Golang Pkg Go Dev
context-labs/whip
Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities.
Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the…
$ npx skills add kubernetes-sigs/cloud-provider-azure --skill cve-remediator-v2 -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kubernetes-sigs/cloud-provider-azure cve-remediator-v2 --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kubernetes-sigs/cloud-provider-azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/cve-remediator-v2 .claude/skills/cve-remediator-v2 && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cve-remediator-v2" agent skill from https://github.com/kubernetes-sigs/cloud-provider-azure/tree/master/.agents/skills/cve-remediator-v2 into .claude/skills/cve-remediator-v2/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cve-remediator-v2", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kubernetes-sigs/cloud-provider-azure/tree/master/.agents/skills/cve-remediator-v2Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kubernetes-sigs/cloud-provider-azure --skill cve-remediator-v2 -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kubernetes-sigs/cloud-provider-azure cve-remediator-v2 --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kubernetes-sigs/cloud-provider-azure.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/cve-remediator-v2 .agents/skills/cve-remediator-v2 && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cve-remediator-v2" agent skill from https://github.com/kubernetes-sigs/cloud-provider-azure/tree/master/.agents/skills/cve-remediator-v2 into .agents/skills/cve-remediator-v2/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cve-remediator-v2", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kubernetes-sigs/cloud-provider-azure --skill cve-remediator-v2 -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kubernetes-sigs/cloud-provider-azure cve-remediator-v2 --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kubernetes-sigs/cloud-provider-azure.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/cve-remediator-v2 .cursor/skills/cve-remediator-v2 && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cve-remediator-v2" agent skill from https://github.com/kubernetes-sigs/cloud-provider-azure/tree/master/.agents/skills/cve-remediator-v2 into .cursor/skills/cve-remediator-v2/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cve-remediator-v2", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kubernetes-sigs/cloud-provider-azure.git --path .agents/skills/cve-remediator-v2--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kubernetes-sigs/cloud-provider-azure --skill cve-remediator-v2 -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kubernetes-sigs/cloud-provider-azure cve-remediator-v2 --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kubernetes-sigs/cloud-provider-azure.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/cve-remediator-v2 .gemini/skills/cve-remediator-v2 && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cve-remediator-v2" agent skill from https://github.com/kubernetes-sigs/cloud-provider-azure/tree/master/.agents/skills/cve-remediator-v2 into .gemini/skills/cve-remediator-v2/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cve-remediator-v2", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kubernetes-sigs/cloud-provider-azure cve-remediator-v2Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kubernetes-sigs/cloud-provider-azure --skill cve-remediator-v2 -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kubernetes-sigs/cloud-provider-azure.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/cve-remediator-v2 .github/skills/cve-remediator-v2 && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cve-remediator-v2" agent skill from https://github.com/kubernetes-sigs/cloud-provider-azure/tree/master/.agents/skills/cve-remediator-v2 into .github/skills/cve-remediator-v2/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cve-remediator-v2", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kubernetes-sigs/cloud-provider-azure --skill cve-remediator-v2 -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kubernetes-sigs/cloud-provider-azure cve-remediator-v2 --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kubernetes-sigs/cloud-provider-azure.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/cve-remediator-v2 .opencode/skills/cve-remediator-v2 && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cve-remediator-v2" agent skill from https://github.com/kubernetes-sigs/cloud-provider-azure/tree/master/.agents/skills/cve-remediator-v2 into .opencode/skills/cve-remediator-v2/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cve-remediator-v2", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cve-remediator-v2Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the…
Cve Remediator V2 is an agent skill from kubernetes-sigs/cloud-provider-azure, published by the product's own GitHub organization. Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the given checks, and publish a PR, all enforced by one script. Use when the user gives vulnerability findings (a table, list, prose or records) naming the affected component or dependency, the CVE/GO ID and the fixed version, and wants source-only Go dependency bumps without building or scanning images.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `scripts/cve_remediator_v2.py`, `scripts/license_refresh_tidy.py` and `scripts/test_cve_remediator_v2.py`).
It sits in Security, covering Vulnerability scanning. It works with Go and Kubernetes. The repository describes itself as: Cloud provider for Azure. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 0201852. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 5 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3makegoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cve Remediator V2 loads about 2.5k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 1,262 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from kubernetes-sigs/cloud-provider-azure at commit 0201852, republished under its Apache-2.0 licence (© kubernetes-sigs). 1,262 words, ~2,547 tokens.
.claude/skills/cve-remediator-v2/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.scripts/cve_remediator_v2.py generates, audits and validates the change and,
with --publish, commits, pushes, and opens or updates the PR in one run. It
enforces the scope, source identity, branch, PR and readback rules itself. It
never fetches advisories, scans images, installs tools, rolls back or retries.
Use fix-image-cves for images. Replace <SKILL_DIR> with this skill directory.
--publish. Use --local-only or
--dry-run only for local-only, no-push, read-only or preview requests.make -B). Never all-root go test or live e2e.LICENSES/ snapshots. A
refresh is needed when planned bumps add vendored module paths or change
license files not covered by existing snapshots; then set licenses.needed
to true with licenses.refresh argv ["python3", "<SKILL_DIR>/scripts/license_refresh_tidy.py", "--", "make", "update-vendor-licenses"] and cwd ".". The repo command downloads
upstream Kubernetes scripts, so it needs network. The wrapper then removes
only the go.mod checksum records the generator adds to root go.sum, and
fails without tidying on any other change outside LICENSES/.
If the user excluded licenses or network, or the command is unavailable, ask
before generating; use a licenses gap only if the user accepts one. Never
refresh for preview or read-only requests..github/PULL_REQUEST_TEMPLATE.md and
pull request guidance. The runtime adds
the release tag to the title and writes the description and reviewer notes
(see Inputs).The F, V, P and body files live outside the checkout, and the checkout must be
clean. The selected Go (--go) runs generation and the sync, and its directory
is first on PATH, so a bare go in checks uses it. For --local-only and
--publish it must be an executable named go (a symlink is fine), new enough
for every tracked go directive and every target. --dry-run accepts any name.
Findings (F) is JSON you prepare from the user's findings; the user need not supply it. Read the input by meaning, not by layout or column names. Each finding should give a vulnerability ID, what is affected, and a fixed version.
.; HPP is health-probe-proxy.
Confirm that any other component maps to a tracked root, or ask. Keep each
row's own fixed version, and keep different dependencies that share an ID as
separate rows.package is the affected Go dependency, never the product. A label such as
"component" may name either; decide by meaning. If the dependency is not
given, identify it from the supplied details, the checkout or a reliable
reference, and ask if it is still unclear. Never guess it from the ID or
version. Set module only when the exact module path is known.fixed is the supplied fixed version or comma-separated list, unchanged;
never choose among candidates yourself. Use N/A only when the finding says
there is no fixed version; if it is missing or unclear, ask.id is an opaque label. installed is the scanned version. It is required
(exact semver) when fixed lists several versions; otherwise provenance
only, "" if not given.The helper performs no CVE or advisory lookups. A single fixed version is
the row's floor. For a list, it picks the lowest version newer than
installed. Per root and module the highest row floor wins and is checked
against the resolved checkout. A list blocks if installed is missing or
invalid or no listed version is newer. Every listed version must be an exact
Go semver of the module's major version.
{"findings": [
{"id": "CVE-2026-81870", "package": "go.opentelemetry.io/otel/sdk", "installed": "v1.44.0", "fixed": "1.45.0"},
{"id": "GO-2026-5932", "package": "golang.org/x/crypto", "installed": "", "fixed": "N/A"}
]}module_root defaults to .; set it for any other root.
Validation (V):
{"checks": [
{"name": "ccm-build", "group": "build", "argv": ["make", "-B", "bin/azure-cloud-controller-manager"], "cwd": "."},
{"name": "root-unit", "group": "unit", "argv": ["make", "test-unit"], "cwd": "."}],
"gaps": [],
"licenses": {"needed": false, "refresh": null}}build and unit each need at least one check, or a gap instead
({"group": "unit", "reason": "..."}), never both. If a refresh is needed,
give "refresh": {"argv": [...], "cwd": "."} or a licenses gap. A refresh
may change only LICENSES/.
Publish (P):
{"host": "github.com", "base_repo": "kubernetes-sigs/cloud-provider-azure", "base_remote": "upstream",
"base": "master", "head_repo": "<you>/cloud-provider-azure", "remote": "origin",
"head": "cve-fix-otel", "title": "chore: bump otel for CVE-2026-81870", "body_file": "/tmp/pr-body.md"}The head must be a dedicated branch, and remote URLs must match exactly, with no ports. A fork head must be a personal, direct fork of the base with the same repository name.
Give title without a release tag. For a release-X.Y base the runtime
publishes [release-X.Y] <title>, for example
[release-1.33] chore: bump otel for CVE-2026-81870; a leading tag that already
names the base is not repeated. A leading [release-...] tag that does not name
the base branch, a repeated tag, or a tag-only title blocks the run.
The body file must keep each #### heading of the checkout's
.github/PULL_REQUEST_TEMPLATE.md exactly once; without that template the run
cannot publish. Fill the kind, issue, release-note and other required sections.
The runtime replaces everything under "What this PR does / why we need it:"
with a fixed intro and one line per proved fix (see Report), for example:
Raises Go dependencies in the source module graphs to at least the reported fixed versions:
- CVE-2026-81870: go.opentelemetry.io/otel/sdk v1.45.0A fix in a root other than . ends with the root, such as
(health-probe-proxy). "Special notes for your reviewer:" gets only the
Unresolved: (residual and pruned rows) and Not run (accepted): (gap
groups and reasons) lists that apply, or stays empty. Check names, argv,
logs and other diagnostics stay in the local report.
python3 <SKILL_DIR>/scripts/cve_remediator_v2.py --repo <checkout> --findings F.json [--go <go>] --dry-run
python3 <SKILL_DIR>/scripts/cve_remediator_v2.py --repo <checkout> --findings F.json [--go <go>] --validation V.json --local-only
python3 <SKILL_DIR>/scripts/cve_remediator_v2.py --repo <checkout> --findings F.json [--go <go>] --validation V.json --publish P.json --gh <absolute-gh>dry-run, validated, no-change or publishedblocked, before any source change (ref fetches and Go caches may
still have changed)failed; stage and remaining_state say where it failed and
what was left behindraised and satisfied mean the floor is met. residual and
pruned stay unresolved.publication.pr as soon as it is found or created, and
verified becomes true only after readback passes; readback also checks the
exact title, and the body ignoring CRLF and trailing whitespace.
publication.title and publication.fixes record the published title and
the proved fixes.raised or satisfied row is listed only if its own
floor is newly met: its baseline is below the floor and selected_after
meets it. A row already met at the baseline is not listed, even when another
row's higher floor lifted the module. The baseline is selected_before; when
the checkout already has PR-range commits (for example on a rerun), it is the
merge-base graphs, which the selected Go lists from copies of the merge
base's committed go.mod and go.sum files outside the checkout (Go may
download module metadata into its cache). A missing root or module, or a
replaced module, proves nothing.range, before any commit or push and keeping the
generated changes, when no fix is proved or the merge-base graphs cannot be
listed safely: for example an untidy go.mod, a go.mod or go.sum that is
not a regular file, or a directory replacement outside the copied layout. A
genuine no-change run still exits 0.© kubernetes-sigs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts) in .agents/skills/cve-remediator-v2 of kubernetes-sigs/cloud-provider-azure.
Open the folder on GitHubat commit 0201852
Cve Remediator V2 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cve Remediator V2 this skillkubernetes-sigs/cloud-provider-azure | 294 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | |
| Golang Pkg Go Devcontext-labs/whip | 1.1k | 2 repos | ~3k | Automated safety check: Pass | MIT | |
| Cyberowlaikarimhabush/cyberowl | 263 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Docsboostsecurityio/poutine | 523 | — | ~336 | Automated safety check: Pass | Apache-2.0 | |
| Snapshotboostsecurityio/poutine | 523 | — | ~214 | Automated safety check: Pass | Apache-2.0 | |
| Update Vulndbboostsecurityio/poutine | 523 | — | ~173 | Automated safety check: Pass | Apache-2.0 |
context-labs/whip
Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities.
karimhabush/cyberowl
Check if recent cybersecurity alerts from 10 international CERTs affect your current project.
boostsecurityio/poutine
Update project documentation when features are added or changed.
boostsecurityio/poutine
Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.
boostsecurityio/poutine
Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository.
ghostsecurity/skills
Ghost Security - Software Composition Analysis (SCA) scanner.
kubernetes-sigs/cloud-provider-azure
Parse a Go e2e test from tests/e2e/, translate each step to kubectl and az CLI commands, and interactively replay the test against a live cluster.
kubernetes-sigs/cloud-provider-azure
Build cloud-provider-azure container images through the repo Makefile with explicit IMAGETAG and IMAGEREGISTRY inputs, optional make flag overrides, and opt-in bounded Docker or Podman retries.
kubernetes-sigs/cloud-provider-azure
Cherry-pick a merged pull request onto a release branch with Prow-style branch naming, manual conflict resolution, targeted validation, and GitHub PR creation.
kubernetes-sigs/cloud-provider-azure
Generate or update the documentation-site release note for a given tag, commit it on a branch, push it to a writable remote, and open a GitHub PR to the docs branch.
kubernetes-sigs/cloud-provider-azure
Create and optionally push the next Kubernetes-style release tag (vX.Y.Z) from a release-X.Y branch by resolving the remote branch tip, computing the next patch tag, and tagging the commit directly…
kubernetes-sigs/cloud-provider-azure
Fetch and analyze Prow e2e pipeline failures for cloud-provider-azure.
Works with
Categories
Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the…. Cve Remediator V2 is an agent skill from kubernetes-sigs/cloud-provider-azure, published by the product's own GitHub organization.sum and root vendor/, audit the source module graphs, run the given checks, and publish a PR, all enforced by one script.
Cve Remediator V2 fits situations like: the user gives vulnerability findings (a table; records) naming the affected component; the CVE/GO ID and the fixed version; wants source-only Go dependency bumps without building.
Run `npx skills add kubernetes-sigs/cloud-provider-azure --skill cve-remediator-v2 -a claude-code`. Or copy the skill folder (.agents/skills/cve-remediator-v2 in kubernetes-sigs/cloud-provider-azure) into .claude/skills/cve-remediator-v2 in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kubernetes-sigs/cloud-provider-azure --skill cve-remediator-v2 -a codex`. Or copy the skill folder (.agents/skills/cve-remediator-v2 in kubernetes-sigs/cloud-provider-azure) into .agents/skills/cve-remediator-v2 in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kubernetes-sigs/cloud-provider-azure --skill cve-remediator-v2 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cve-remediator-v2, .gemini/skills/cve-remediator-v2, .github/skills/cve-remediator-v2 and .opencode/skills/cve-remediator-v2 in your project.
Going by SKILL.md and its folder, Cve Remediator V2 needs Python for the scripts in its folder and the command-line tools its instructions call (python3, make and go). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Cve Remediator V2 is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cve Remediator V2: Golang Pkg Go Dev (context-labs/whip, 1.1k stars), Cyberowlai (karimhabush/cyberowl, 263 stars), Docs (boostsecurityio/poutine, 523 stars) and Snapshot (boostsecurityio/poutine, 523 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kubernetes-sigs (a GitHub organization, an official publisher) maintains it in kubernetes-sigs/cloud-provider-azure, which has 294 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 9, 2026.
Source: kubernetes-sigs/cloud-provider-azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.