Agent skill

Trivy Offline Vulnerability Scanning

by benchflow-ai in benchflow-ai/skillsbench

Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files.

Apache-2.0Auto-check passedSecurity

Install Trivy Offline Vulnerability Scanning

skills CLI
$ npx skills add benchflow-ai/skillsbench --skill trivy-offline-vulnerability-scanning -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install benchflow-ai/skillsbench trivy-offline-vulnerability-scanning --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/benchflow-ai/skillsbench.git skills-src && mkdir -p .claude/skills && cp -r skills-src/tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning .claude/skills/trivy-offline-vulnerability-scanning && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
trivy-offline-vulnerability-scanning
GitHub stars
1.8k
Token cost
~1.8k tokens
SKILL.md length
324 words
Files
1
Skills in repo
189
Repo updated
First seen
Licence
Apache-2.0

At a glance

Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files.

  • Works in 3 steps: Verify Database Existence → Construct Trivy Command → Execute Scan
  • Tasks that involve Vulnerability scanning
  • SKILL.md covers Overview, Why Offline Mode?, Trivy Database Structure and Offline Scanning Workflow, plus 5 more sections
  • Calls apt-get and wget; reaches aquasecurity.github.io and avd.aquasec.com

What it does

Trivy Offline Vulnerability Scanning is an agent skill from benchflow-ai/skillsbench. Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files. This skill covers setting up offline scanning, executing Trivy against package lock files, and generating JSON vulnerability reports without requiring internet access.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning. It works with Trivy. The repository describes itself as: SkillsBench evaluates how well skills work and how effective agents are at using them. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Vulnerability scanning

Example prompts

  • “/trivy-offline-vulnerability-scanning”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Verify Database Existence
  2. Construct Trivy Command
  3. Execute Scan

What it can do on your machine

Read from SKILL.md and the folder at commit 9a1f4dd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • apt-get
    • wget

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • aquasecurity.github.io
    • avd.aquasec.com

    Also links to:

    • cve.mitre.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Trivy Offline Vulnerability Scanning loads about 1.8k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 324 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from benchflow-ai/skillsbench at commit 9a1f4dd, republished under its Apache-2.0 licence (© benchflow-ai). 324 words, ~1,795 tokens.

Download SKILL.mdSave it as .claude/skills/trivy-offline-vulnerability-scanning/SKILL.md (or your agent's skills folder).
name
trivy-offline-vulnerability-scanning
description
Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files. This skill covers setting up offline scanning, executing Trivy against package lock files, and generating JSON vulnerability reports without requiring internet access.

Trivy Offline Vulnerability Scanning

This skill provides guidance on using Trivy, an open-source security scanner, to discover vulnerabilities in software dependencies using offline mode.

Overview

Trivy is a comprehensive vulnerability scanner that can analyze various targets including container images, filesystems, and dependency lock files. Offline scanning is crucial for:

  • Air-gapped environments without internet access
  • Reproducible security audits with fixed vulnerability databases
  • Faster CI/CD pipelines avoiding network latency
  • Compliance requirements for controlled environments

Why Offline Mode?

Challenges with Online Scanning
  • Network dependency introduces failure points
  • Database updates can cause inconsistent results across runs
  • Slower execution due to download times
  • Security policies may restrict external connections
Benefits of Offline Scanning
  • Reproducibility: Same database = same results
  • Speed: No network overhead
  • Reliability: No external dependencies
  • Compliance: Works in restricted environments

Trivy Database Structure

Trivy's vulnerability database consists of:

  • trivy.db: SQLite database containing CVE information
  • metadata.json: Database version and update timestamp

Database location: <cache-dir>/db/trivy.db

Offline Scanning Workflow

Step 1: Verify Database Existence

Before scanning, ensure the offline database is available:

python
import os
import sys

TRIVY_CACHE_PATH = './trivy-cache'

# Check for database file
db_path = os.path.join(TRIVY_CACHE_PATH, "db", "trivy.db")
if not os.path.exists(db_path):
    print(f"[!] Error: Trivy database not found at {db_path}")
    print("    Download database first with:")
    print(f"    trivy image --download-db-only --cache-dir {TRIVY_CACHE_PATH}")
    sys.exit(1)
Step 2: Construct Trivy Command

Key flags for offline scanning:

FlagPurpose
fs <target>Scan filesystem/file (e.g., package-lock.json)
--format jsonOutput in JSON format for parsing
--output <file>Save results to file
--scanners vulnScan only for vulnerabilities (not misconfigs)
--skip-db-updateCritical: Do not update database
--offline-scanEnable offline mode
--cache-dir <path>Path to pre-downloaded database
python
import subprocess

TARGET_FILE = 'package-lock.json'
OUTPUT_FILE = 'trivy_report.json'
TRIVY_CACHE_PATH = './trivy-cache'

command = [
    "trivy", "fs", TARGET_FILE,
    "--format", "json",
    "--output", OUTPUT_FILE,
    "--scanners", "vuln",
    "--skip-db-update",      # Prevent online updates
    "--offline-scan",         # Enable offline mode
    "--cache-dir", TRIVY_CACHE_PATH
]
Step 3: Execute Scan
python
try:
    result = subprocess.run(
        command,
        capture_output=True,
        text=True,
        check=False  # Don't raise exception on non-zero exit
    )
    
    if result.returncode != 0:
        print("[!] Trivy scan failed:")
        print(result.stderr)
        sys.exit(1)
    
    print("[*] Scan completed successfully")
    print(f"[*] Results saved to: {OUTPUT_FILE}")
    
except FileNotFoundError:
    print("[!] Error: 'trivy' command not found")
    print("    Install Trivy: https://aquasecurity.github.io/trivy/latest/getting-started/installation/")
    sys.exit(1)

Complete Example

python
import os
import sys
import subprocess

def run_trivy_offline_scan(target_file, output_file, cache_dir='./trivy-cache'):
    """
    Execute Trivy vulnerability scan in offline mode.
    
    Args:
        target_file: Path to file to scan (e.g., package-lock.json)
        output_file: Path to save JSON results
        cache_dir: Path to Trivy offline database
    """
    print(f"[*] Starting Trivy offline scan...")
    print(f"    Target: {target_file}")
    print(f"    Database: {cache_dir}")
    
    # Verify database exists
    db_path = os.path.join(cache_dir, "db", "trivy.db")
    if not os.path.exists(db_path):
        print(f"[!] Error: Database not found at {db_path}")
        sys.exit(1)
    
    # Build command
    command = [
        "trivy", "fs", target_file,
        "--format", "json",
        "--output", output_file,
        "--scanners", "vuln",
        "--skip-db-update",
        "--offline-scan",
        "--cache-dir", cache_dir
    ]
    
    # Execute
    try:
        result = subprocess.run(command, capture_output=True, text=True)
        
        if result.returncode != 0:
            print("[!] Scan failed:")
            print(result.stderr)
            sys.exit(1)
        
        print("[*] Scan completed successfully")
        return output_file
        
    except FileNotFoundError:
        print("[!] Trivy not found. Install from:")
        print("    https://aquasecurity.github.io/trivy/")
        sys.exit(1)

# Usage
if __name__ == "__main__":
    run_trivy_offline_scan(
        target_file='package-lock.json',
        output_file='trivy_report.json'
    )

JSON Output Structure

Trivy outputs vulnerability data in this format:

json
{
  "Results": [
    {
      "Target": "package-lock.json",
      "Vulnerabilities": [
        {
          "VulnerabilityID": "CVE-2021-44906",
          "PkgName": "minimist",
          "InstalledVersion": "1.2.5",
          "FixedVersion": "1.2.6",
          "Severity": "CRITICAL",
          "Title": "Prototype Pollution in minimist",
          "PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-44906",
          "CVSS": {
            "nvd": { "V3Score": 9.8 }
          }
        }
      ]
    }
  ]
}

Common Issues

Issue: "failed to initialize DB"

Cause: Database not found or corrupted
Solution: Re-download database or check --cache-dir path

Issue: Scan finds no vulnerabilities when they exist

Cause: Database is outdated
Solution: Download newer database (before going offline)

Issue: "command not found: trivy"

Cause: Trivy not installed or not in PATH
Solution: Install Trivy following official documentation

Dependencies

Required Tools
  • Trivy: Version 0.40.0 or later recommended
    bash
    # Installation (example for Debian/Ubuntu)
    wget -qO - https://aquasecurity.github.io/trivy-repo/deb/public.key | apt-key add -
    echo "deb https://aquasecurity.github.io/trivy-repo/deb $(lsb_release -sc) main" | tee -a /etc/apt/sources.list.d/trivy.list
    apt-get update
    apt-get install trivy
Python Modules
  • subprocess (standard library)
  • os (standard library)
  • sys (standard library)

References

© benchflow-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning of benchflow-ai/skillsbench.

Open the folder on GitHubat commit 9a1f4dd

Compare with similar skills

Trivy Offline Vulnerability Scanning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Trivy Offline Vulnerability Scanning compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Trivy Offline Vulnerability Scanning this skillbenchflow-ai/skillsbench1.8k—~1.8kAutomated safety check: PassApache-2.0
DefectDojo Vulnerability ManagementAgentSecOps/SecOpsAgentKit220—~2.3kAutomated safety check: PassCustom licence
Container Securityhardw00t/ai-security-arsenal105—~2.8kAutomated safety check: PassNone
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence
Pipeline Security Gatesrevfactory/harness-1001.3k—~1.5kAutomated safety check: PassApache-2.0
Upgrade Java Depsnvuillam/npm-groovy-lint248—~1.9kAutomated safety check: NotesMIT

Similar skills

  • DefectDojo Vulnerability Management

    AgentSecOps/SecOpsAgentKit

    Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

    220 GitHub stars~2.3k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    105 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Pipeline Security Gates

    revfactory/harness-100

    CI/CD pipeline security gate design guide. An agent skill from revfactory/harness-100.

    1.3k GitHub stars~1.5k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Upgrade Java Deps

    nvuillam/npm-groovy-lint

    Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…

    248 GitHub stars~1.9k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Dep Scan

    epam/ai-dial-chat

    Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema.

    504 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check passed

More from benchflow-ai/skillsbench

All 189 skills in this repo
  • Lean4 Memories

    benchflow-ai/skillsbench

    This skill should be used when working on Lean 4 formalization projects to maintain persistent memory of successful proof patterns, failed approaches, project conventions, and user preferences…

    1.8k GitHub stars~3.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Senior Data Engineer

    benchflow-ai/skillsbench

    World-class data engineering skill for building scalable data pipelines, ETL/ELT systems, real-time streaming, and data infrastructure.

    1.8k GitHub stars~5.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Ac Branch Pi Model

    benchflow-ai/skillsbench

    AC branch pi-model power flow equations (P/Q and |S|) with transformer tap ratio and phase shift, matching acopf-math-model.md and MATPOWER branch fields.

    1.8k GitHub stars~1.1k tokensUpdated 2 mo ago
    Auto-check passed
  • Civ6lib

    benchflow-ai/skillsbench

    Civilization 6 district mechanics library. An agent skill from benchflow-ai/skillsbench.

    1.8k GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed
  • D3 Visualization

    benchflow-ai/skillsbench

    Build deterministic, verifiable data visualizations with D3.js (v6).

    1.8k GitHub stars~1.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Dc Power Flow

    benchflow-ai/skillsbench

    DC power flow analysis for power systems. An agent skill from benchflow-ai/skillsbench.

    1.8k GitHub stars~717 tokensUpdated 2 mo ago
    Auto-check passed

Works with

Categories

Questions about Trivy Offline Vulnerability Scanning

What does Trivy Offline Vulnerability Scanning do?

Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files. Trivy Offline Vulnerability Scanning is an agent skill from benchflow-ai/skillsbench. Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files.

When should I use Trivy Offline Vulnerability Scanning?

Trivy Offline Vulnerability Scanning fits situations like: tasks that involve Vulnerability scanning.

How do I install Trivy Offline Vulnerability Scanning in Claude Code?

Run `npx skills add benchflow-ai/skillsbench --skill trivy-offline-vulnerability-scanning -a claude-code`. Or copy the skill folder (tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning in benchflow-ai/skillsbench) into .claude/skills/trivy-offline-vulnerability-scanning in your project. Claude Code loads it when a task matches its description.

How do I install Trivy Offline Vulnerability Scanning in Codex?

Run `npx skills add benchflow-ai/skillsbench --skill trivy-offline-vulnerability-scanning -a codex`. Or copy the skill folder (tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning in benchflow-ai/skillsbench) into .agents/skills/trivy-offline-vulnerability-scanning in your project. Codex loads it when a task matches its description.

Can I use Trivy Offline Vulnerability Scanning in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add benchflow-ai/skillsbench --skill trivy-offline-vulnerability-scanning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/trivy-offline-vulnerability-scanning, .gemini/skills/trivy-offline-vulnerability-scanning, .github/skills/trivy-offline-vulnerability-scanning and .opencode/skills/trivy-offline-vulnerability-scanning in your project.

What does Trivy Offline Vulnerability Scanning need to run?

Going by SKILL.md and its folder, Trivy Offline Vulnerability Scanning needs the command-line tools its instructions call (apt-get and wget). Our summary lists: Python 3.

Does Trivy Offline Vulnerability Scanning access the network?

SKILL.md names 3 domains. In commands or code: aquasecurity.github.io and avd.aquasec.com; the agent is likely to contact these when it follows the instructions. As links in the text: cve.mitre.org. This is read from the text; nothing was executed.

Is Trivy Offline Vulnerability Scanning safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Trivy Offline Vulnerability Scanning use?

Trivy Offline Vulnerability Scanning is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Trivy Offline Vulnerability Scanning use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Trivy Offline Vulnerability Scanning?

Skills that share tags, products or a category with Trivy Offline Vulnerability Scanning: DefectDojo Vulnerability Management (AgentSecOps/SecOpsAgentKit, 220 stars), Container Security (hardw00t/ai-security-arsenal, 105 stars), Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars) and Pipeline Security Gates (revfactory/harness-100, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Trivy Offline Vulnerability Scanning?

benchflow-ai (a GitHub organization) maintains it in benchflow-ai/skillsbench, which has 1,835 GitHub stars. The repository holds 189 skills in this directory. The repository was last updated on July 23, 2026.

Source: benchflow-ai/skillsbench on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.