Official agent skill

Handle Cve

by DataDog in DataDog/dd-trace-rb

A skill your agent uses when the dependency audit goes red — .github/scripts/check/dependencyaudit.sh or the bundler-audit CI job — or when a newly published CVE/GHSA on a dependency gem blocks a PR.

OfficialCustom licenceAuto-check passedSecurity

Install Handle Cve

skills CLI
$ npx skills add DataDog/dd-trace-rb --skill handle-cve -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install DataDog/dd-trace-rb handle-cve --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/DataDog/dd-trace-rb.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/handle-cve .claude/skills/handle-cve && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
handle-cve
GitHub stars
417
Token cost
~2.6k tokens
SKILL.md length
1,376 words
Files
2
Skills in repo
4
Repo updated
First seen
Licence
Custom licence

At a glance

A skill your agent uses when the dependency audit goes red — .github/scripts/check/dependencyaudit.sh or the bundler-audit CI job — or when a newly published CVE/GHSA on a dependency gem blocks a PR.

  • Works in 5 steps: Role and priority → Identify the CVE and its blast radius → Research the CVE → …
  • The dependency audit goes red — .github/scripts/check/dependencyaudit.sh
  • SKILL.md covers 1. Role and priority, 2. Identify the CVE and its…, 3. Research the CVE and 4. Decide how to unblock, plus 2 more sections
  • Calls docker, bundle and gem; reaches github.com

What it does

Handle Cve is an agent skill from DataDog/dd-trace-rb, published by the product's own GitHub organization. Use when the dependency audit goes red — .github/scripts/check/dependencyaudit.sh or the bundler-audit CI job — or when a newly published CVE/GHSA on a dependency gem blocks a PR.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `CASE-STUDIES.md`).

It sits in Security, covering Vulnerability scanning. It works with Datadog, GitHub and Ruby. The repository describes itself as: Datadog's client library for Ruby.

When your agent uses it

  • The dependency audit goes red — .github/scripts/check/dependencyaudit.sh
  • The bundler-audit CI job —
  • A newly published CVE/GHSA on a dependency gem blocks a PR

Example prompts

  • “/handle-cve”

Requirements

  • Docker

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Role and priority
  2. Identify the CVE and its blast radius
  3. Research the CVE
  4. Decide how to unblock
  5. Validate and ship

What it can do on your machine

Read from SKILL.md and the folder at commit 10bb407. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker
    • bundle
    • gem

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Handle Cve loads about 2.6k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 1,376 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,376 words (~2,594 tokens).

“Goal: turn the red audit task green, locally. Run the audit on your machine, research the CVE, triage the impact, decide the fix, and validate before you push. CI runs the same audit later and only confirms what you already…”

— opening of SKILL.md by DataDog, Custom licence
name
handle-cve

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file in .agents/skills/handle-cve of DataDog/dd-trace-rb.

  • SKILL.md
  • CASE-STUDIES.md

Open the folder on GitHubat commit 10bb407

Compare with similar skills

Handle Cve next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Handle Cve compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Handle Cve this skillDataDog/dd-trace-rb417—~2.6kAutomated safety check: PassCustom licence
Review Dependenciestobihagemann/turbo407—~1.5kAutomated safety check: PassMIT
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
Cyberowlaikarimhabush/cyberowl263—~2.5kAutomated safety check: PassMIT
Audit Fixopenplayerjs/openplayerjs649—~1kAutomated safety check: PassMIT
Cyber NeoHainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT

Similar skills

  • Review Dependencies

    tobihagemann/turbo

    Detect package managers and CI action pins, then discover outdated or vulnerable dependencies.

    407 GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated today
    SecurityAuto-check: notes
  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated today
    SecurityAuto-check passed
  • Audit Fix

    openplayerjs/openplayerjs

    Resolve a pnpm audit (dependency-audit CI job) failure — high/critical CVEs in the dependency tree.

    649 GitHub stars~1k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    281 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Docs

    boostsecurityio/poutine

    Update project documentation when features are added or changed.

    523 GitHub stars~336 tokensUpdated yesterday
    SecurityAuto-check passed

More from DataDog/dd-trace-rb

  • Write Rbs

    DataDog/dd-trace-rb

    Official

    A skill your agent uses when writing, reviewing, or modifying RBS type signatures (sig//.rbs, vendor/rbs//.rbs, or inline : annotations) or running Steep – e.g.

    417 GitHub stars~805 tokensUpdated today
    Auto-check passed
  • Write Changelog

    DataDog/dd-trace-rb

    Official

    A skill your agent uses when a change in this repo needs a customer-facing changelog entry — e.g.

    417 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Write Comment

    DataDog/dd-trace-rb

    Official

    A skill your agent uses whenever writing or reviewing a code comment anywhere in this repo (lib, ext, spec, sig, docs, CI config, etc.) – e.g.

    417 GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Categories

Questions about Handle Cve

What does Handle Cve do?

A skill your agent uses when the dependency audit goes red — .github/scripts/check/dependencyaudit.sh or the bundler-audit CI job — or when a newly published CVE/GHSA on a dependency gem blocks a PR. Handle Cve is an agent skill from DataDog/dd-trace-rb, published by the product's own GitHub organization.sh or the bundler-audit CI job — or when a newly published CVE/GHSA on a dependency gem blocks a PR.

When should I use Handle Cve?

Handle Cve fits situations like: the dependency audit goes red — .github/scripts/check/dependencyaudit.sh; the bundler-audit CI job —; A newly published CVE/GHSA on a dependency gem blocks a PR.

How do I install Handle Cve in Claude Code?

Run `npx skills add DataDog/dd-trace-rb --skill handle-cve -a claude-code`. Or copy the skill folder (.agents/skills/handle-cve in DataDog/dd-trace-rb) into .claude/skills/handle-cve in your project. Claude Code loads it when a task matches its description.

How do I install Handle Cve in Codex?

Run `npx skills add DataDog/dd-trace-rb --skill handle-cve -a codex`. Or copy the skill folder (.agents/skills/handle-cve in DataDog/dd-trace-rb) into .agents/skills/handle-cve in your project. Codex loads it when a task matches its description.

Can I use Handle Cve in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add DataDog/dd-trace-rb --skill handle-cve -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/handle-cve, .gemini/skills/handle-cve, .github/skills/handle-cve and .opencode/skills/handle-cve in your project.

What does Handle Cve need to run?

Going by SKILL.md and its folder, Handle Cve needs the command-line tools its instructions call (docker, bundle and gem). Our summary lists: Docker.

Does Handle Cve access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Handle Cve safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Handle Cve use?

Handle Cve has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Handle Cve use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Handle Cve?

Skills that share tags, products or a category with Handle Cve: Review Dependencies (tobihagemann/turbo, 407 stars), Pyspector Security Audit (ParzivalHack/PySpector, 151 stars), Cyberowlai (karimhabush/cyberowl, 263 stars) and Audit Fix (openplayerjs/openplayerjs, 649 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Handle Cve?

DataDog (a GitHub organization, an official publisher) maintains it in DataDog/dd-trace-rb, which has 417 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 8, 2026.

Source: DataDog/dd-trace-rb on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.