DefectDojo Vulnerability Management
AgentSecOps/SecOpsAgentKit
Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.
Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files.
$ npx skills add benchflow-ai/skillsbench --skill trivy-offline-vulnerability-scanning -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install benchflow-ai/skillsbench trivy-offline-vulnerability-scanning --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/benchflow-ai/skillsbench.git skills-src && mkdir -p .claude/skills && cp -r skills-src/tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning .claude/skills/trivy-offline-vulnerability-scanning && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "trivy-offline-vulnerability-scanning" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning into .claude/skills/trivy-offline-vulnerability-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trivy-offline-vulnerability-scanning", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanningType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add benchflow-ai/skillsbench --skill trivy-offline-vulnerability-scanning -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install benchflow-ai/skillsbench trivy-offline-vulnerability-scanning --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/benchflow-ai/skillsbench.git skills-src && mkdir -p .agents/skills && cp -r skills-src/tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning .agents/skills/trivy-offline-vulnerability-scanning && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "trivy-offline-vulnerability-scanning" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning into .agents/skills/trivy-offline-vulnerability-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trivy-offline-vulnerability-scanning", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add benchflow-ai/skillsbench --skill trivy-offline-vulnerability-scanning -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install benchflow-ai/skillsbench trivy-offline-vulnerability-scanning --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/benchflow-ai/skillsbench.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning .cursor/skills/trivy-offline-vulnerability-scanning && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "trivy-offline-vulnerability-scanning" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning into .cursor/skills/trivy-offline-vulnerability-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trivy-offline-vulnerability-scanning", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/benchflow-ai/skillsbench.git --path tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add benchflow-ai/skillsbench --skill trivy-offline-vulnerability-scanning -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install benchflow-ai/skillsbench trivy-offline-vulnerability-scanning --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/benchflow-ai/skillsbench.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning .gemini/skills/trivy-offline-vulnerability-scanning && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "trivy-offline-vulnerability-scanning" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning into .gemini/skills/trivy-offline-vulnerability-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trivy-offline-vulnerability-scanning", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install benchflow-ai/skillsbench trivy-offline-vulnerability-scanningInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add benchflow-ai/skillsbench --skill trivy-offline-vulnerability-scanning -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/benchflow-ai/skillsbench.git skills-src && mkdir -p .github/skills && cp -r skills-src/tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning .github/skills/trivy-offline-vulnerability-scanning && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "trivy-offline-vulnerability-scanning" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning into .github/skills/trivy-offline-vulnerability-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trivy-offline-vulnerability-scanning", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add benchflow-ai/skillsbench --skill trivy-offline-vulnerability-scanning -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install benchflow-ai/skillsbench trivy-offline-vulnerability-scanning --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/benchflow-ai/skillsbench.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning .opencode/skills/trivy-offline-vulnerability-scanning && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "trivy-offline-vulnerability-scanning" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning into .opencode/skills/trivy-offline-vulnerability-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "trivy-offline-vulnerability-scanning", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
trivy-offline-vulnerability-scanningUse Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files.
Trivy Offline Vulnerability Scanning is an agent skill from benchflow-ai/skillsbench. Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files. This skill covers setting up offline scanning, executing Trivy against package lock files, and generating JSON vulnerability reports without requiring internet access.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Vulnerability scanning. It works with Trivy. The repository describes itself as: SkillsBench evaluates how well skills work and how effective agents are at using them. The licence is Apache-2.0.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9a1f4dd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
apt-getwgetFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
aquasecurity.github.ioavd.aquasec.comAlso links to:
cve.mitre.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Trivy Offline Vulnerability Scanning loads about 1.8k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 324 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from benchflow-ai/skillsbench at commit 9a1f4dd, republished under its Apache-2.0 licence (© benchflow-ai). 324 words, ~1,795 tokens.
.claude/skills/trivy-offline-vulnerability-scanning/SKILL.md (or your agent's skills folder).This skill provides guidance on using Trivy, an open-source security scanner, to discover vulnerabilities in software dependencies using offline mode.
Trivy is a comprehensive vulnerability scanner that can analyze various targets including container images, filesystems, and dependency lock files. Offline scanning is crucial for:
Trivy's vulnerability database consists of:
Database location: <cache-dir>/db/trivy.db
Before scanning, ensure the offline database is available:
import os
import sys
TRIVY_CACHE_PATH = './trivy-cache'
# Check for database file
db_path = os.path.join(TRIVY_CACHE_PATH, "db", "trivy.db")
if not os.path.exists(db_path):
print(f"[!] Error: Trivy database not found at {db_path}")
print(" Download database first with:")
print(f" trivy image --download-db-only --cache-dir {TRIVY_CACHE_PATH}")
sys.exit(1)Key flags for offline scanning:
| Flag | Purpose |
|---|---|
fs <target> | Scan filesystem/file (e.g., package-lock.json) |
--format json | Output in JSON format for parsing |
--output <file> | Save results to file |
--scanners vuln | Scan only for vulnerabilities (not misconfigs) |
--skip-db-update | Critical: Do not update database |
--offline-scan | Enable offline mode |
--cache-dir <path> | Path to pre-downloaded database |
import subprocess
TARGET_FILE = 'package-lock.json'
OUTPUT_FILE = 'trivy_report.json'
TRIVY_CACHE_PATH = './trivy-cache'
command = [
"trivy", "fs", TARGET_FILE,
"--format", "json",
"--output", OUTPUT_FILE,
"--scanners", "vuln",
"--skip-db-update", # Prevent online updates
"--offline-scan", # Enable offline mode
"--cache-dir", TRIVY_CACHE_PATH
]try:
result = subprocess.run(
command,
capture_output=True,
text=True,
check=False # Don't raise exception on non-zero exit
)
if result.returncode != 0:
print("[!] Trivy scan failed:")
print(result.stderr)
sys.exit(1)
print("[*] Scan completed successfully")
print(f"[*] Results saved to: {OUTPUT_FILE}")
except FileNotFoundError:
print("[!] Error: 'trivy' command not found")
print(" Install Trivy: https://aquasecurity.github.io/trivy/latest/getting-started/installation/")
sys.exit(1)import os
import sys
import subprocess
def run_trivy_offline_scan(target_file, output_file, cache_dir='./trivy-cache'):
"""
Execute Trivy vulnerability scan in offline mode.
Args:
target_file: Path to file to scan (e.g., package-lock.json)
output_file: Path to save JSON results
cache_dir: Path to Trivy offline database
"""
print(f"[*] Starting Trivy offline scan...")
print(f" Target: {target_file}")
print(f" Database: {cache_dir}")
# Verify database exists
db_path = os.path.join(cache_dir, "db", "trivy.db")
if not os.path.exists(db_path):
print(f"[!] Error: Database not found at {db_path}")
sys.exit(1)
# Build command
command = [
"trivy", "fs", target_file,
"--format", "json",
"--output", output_file,
"--scanners", "vuln",
"--skip-db-update",
"--offline-scan",
"--cache-dir", cache_dir
]
# Execute
try:
result = subprocess.run(command, capture_output=True, text=True)
if result.returncode != 0:
print("[!] Scan failed:")
print(result.stderr)
sys.exit(1)
print("[*] Scan completed successfully")
return output_file
except FileNotFoundError:
print("[!] Trivy not found. Install from:")
print(" https://aquasecurity.github.io/trivy/")
sys.exit(1)
# Usage
if __name__ == "__main__":
run_trivy_offline_scan(
target_file='package-lock.json',
output_file='trivy_report.json'
)Trivy outputs vulnerability data in this format:
{
"Results": [
{
"Target": "package-lock.json",
"Vulnerabilities": [
{
"VulnerabilityID": "CVE-2021-44906",
"PkgName": "minimist",
"InstalledVersion": "1.2.5",
"FixedVersion": "1.2.6",
"Severity": "CRITICAL",
"Title": "Prototype Pollution in minimist",
"PrimaryURL": "https://avd.aquasec.com/nvd/cve-2021-44906",
"CVSS": {
"nvd": { "V3Score": 9.8 }
}
}
]
}
]
}Cause: Database not found or corrupted
Solution: Re-download database or check --cache-dir path
Cause: Database is outdated
Solution: Download newer database (before going offline)
Cause: Trivy not installed or not in PATH
Solution: Install Trivy following official documentation
# Installation (example for Debian/Ubuntu)
wget -qO - https://aquasecurity.github.io/trivy-repo/deb/public.key | apt-key add -
echo "deb https://aquasecurity.github.io/trivy-repo/deb $(lsb_release -sc) main" | tee -a /etc/apt/sources.list.d/trivy.list
apt-get update
apt-get install trivysubprocess (standard library)os (standard library)sys (standard library)© benchflow-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning of benchflow-ai/skillsbench.
Open the folder on GitHubat commit 9a1f4dd
Trivy Offline Vulnerability Scanning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Trivy Offline Vulnerability Scanning this skillbenchflow-ai/skillsbench | 1.8k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| DefectDojo Vulnerability ManagementAgentSecOps/SecOpsAgentKit | 220 | — | ~2.3k | Automated safety check: Pass | Custom licence | |
| Container Securityhardw00t/ai-security-arsenal | 105 | — | ~2.8k | Automated safety check: Pass | None | |
| Sca TrivyAgentSecOps/SecOpsAgentKit | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Custom licence | |
| Pipeline Security Gatesrevfactory/harness-100 | 1.3k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Upgrade Java Depsnvuillam/npm-groovy-lint | 248 | — | ~1.9k | Automated safety check: Notes | MIT |
AgentSecOps/SecOpsAgentKit
Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.
hardw00t/ai-security-arsenal
Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
revfactory/harness-100
CI/CD pipeline security gate design guide. An agent skill from revfactory/harness-100.
nvuillam/npm-groovy-lint
Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…
epam/ai-dial-chat
Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema.
benchflow-ai/skillsbench
This skill should be used when working on Lean 4 formalization projects to maintain persistent memory of successful proof patterns, failed approaches, project conventions, and user preferences…
benchflow-ai/skillsbench
World-class data engineering skill for building scalable data pipelines, ETL/ELT systems, real-time streaming, and data infrastructure.
benchflow-ai/skillsbench
AC branch pi-model power flow equations (P/Q and |S|) with transformer tap ratio and phase shift, matching acopf-math-model.md and MATPOWER branch fields.
benchflow-ai/skillsbench
Civilization 6 district mechanics library. An agent skill from benchflow-ai/skillsbench.
benchflow-ai/skillsbench
Build deterministic, verifiable data visualizations with D3.js (v6).
benchflow-ai/skillsbench
DC power flow analysis for power systems. An agent skill from benchflow-ai/skillsbench.
Works with
Categories
Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files. Trivy Offline Vulnerability Scanning is an agent skill from benchflow-ai/skillsbench. Use Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files.
Trivy Offline Vulnerability Scanning fits situations like: tasks that involve Vulnerability scanning.
Run `npx skills add benchflow-ai/skillsbench --skill trivy-offline-vulnerability-scanning -a claude-code`. Or copy the skill folder (tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning in benchflow-ai/skillsbench) into .claude/skills/trivy-offline-vulnerability-scanning in your project. Claude Code loads it when a task matches its description.
Run `npx skills add benchflow-ai/skillsbench --skill trivy-offline-vulnerability-scanning -a codex`. Or copy the skill folder (tasks/software-dependency-audit/environment/skills/trivy-offline-vulnerability-scanning in benchflow-ai/skillsbench) into .agents/skills/trivy-offline-vulnerability-scanning in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add benchflow-ai/skillsbench --skill trivy-offline-vulnerability-scanning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/trivy-offline-vulnerability-scanning, .gemini/skills/trivy-offline-vulnerability-scanning, .github/skills/trivy-offline-vulnerability-scanning and .opencode/skills/trivy-offline-vulnerability-scanning in your project.
Going by SKILL.md and its folder, Trivy Offline Vulnerability Scanning needs the command-line tools its instructions call (apt-get and wget). Our summary lists: Python 3.
SKILL.md names 3 domains. In commands or code: aquasecurity.github.io and avd.aquasec.com; the agent is likely to contact these when it follows the instructions. As links in the text: cve.mitre.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Trivy Offline Vulnerability Scanning is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Trivy Offline Vulnerability Scanning: DefectDojo Vulnerability Management (AgentSecOps/SecOpsAgentKit, 220 stars), Container Security (hardw00t/ai-security-arsenal, 105 stars), Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars) and Pipeline Security Gates (revfactory/harness-100, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
benchflow-ai (a GitHub organization) maintains it in benchflow-ai/skillsbench, which has 1,835 GitHub stars. The repository holds 189 skills in this directory. The repository was last updated on July 23, 2026.
Source: benchflow-ai/skillsbench on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.