Agent skill

Fix Security Issue

by hardisgroupcom in hardisgroupcom/sfdx-hardis

Handle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.).

AGPL-3.0Auto-check: notesSecurity

Install Fix Security Issue

skills CLI
$ npx skills add hardisgroupcom/sfdx-hardis --skill fix-security-issue -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hardisgroupcom/sfdx-hardis fix-security-issue --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hardisgroupcom/sfdx-hardis.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/fix-security-issue .claude/skills/fix-security-issue && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fix-security-issue
GitHub stars
401
Token cost
~1.3k tokens
SKILL.md length
650 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Handle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.).

  • Works in 7 steps: Research the CVE → Locate the vulnerable dependency → Try to upgrade → …
  • Tasks that involve Vulnerability scanning
  • SKILL.md covers Step 1 — Research the CVE, Step 2 — Locate the vulnerable…, Step 3 — Try to upgrade and Step 4 — Assess impact when…, plus 3 more sections
  • Calls uv and make; reaches avd.aquasec.com

What it does

Fix Security Issue is an agent skill from hardisgroupcom/sfdx-hardis. Handle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.). Tries to upgrade first; ignores only when safe and justified.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning and Linting and formatting. It works with Trivy, npm and Python. The repository describes itself as: French-army-knife Toolbox for Salesforce. Orchestrates base commands and assist users with interactive wizards to make much more than native Salesforce CLI + Allows you to define…. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve Vulnerability scanning
  • Tasks that involve Linting and formatting

Example prompts

  • “/fix-security-issue”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Edit, Write, Bash, WebFetch, WebSearch

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Research the CVE
  2. Locate the vulnerable dependency
  3. Try to upgrade
  4. Assess impact when upgrade is not possible
  5. Decide: block or ignore
  6. Add the exception
  7. Update CHANGELOG

What it can do on your machine

Read from SKILL.md and the folder at commit 9625b22. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Edit
    • Write
    • Bash
    • WebFetch
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • avd.aquasec.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fix Security Issue loads about 1.3k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 650 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Edit, Write, Bash, WebFetch, WebSearch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hardisgroupcom/sfdx-hardis at commit 9625b22, republished under its AGPL-3.0 licence (© hardisgroupcom). 650 words, ~1,283 tokens.

Download SKILL.mdSave it as .claude/skills/fix-security-issue/SKILL.md (or your agent's skills folder).
name
fix-security-issue
description
Handle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.). Tries to upgrade first; ignores only when safe and justified.
allowed-tools
Read, Grep, Glob, Edit, Write, Bash, WebFetch, WebSearch
argument-hint
[CVE-ID or vulnerability description]
model
sonnet

Investigate and fix the security issue $ARGUMENTS reported by trivy, osv-scanner, or another security linter.

Step 1 — Research the CVE

Browse the internet to gather full context:

  • Visit the CVE URL from the scan output (e.g. https://avd.aquasec.com/nvd/<cve-id>)
  • Check the fixed version, affected component, and attack vector
  • Understand the exploit mechanism: what input/behavior triggers the vulnerability?

Step 2 — Locate the vulnerable dependency

Find where the vulnerable package comes from:

  • Go binary (e.g. stdlib): check which linter binary embeds it — the scan output names the file (e.g. usr/bin/actionlint). Find the linter's descriptor in megalinter/descriptors/ and its pinned version.
  • Python package: check pyproject.toml, uv.lock, .config/python/dev/requirements.txt, server/requirements.txt.
  • npm package (direct): search descriptors for npm: blocks containing the package name.
  • npm package (transitive): identify the top-level npm package that brings it in, then check its upstream changelog/release notes.
  • OS package (Alpine apk): find the descriptor that installs it.

Step 3 — Try to upgrade

Check whether a fixed version is available and reachable:

  • For linter binary CVEs (Go stdlib, etc.): check if a newer release of the linter exists that was compiled with a fixed runtime. Look at GitHub releases.
  • For Python packages: update the version pin in pyproject.toml / requirements files, then run uv lock --python 3.12 to regenerate uv.lock.
  • For npm packages (direct descriptor): bump the ARG ..._VERSION= line in the descriptor, then run make megalinter-build.
  • For npm packages (transitive): upgrade the parent package to a version whose package.json lists a fixed transitive version.
  • For OS packages: bump the apk package version in the descriptor if pinned.

If an upgrade is possible and available: do it, then stop here. No ignore entry needed.

Step 4 — Assess impact when upgrade is not possible

If no fixed version exists yet (latest release is still affected), analyze whether the vulnerability is exploitable in MegaLinter's context:

Ask:

  1. How is the vulnerable code path triggered? (e.g. parsing attacker-controlled input, making network requests, running a server)
  2. Does MegaLinter invoke that code path? Linters run as static analysis tools — they read source files, they do not serve HTTP, process untrusted templates, or accept external network connections.
  3. What is the actual impact? Consider:
    • DoS / resource exhaustion → generally not exploitable in a one-shot CI linter
    • Credential theft / data exfiltration → only relevant if the linter makes outbound connections or reads secrets from env
    • Arbitrary code execution → serious; check if the attack vector reaches the linter's execution environment
Show full SKILL.md (255 more words)Show less

Step 5 — Decide: block or ignore

Stop and warn the user if:

  • The vulnerability involves credential theft, secret exposure, or supply-chain compromise
  • The attack vector is reachable (e.g. a linter that fetches remote configs or calls an external API)
  • The severity is CRITICAL and the exploit mechanism is not ruled out

Add an exception only when the CVE is genuinely not exploitable in MegaLinter's context. Acceptable reasons:

  • DoS via crafted input that the linter never receives (e.g. crypto/tls in a tool that makes no TLS calls)
  • Template/injection attack requiring untrusted user-controlled input that MegaLinter never passes
  • Server-side vulnerability in a tool used only as a CLI client
  • Debug/tooling CVE (e.g. cilium-bugtool) in a package imported only for its data types

Step 6 — Add the exception

.trivyignore (for trivy findings)

Append to the appropriate section (or create a new one):

# <linter/package>: <one-line explanation of why not exploitable in MegaLinter>
CVE-XXXX-XXXXX
osv-scanner config (for osv-scanner findings)

Check for an osv-scanner config file (e.g. .osv-scanner.toml or osv-scanner.toml) and add an ignore entry following its schema.

General rule

Always include:

  • The CVE ID
  • A comment naming the affected package and the specific reason it is not exploitable
  • A note if the ignore should be revisited (e.g. "remove when <linter> releases a version compiled with Go X.Y.Z")

Step 7 — Update CHANGELOG

Do not update CHANGELOG.md for:

  • CVE ignore entries — not user-facing
  • Linter version bumps — the auto-upgrade workflow owns Linter versions upgrades

If you made a real behavior change (e.g. a linter disabled due to a security incident, a config workaround added), add one line under Fixes in the beta section:

- Fix <linter/component>: <what changed and why, one sentence for users>

© hardisgroupcom, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/fix-security-issue of hardisgroupcom/sfdx-hardis.

Open the folder on GitHubat commit 9625b22

Compare with similar skills

Fix Security Issue next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fix Security Issue compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fix Security Issue this skillhardisgroupcom/sfdx-hardis401—~1.3kAutomated safety check: NotesAGPL-3.0
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Upgrade Java Depsnvuillam/npm-groovy-lint248—~1.9kAutomated safety check: NotesMIT
npm Supply Chain Checkmajiayu000/spellbook286—~1.5kAutomated safety check: PassMIT
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence
Tracing Transitive Vulnerabilitiesjeremylongshore/tons-of-skills-marketplace2.8k—~2.2kAutomated safety check: NotesMIT

Similar skills

  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Upgrade Java Deps

    nvuillam/npm-groovy-lint

    Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…

    248 GitHub stars~1.9k tokensUpdated 4 days ago
    SecurityAuto-check: notes
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    286 GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Tracing Transitive Vulnerabilities

    jeremylongshore/tons-of-skills-marketplace

    Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies.

    2.8k GitHub stars~2.2k tokensUpdated today
    SecurityAuto-check: notes
  • Dependency Scan

    jwynia/agent-skills

    Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.

    166 GitHub stars~1.7k tokensUpdated 7 mo ago
    SecurityAuto-check passed

More from hardisgroupcom/sfdx-hardis

All 21 skills in this repo
  • sfdx-hardis Training End-to-End Test

    hardisgroupcom/sfdx-hardis

    Walks the sfdx-hardis training course end to end as a learner would, against a real Developer Edition org and fork, fixing broken steps and screenshots that no longer match.

    401 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Promotion Branches E2E Test

    hardisgroupcom/sfdx-hardis

    Runs a full end-to-end test of sfdx-hardis promotion branches and backpromote against real Salesforce orgs and a throwaway repository, then writes a report.

    401 GitHub stars~5.5k tokensUpdated today
    Auto-check: notes
  • sfdx-hardis Architecture Guide

    hardisgroupcom/sfdx-hardis

    Explains how the sfdx-hardis Salesforce CLI plugin is built: its TypeScript and Oclif stack, command layout, agent-mode flag and provider classes for git, notifications and AI.

    401 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Changelog Style Rules

    hardisgroupcom/sfdx-hardis

    Style rules for adding CHANGELOG.md entries: short, user-facing bullets grouped by command under the beta section, each linking the command's docs page.

    401 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Documentation

    hardisgroupcom/sfdx-hardis

    Documentation standards for sfdx-hardis commands (description format with Command Behavior and Technical explanations sections, MkDocs site, build:doc).

    401 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Fix Jscpd

    hardisgroupcom/sfdx-hardis

    Decision framework for fixing jscpd (copy-paste detector) errors.

    401 GitHub stars~613 tokensUpdated today
    Auto-check passed

Works with

Questions about Fix Security Issue

What does Fix Security Issue do?

Handle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.). Fix Security Issue is an agent skill from hardisgroupcom/sfdx-hardis.).

When should I use Fix Security Issue?

Fix Security Issue fits situations like: tasks that involve Vulnerability scanning; tasks that involve Linting and formatting.

How do I install Fix Security Issue in Claude Code?

Run `npx skills add hardisgroupcom/sfdx-hardis --skill fix-security-issue -a claude-code`. Or copy the skill folder (.claude/skills/fix-security-issue in hardisgroupcom/sfdx-hardis) into .claude/skills/fix-security-issue in your project. Claude Code loads it when a task matches its description.

How do I install Fix Security Issue in Codex?

Run `npx skills add hardisgroupcom/sfdx-hardis --skill fix-security-issue -a codex`. Or copy the skill folder (.claude/skills/fix-security-issue in hardisgroupcom/sfdx-hardis) into .agents/skills/fix-security-issue in your project. Codex loads it when a task matches its description.

Can I use Fix Security Issue in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hardisgroupcom/sfdx-hardis --skill fix-security-issue -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fix-security-issue, .gemini/skills/fix-security-issue, .github/skills/fix-security-issue and .opencode/skills/fix-security-issue in your project.

What does Fix Security Issue need to run?

Going by SKILL.md and its folder, Fix Security Issue needs the command-line tools its instructions call (uv and make). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Grep, Glob, Edit, Write, Bash, WebFetch, WebSearch.

Does Fix Security Issue access the network?

SKILL.md names 1 domain. In commands or code: avd.aquasec.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Fix Security Issue safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Fix Security Issue use?

Fix Security Issue is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fix Security Issue use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fix Security Issue?

Skills that share tags, products or a category with Fix Security Issue: Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Upgrade Java Deps (nvuillam/npm-groovy-lint, 248 stars), npm Supply Chain Check (majiayu000/spellbook, 286 stars) and Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fix Security Issue?

hardisgroupcom (a GitHub organization) maintains it in hardisgroupcom/sfdx-hardis, which has 401 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 8, 2026.

Source: hardisgroupcom/sfdx-hardis on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.