tokensUpdated 10 mo ago
    Auto-check passed

Works with

Questions about Managing Vulnerabilities

What does Managing Vulnerabilities do?

Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines. Managing Vulnerabilities is an agent skill from ancoleman/ai-design-components. Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines.

When should I use Managing Vulnerabilities?

Managing Vulnerabilities fits situations like: building DevSecOps workflows; ensuring compliance; establishing security gates for container deployments.

How do I install Managing Vulnerabilities in Claude Code?

Run `npx skills add ancoleman/ai-design-components --skill managing-vulnerabilities -a claude-code`. Or copy the skill folder (skills/managing-vulnerabilities in ancoleman/ai-design-components) into .claude/skills/managing-vulnerabilities in your project. Claude Code loads it when a task matches its description.

How do I install Managing Vulnerabilities in Codex?

Run `npx skills add ancoleman/ai-design-components --skill managing-vulnerabilities -a codex`. Or copy the skill folder (skills/managing-vulnerabilities in ancoleman/ai-design-components) into .agents/skills/managing-vulnerabilities in your project. Codex loads it when a task matches its description.

Can I use Managing Vulnerabilities in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ancoleman/ai-design-components --skill managing-vulnerabilities -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/managing-vulnerabilities, .gemini/skills/managing-vulnerabilities, .github/skills/managing-vulnerabilities and .opencode/skills/managing-vulnerabilities in your project.

What does Managing Vulnerabilities need to run?

Going by SKILL.md and its folder, Managing Vulnerabilities needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (trivy and gitleaks). Our summary lists: Python 3; A Bash shell; Docker.

Does Managing Vulnerabilities access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Managing Vulnerabilities safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Managing Vulnerabilities use?

Managing Vulnerabilities is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Managing Vulnerabilities use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 18k tokens, read only when the agent opens those files.

What are the alternatives to Managing Vulnerabilities?

Skills that share tags, products or a category with Managing Vulnerabilities: Vulnerability Scanning (secondsky/claude-skills, 227 stars), Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars), CI/CD Pipeline Principles (irahardianto/awesome-agv, 157 stars) and Atmos CI (cloudposse/atmos, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Managing Vulnerabilities?

ancoleman (a GitHub user) maintains it in ancoleman/ai-design-components, which has 526 GitHub stars. The repository holds 75 skills in this directory. The repository was last updated on December 11, 2025.

Source: ancoleman/ai-design-components on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.