Agent skill

Security Vulnerability Analysis

by eclipse-ankaios in eclipse-ankaios/ankaios

Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.

Apache-2.0Auto-check passedSecurity

Install Security Vulnerability Analysis

skills CLI
$ npx skills add eclipse-ankaios/ankaios --skill security-vulnerability-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install eclipse-ankaios/ankaios security-vulnerability-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/eclipse-ankaios/ankaios.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/security-vulnerability-analysis .claude/skills/security-vulnerability-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-vulnerability-analysis
GitHub stars
125
Token cost
~1.5k tokens
SKILL.md length
744 words
Files
4 (incl. scripts, references)
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.

  • Works in 4 steps: Initial analysis → Safe reproduction → Recommendation, scoring, and… → …
  • Security report triage
  • SKILL.md covers Intake, Workflow and Report format
  • Runs Python scripts from its folder

What it does

Security Vulnerability Analysis is an agent skill from eclipse-ankaios/ankaios. Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs. Use for security report triage, safe reproduction, CVE recommendations, CVSS 3.1 and CVSS 4.0 scoring, CWE and CAPEC classification, embargo planning, Eclipse Foundation CVE requests, and GitHub security advisories.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/disclosure-workflow.md`, `references/scoring-and-classification.md` and `scripts/calculate_cvss.py`).

It sits in Security, covering Vulnerability scanning. It works with GitHub. The repository describes itself as: Eclipse Ankaios provides workload and container orchestration for embedded devices like automotive HPCs. The licence is Apache-2.0.

When your agent uses it

  • Security report triage
  • Safe reproduction
  • CVE recommendations
  • CVSS 3.1 and CVSS 4.0 scoring

Example prompts

  • “/security-vulnerability-analysis”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Initial analysis
  2. Safe reproduction
  3. Recommendation, scoring, and classification
  4. Coordinated resolution and disclosure

What it can do on your machine

Read from SKILL.md and the folder at commit ae46412. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Vulnerability Analysis loads about 1.5k tokens when it runs, and up to ~4.2k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 744 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from eclipse-ankaios/ankaios at commit ae46412, republished under its Apache-2.0 licence (© eclipse-ankaios). 744 words, ~1,489 tokens.

Download SKILL.mdSave it as .claude/skills/security-vulnerability-analysis/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
security-vulnerability-analysis
description
Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs. Use for security report triage, safe reproduction, CVE recommendations, CVSS 3.1 and CVSS 4.0 scoring, CWE and CAPEC classification, embargo planning, Eclipse Foundation CVE requests, and GitHub security advisories.
argument-hint
Paste the report or provide a confidential advisory URL

Security Vulnerability Analysis

Guide the user through evidence-based vulnerability triage and coordinated disclosure. Treat all non-public report details as confidential until publication.

Intake

Accept any of these inputs:

  • A report pasted with the skill invocation.
  • A concise description plus relevant logs, code, versions, and deployment assumptions.
  • A public or private security advisory URL which is opened in an internal VS code browser s.t. the agent can read the text

For a URL, use available authenticated GitHub tooling only when it already has access. A GitHub extension is optional: it can make private advisory retrieval easier, but it does not grant permission by itself. Never request credentials or tokens in chat. If the advisory cannot be accessed, ask the user to paste its description and omit unnecessary confidential or personal data.

Before analysis, establish:

  • Affected component and supported versions, including whether any affected version was released.
  • Attacker prerequisites, privileges, and reachable input surface.
  • Expected trust or isolation boundary.
  • Claimed impact and impact on assets outside the attacker's existing authority.
  • Existing mitigations, deployment defaults, and recovery behavior.
  • Whether details are public, embargoed, or of unknown disclosure status.

Do not dismiss an issue merely because one proof-of-concept input has limited impact. Distinguish that observation from nearby inputs and platform behavior that could produce the claimed impact.

Workflow

Follow the stages in order. At each stage, distinguish verified facts, reasoned conclusions, assumptions, and unknowns.

1. Initial analysis

Inspect the smallest relevant code path, configuration, release behavior, and available evidence. Identify:

  1. The untrusted input and the code that consumes it.
  2. The violated security property or trust boundary.
  3. The preconditions needed for exploitation.
  4. The direct and cross-component confidentiality, integrity, or availability impact.
  5. Whether the behavior exceeds privileges the attacker already legitimately has.
  6. Plausible variants that differ from the submitted proof of concept.
  7. A falsifiable hypothesis and the cheapest safe check that could disprove it.

Give a preliminary result of one of:

  • Likely vulnerability
  • Security hardening / defense in depth
  • Likely non-security bug
  • Insufficient evidence

Explain what evidence would change the result. This is a recommendation, not the Eclipse Foundation Security Team's final classification.

If the issue is likely non-security, stop before exploit development unless the user asks to continue. Recommend normal defect handling without disclosing confidential report details.

Show full SKILL.md (366 more words)Show less
2. Safe reproduction

If the issue remains plausibly security-related, try to reproduce it locally when the environment can be isolated and recovery is understood. Otherwise give the user exact reproduction and evidence-collection steps.

Before running a proof of concept:

  • Confirm it targets only disposable local resources and test data.
  • Avoid production, shared clusters, public CI, and third-party systems.
  • Prefer a unit test or bounded simulation over resource exhaustion, process abort, OOM, persistent crash loops, or destructive operations.
  • Record the exact build profile, target, version or commit, runtime configuration, resource limits, and attacker privilege.
  • Establish baseline process and workload state and a cleanup/recovery command.
  • Ask for explicit confirmation before a test that can exhaust host resources, terminate shared services, or disrupt unrelated workloads.

Collect evidence for both the vulnerable behavior and the security boundary impact. Re-test a patched build with the same behavior-focused check. Never place embargoed details in public logs, issues, branches, CI, or commit messages.

3. Recommendation, scoring, and classification

Use scoring and classification guidance.

Produce:

  • A CVE recommendation: request, probably request, probably not, or not enough evidence.
  • The affected released versions and fixed version, if known.
  • CVSS v3.1 base vector, metric rationale, and base score.
  • CVSS v4.0 base vector, metric rationale, and base score.
  • Primary and secondary CWE mappings with rationale and links to their canonical MITRE pages.
  • Relevant CAPEC attack patterns with rationale and links to their canonical MITRE pages, or state that no precise CAPEC mapping was found.
  • Explicit assumptions and alternative vectors where an unresolved fact changes a metric.
4. Coordinated resolution and disclosure

Use Eclipse and GitHub workflow as the source of truth for sequencing, gates, and embargo constraints. Produce a status-aware checklist showing only applicable pending steps, their prerequisites, owner if known, and the information needed to complete each one.

Report format

Return a living assessment with these sections:

  1. Confidentiality status
  2. Executive assessment
  3. Evidence and unknowns
  4. Reproduction result or plan
  5. Security boundary and impact
  6. CVE recommendation
  7. CVSS v3.1
  8. CVSS v4.0
  9. CWE and CAPEC mappings
  10. Fix and regression-test requirements
  11. Eclipse/GitHub follow-up checklist

Include vectors alongside scores. Mark preliminary outputs clearly and update them when new evidence changes the analysis.

© eclipse-ankaios, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in .github/skills/security-vulnerability-analysis of eclipse-ankaios/ankaios.

  • SKILL.md
  • references/disclosure-workflow.md
  • references/scoring-and-classification.md
  • scripts/calculate_cvss.py

Open the folder on GitHubat commit ae46412

Compare with similar skills

Security Vulnerability Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Vulnerability Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Vulnerability Analysis this skilleclipse-ankaios/ankaios125—~1.5kAutomated safety check: PassApache-2.0
Security AdvisoryMidnightBSD/src114—~2.2kAutomated safety check: PassCustom licence
Warp Vulnerability Triagewarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0
Cve Doctorgetlago/lago-front163—~2.9kAutomated safety check: PassMIT
Deal With Security Advisorypaperclipai/paperclip99k—~2kAutomated safety check: PassMIT
Snapshotboostsecurityio/poutine523—~214Automated safety check: PassApache-2.0

Similar skills

  • Security Advisory

    MidnightBSD/src

    Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING…

    114 GitHub stars~2.2k tokensUpdated today
    SecurityAuto-check passed
  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed
  • Cve Doctor

    getlago/lago-front

    Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix.

    163 GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check passed
  • Deal With Security Advisory

    paperclipai/paperclip

    Handle confidential GitHub Security Advisory response for Paperclip.

    99k GitHub stars~2k tokensUpdated today
    SecurityAuto-check passed
  • Snapshot

    boostsecurityio/poutine

    Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

    523 GitHub stars~214 tokensUpdated today
    SecurityAuto-check passed
  • Analyze Cve

    openshift-eng/ai-helpers

    Full Go CVE analysis workflow. An agent skill from openshift-eng/ai-helpers.

    120 GitHub stars~2k tokensUpdated 3 days ago
    SecurityAuto-check: notes

More from eclipse-ankaios/ankaios

  • Examples Checker

    eclipse-ankaios/ankaios

    Check Ankaios examples by building and running each example in the devcontainer and validating they work correctly.

    125 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Requirement Tracing

    eclipse-ankaios/ankaios

    Manage requirement tracing — write new or update existing requirements/design decisions, link implementations and tests to existing ones, and maintain tracing consistency.

    125 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Tutorial Checker

    eclipse-ankaios/ankaios

    Check Ankaios tutorials by executing safe documented shell steps and validating expected outputs.

    125 GitHub stars~1.8k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Security Vulnerability Analysis

What does Security Vulnerability Analysis do?

Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs. Security Vulnerability Analysis is an agent skill from eclipse-ankaios/ankaios. Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.

When should I use Security Vulnerability Analysis?

Security Vulnerability Analysis fits situations like: security report triage; safe reproduction; CVE recommendations; CVSS 3.1 and CVSS 4.0 scoring.

How do I install Security Vulnerability Analysis in Claude Code?

Run `npx skills add eclipse-ankaios/ankaios --skill security-vulnerability-analysis -a claude-code`. Or copy the skill folder (.github/skills/security-vulnerability-analysis in eclipse-ankaios/ankaios) into .claude/skills/security-vulnerability-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Security Vulnerability Analysis in Codex?

Run `npx skills add eclipse-ankaios/ankaios --skill security-vulnerability-analysis -a codex`. Or copy the skill folder (.github/skills/security-vulnerability-analysis in eclipse-ankaios/ankaios) into .agents/skills/security-vulnerability-analysis in your project. Codex loads it when a task matches its description.

Can I use Security Vulnerability Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add eclipse-ankaios/ankaios --skill security-vulnerability-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-vulnerability-analysis, .gemini/skills/security-vulnerability-analysis, .github/skills/security-vulnerability-analysis and .opencode/skills/security-vulnerability-analysis in your project.

What does Security Vulnerability Analysis need to run?

Going by SKILL.md and its folder, Security Vulnerability Analysis needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Security Vulnerability Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Vulnerability Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Vulnerability Analysis use?

Security Vulnerability Analysis is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Vulnerability Analysis use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.

What are the alternatives to Security Vulnerability Analysis?

Skills that share tags, products or a category with Security Vulnerability Analysis: Security Advisory (MidnightBSD/src, 114 stars), Warp Vulnerability Triage (warpdotdev/warp, 65k stars), Cve Doctor (getlago/lago-front, 163 stars) and Deal With Security Advisory (paperclipai/paperclip, 99k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Vulnerability Analysis?

eclipse-ankaios (a GitHub organization) maintains it in eclipse-ankaios/ankaios, which has 125 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 9, 2026.

Source: eclipse-ankaios/ankaios on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.