Agent skill

Dep Scan

by epam in epam/ai-dial-chat

Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema.

Apache-2.0Auto-check passedSecurity

Install Dep Scan

skills CLI
$ npx skills add epam/ai-dial-chat --skill dep-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install epam/ai-dial-chat dep-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/epam/ai-dial-chat.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/dep-scan .claude/skills/dep-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dep-scan
GitHub stars
504
Token cost
~1.2k tokens
SKILL.md length
472 words
Files
1
Skills in repo
18
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema.

  • Works in 5 steps: Run Trivy → Parse the report → Map each vulnerability to a finding → …
  • An agent needs to detect known CVEs in project dependencies for downstream triage
  • SKILL.md covers Overview, When to use, Required tools and Process, plus 2 more sections
  • Calls trivy

What it does

Dep Scan is an agent skill from epam/ai-dial-chat. Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema. Use when an agent needs to detect known CVEs in project dependencies for downstream triage or human review.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning. It works with Trivy and Bash. The repository describes itself as: A default UI for AI DIAL. The licence is Apache-2.0.

When your agent uses it

  • An agent needs to detect known CVEs in project dependencies for downstream triage
  • Tasks that involve Vulnerability scanning

Example prompts

  • “/dep-scan”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Run Trivy
  2. Parse the report
  3. Map each vulnerability to a finding
  4. Set status
  5. Write stage-output.json

What it can do on your machine

Read from SKILL.md and the folder at commit 2d66a8d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • trivy

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dep Scan loads about 1.2k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 472 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from epam/ai-dial-chat at commit 2d66a8d, republished under its Apache-2.0 licence (© epam). 472 words, ~1,226 tokens.

Download SKILL.mdSave it as .claude/skills/dep-scan/SKILL.md (or your agent's skills folder).
name
dep-scan
description
Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema. Use when an agent needs to detect known CVEs in project dependencies for downstream triage or human review.
disable-model-invocation
true

Dependency Scan (Trivy)

Overview

Filesystem scan for known CVEs. Trivy autodetects lockfiles (package-lock.json, pnpm-lock.yaml, etc.) and produces a JSON report; this skill parses that report and emits findings in the SDLC reviewer shape so downstream agents (e.g., /dep-triage) and human reviewers can consume them uniformly.

This is the scan step only — no triage, no false-positive analysis. That happens downstream.

When to use

  • PR-time dependency check (chained before /dep-triage).
  • Scheduled dependency scans (nightly, weekly).
  • Any flow needing machine-readable vulnerability output that another agent or process will consume.

Required tools

  • Bash(trivy:*) — to invoke the CLI
  • Write — to produce stage-output.json (auto-granted by the platform)
  • Read, Glob — to inspect lockfiles or scan output if needed

Process

1. Run Trivy

Filesystem scan from repo root, JSON output, medium severity and above. Use Trivy's --output flag, not shell redirection (>) — Claude Code's Bash tool rejects shell-redirection operators and would deny the command:

bash
trivy fs --format json --severity HIGH,CRITICAL,MEDIUM --quiet --output /tmp/trivy.json .

Same effect: writes report to /tmp/trivy.json. No >, no |, no shell-variable expansion — exactly what Bash(trivy:*) allows.

Notes:

  • --quiet suppresses interactive UI noise.
  • If /tmp/trivy.json is missing or zero-length after the command, treat it as a scanner failure (see Heuristics).
2. Parse the report

Use the Read tool to load /tmp/trivy.json into your reasoning context. Do NOT attempt to use cat, head, tail, jq, grep, awk, or any other shell command to inspect the file — those aren't in the agent's allowed_tools (only Bash(trivy:*) is) and the Bash tool will deny them, burning turns on retries. The Read tool is the intended path for inspecting on-disk JSON.

The file is on the order of tens-to-hundreds of KB; one Read call loads it cleanly.

Trivy's structure:

{
  "Results": [
    {
      "Target": "package-lock.json",
      "Type": "npm",
      "Vulnerabilities": [
        {
          "VulnerabilityID": "CVE-...",
          "PkgName": "lodash",
          "InstalledVersion": "4.17.20",
          "FixedVersion": "4.17.21",
          "Severity": "HIGH",
          "Title": "..."
        }
      ]
    }
  ]
}

A Result may have no Vulnerabilities array if the target is clean — skip it.

Show full SKILL.md (191 more words)Show less
3. Map each vulnerability to a finding

Lowercase severity; carry through CVE, package, versions:

{
  "severity": "high",
  "file": "package-lock.json",
  "message": "<CVE>: <Title>. Affected: <pkg>@<version>. Fixed in <fixed>.",
  "suggested_fix": "Upgrade <pkg> to >=<fixed>.",
  "cve": "<CVE>",
  "package": "<pkg>",
  "installed_version": "<installed>",
  "fixed_version": "<fixed>",
  "target_type": "<npm|gomod|...>"
}

The cve, package, installed_version, fixed_version, and target_type fields are the contract for /dep-triage — don't omit them.

4. Set status
  • passed — no findings at MEDIUM+
  • passed_with_findings — findings exist but all are MEDIUM (no HIGH/CRITICAL)
  • failed — any HIGH or CRITICAL finding
5. Write stage-output.json

Use the Write tool to save at the repo root. Include payload.scan_summary so downstream consumers don't have to recount:

{
  "stage": "scan-deps",
  "status": "<above>",
  "summary": "Trivy fs: <N> findings (<H> high, <M> medium).",
  "payload": {
    "scan_summary": {
      "total": <N>,
      "by_severity": { "critical": <c>, "high": <h>, "medium": <m> },
      "scanner": "trivy fs"
    },
    "findings": [ ... ]
  }
}

Heuristics

  • Scanner failure → high-severity finding. If trivy exits non-zero or /tmp/trivy.json is empty/malformed, emit one high-severity finding with file: null and message quoting the stderr verbatim, then set status: failed. Don't silently produce empty findings.
  • Truncate verbose descriptions. Trivy's Description field can be very long; keep it brief in the message field or move detail to cve lookups elsewhere.
  • Don't filter by reachability here. That's /dep-triage's job. Emit every CVE Trivy finds at the configured severity threshold.

Output for downstream

The exact shape above is the contract for /dep-triage. The triage skill keys off cve, package, and installed_version to look up usage in the repo. Omit those fields and triage degrades to "every finding marked confirmed."

© epam, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/dep-scan of epam/ai-dial-chat.

Open the folder on GitHubat commit 2d66a8d

Compare with similar skills

Dep Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dep Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dep Scan this skillepam/ai-dial-chat504—~1.2kAutomated safety check: PassApache-2.0
Upgrade Java Depsnvuillam/npm-groovy-lint248—~1.9kAutomated safety check: NotesMIT
Fix Scan Findingmalloydata/publisher116—~5.1kAutomated safety check: PassMIT
Security Vulnerabilities Patcheraxelixlabs/axelix148—~4.2kAutomated safety check: PassLGPL-3.0
Fix Image Cveskubernetes-sigs/cloud-provider-azure294—~818Automated safety check: PassApache-2.0
Security ReviewerJeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT

Similar skills

  • Upgrade Java Deps

    nvuillam/npm-groovy-lint

    Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…

    248 GitHub stars~1.9k tokensUpdated 4 days ago
    SecurityAuto-check: notes
  • Fix Scan Finding

    malloydata/publisher

    Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…

    116 GitHub stars~5.1k tokensUpdated today
    SecurityAuto-check passed
  • Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…

    148 GitHub stars~4.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Fix Image Cves

    kubernetes-sigs/cloud-provider-azure

    Official

    Scan a built container image with Trivy, classify fixable Go-module and base-image CVEs, apply dependency and Dockerfile fixes, and verify the result with file checks and an optional image rescan.

    294 GitHub stars~818 tokensUpdated today
    SecurityAuto-check passed
  • Security Reviewer

    Jeffallan/claude-skills

    Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

    12k GitHub stars~1.3k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Security Audit

    Aedelon/claude-code-blueprint

    Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults.

    120 GitHub stars~1.6k tokensUpdated 7 mo ago
    SecurityAuto-check: notes

More from epam/ai-dial-chat

All 18 skills in this repo
  • Refactoring Audit

    epam/ai-dial-chat

    Deep codebase refactoring audit for AI DIAL Chat. An agent skill from epam/ai-dial-chat.

    504 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Read unresolved GitHub code review threads for the pull request associated with the current branch, classify each comment, and implement and verify required code fixes.

    504 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Create Ticket

    epam/ai-dial-chat

    Interactively create OR update GitHub issues (Bug, Feature, Task) for the current repository.

    504 GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • Figma

    epam/ai-dial-chat

    Design-to-code workflow for Figma designs. An agent skill from epam/ai-dial-chat.

    504 GitHub stars~997 tokensUpdated today
    Auto-check passed
  • Git Ship

    epam/ai-dial-chat

    A skill your agent uses whenever the user wants to commit, push, or ship changes in a git repository.

    504 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Responsive Design

    epam/ai-dial-chat

    Responsive (mobile + desktop) layout workflow. An agent skill from epam/ai-dial-chat.

    504 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Dep Scan

What does Dep Scan do?

Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema. Dep Scan is an agent skill from epam/ai-dial-chat. Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema.

When should I use Dep Scan?

Dep Scan fits situations like: an agent needs to detect known CVEs in project dependencies for downstream triage; tasks that involve Vulnerability scanning.

How do I install Dep Scan in Claude Code?

Run `npx skills add epam/ai-dial-chat --skill dep-scan -a claude-code`. Or copy the skill folder (.claude/skills/dep-scan in epam/ai-dial-chat) into .claude/skills/dep-scan in your project. Claude Code loads it when a task matches its description.

How do I install Dep Scan in Codex?

Run `npx skills add epam/ai-dial-chat --skill dep-scan -a codex`. Or copy the skill folder (.claude/skills/dep-scan in epam/ai-dial-chat) into .agents/skills/dep-scan in your project. Codex loads it when a task matches its description.

Can I use Dep Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add epam/ai-dial-chat --skill dep-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dep-scan, .gemini/skills/dep-scan, .github/skills/dep-scan and .opencode/skills/dep-scan in your project.

What does Dep Scan need to run?

Going by SKILL.md and its folder, Dep Scan needs the command-line tools its instructions call (trivy).

Does Dep Scan access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dep Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dep Scan use?

Dep Scan is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dep Scan use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dep Scan?

Skills that share tags, products or a category with Dep Scan: Upgrade Java Deps (nvuillam/npm-groovy-lint, 248 stars), Fix Scan Finding (malloydata/publisher, 116 stars), Security Vulnerabilities Patcher (axelixlabs/axelix, 148 stars) and Fix Image Cves (kubernetes-sigs/cloud-provider-azure, 294 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dep Scan?

epam (a GitHub organization) maintains it in epam/ai-dial-chat, which has 504 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 7, 2026.

Source: epam/ai-dial-chat on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.