Official agent skill

Cve Remediator V2

by kubernetes-sigs in kubernetes-sigs/cloud-provider-azure

Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the…

OfficialApache-2.0Auto-check passedSecurity

Install Cve Remediator V2

skills CLI
$ npx skills add kubernetes-sigs/cloud-provider-azure --skill cve-remediator-v2 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kubernetes-sigs/cloud-provider-azure cve-remediator-v2 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kubernetes-sigs/cloud-provider-azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/cve-remediator-v2 .claude/skills/cve-remediator-v2 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cve-remediator-v2
GitHub stars
294
Token cost
~2.5k tokens
SKILL.md length
1,262 words
Files
6 (incl. scripts)
Skills in repo
12
Repo updated
First seen
Licence
Apache-2.0

At a glance

Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the…

  • The user gives vulnerability findings (a table
  • SKILL.md covers Your decisions, Inputs, Run and Report
  • Runs Python scripts from its folder; calls python3, make and go
  • Records) naming the affected component

What it does

Cve Remediator V2 is an agent skill from kubernetes-sigs/cloud-provider-azure, published by the product's own GitHub organization. Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the given checks, and publish a PR, all enforced by one script. Use when the user gives vulnerability findings (a table, list, prose or records) naming the affected component or dependency, the CVE/GO ID and the fixed version, and wants source-only Go dependency bumps without building or scanning images.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `scripts/cve_remediator_v2.py`, `scripts/license_refresh_tidy.py` and `scripts/test_cve_remediator_v2.py`).

It sits in Security, covering Vulnerability scanning. It works with Go and Kubernetes. The repository describes itself as: Cloud provider for Azure. The licence is Apache-2.0.

When your agent uses it

  • The user gives vulnerability findings (a table
  • Records) naming the affected component
  • The CVE/GO ID and the fixed version
  • Wants source-only Go dependency bumps without building

Example prompts

  • “/cve-remediator-v2”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 0201852. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 5 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • make
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cve Remediator V2 loads about 2.5k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 1,262 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from kubernetes-sigs/cloud-provider-azure at commit 0201852, republished under its Apache-2.0 licence (© kubernetes-sigs). 1,262 words, ~2,547 tokens.

Download SKILL.mdSave it as .claude/skills/cve-remediator-v2/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
cve-remediator-v2
description
Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the given checks, and publish a PR, all enforced by one script. Use when the user gives vulnerability findings (a table, list, prose or records) naming the affected component or dependency, the CVE/GO ID and the fixed version, and wants source-only Go dependency bumps without building or scanning images.

CVE Remediator v2 (source-only)

scripts/cve_remediator_v2.py generates, audits and validates the change and, with --publish, commits, pushes, and opens or updates the PR in one run. It enforces the scope, source identity, branch, PR and readback rules itself. It never fetches advisories, scans images, installs tools, rolls back or retries. Use fix-image-cves for images. Replace <SKILL_DIR> with this skill directory.

Your decisions

  • Scope: keep only findings that apply to the chosen checkout's Linux components and releases, whatever the input layout. Never infer branches from image tags. If the scope is unclear or nothing applies, ask.
  • Mode: ordinary remediation uses --publish. Use --local-only or --dry-run only for local-only, no-push, read-only or preview requests.
  • Checks: real build and unit test commands for the affected roots that actually rebuild (for example make -B). Never all-root go test or live e2e.
  • Gaps: only for checks the caller accepted as not run, never for a failed check. Reasons are published in the PR; keep them truthful and public-safe.
  • Licenses: ordinary remediation includes needed LICENSES/ snapshots. A refresh is needed when planned bumps add vendored module paths or change license files not covered by existing snapshots; then set licenses.needed to true with licenses.refresh argv ["python3", "<SKILL_DIR>/scripts/license_refresh_tidy.py", "--", "make", "update-vendor-licenses"] and cwd ".". The repo command downloads upstream Kubernetes scripts, so it needs network. The wrapper then removes only the go.mod checksum records the generator adds to root go.sum, and fails without tidying on any other change outside LICENSES/. If the user excluded licenses or network, or the command is unavailable, ask before generating; use a licenses gap only if the user accepts one. Never refresh for preview or read-only requests.
  • PR: explicit targets, and a truthful public title and body based on the target checkout's .github/PULL_REQUEST_TEMPLATE.md and pull request guidance. The runtime adds the release tag to the title and writes the description and reviewer notes (see Inputs).

Inputs

The F, V, P and body files live outside the checkout, and the checkout must be clean. The selected Go (--go) runs generation and the sync, and its directory is first on PATH, so a bare go in checks uses it. For --local-only and --publish it must be an executable named go (a symlink is fine), new enough for every tracked go directive and every target. --dry-run accepts any name.

Findings (F) is JSON you prepare from the user's findings; the user need not supply it. Read the input by meaning, not by layout or column names. Each finding should give a vulnerability ID, what is affected, and a fixed version.

  • Write one row per vulnerability, affected Go dependency and affected tracked root. CCM and CNM share the root module .; HPP is health-probe-proxy. Confirm that any other component maps to a tracked root, or ask. Keep each row's own fixed version, and keep different dependencies that share an ID as separate rows.
  • package is the affected Go dependency, never the product. A label such as "component" may name either; decide by meaning. If the dependency is not given, identify it from the supplied details, the checkout or a reliable reference, and ask if it is still unclear. Never guess it from the ID or version. Set module only when the exact module path is known.
  • fixed is the supplied fixed version or comma-separated list, unchanged; never choose among candidates yourself. Use N/A only when the finding says there is no fixed version; if it is missing or unclear, ask.
  • id is an opaque label. installed is the scanned version. It is required (exact semver) when fixed lists several versions; otherwise provenance only, "" if not given.

The helper performs no CVE or advisory lookups. A single fixed version is the row's floor. For a list, it picks the lowest version newer than installed. Per root and module the highest row floor wins and is checked against the resolved checkout. A list blocks if installed is missing or invalid or no listed version is newer. Every listed version must be an exact Go semver of the module's major version.

json
{"findings": [
  {"id": "CVE-2026-81870", "package": "go.opentelemetry.io/otel/sdk", "installed": "v1.44.0", "fixed": "1.45.0"},
  {"id": "GO-2026-5932", "package": "golang.org/x/crypto", "installed": "", "fixed": "N/A"}
]}

module_root defaults to .; set it for any other root.

Validation (V):

json
{"checks": [
  {"name": "ccm-build", "group": "build", "argv": ["make", "-B", "bin/azure-cloud-controller-manager"], "cwd": "."},
  {"name": "root-unit", "group": "unit", "argv": ["make", "test-unit"], "cwd": "."}],
 "gaps": [],
 "licenses": {"needed": false, "refresh": null}}

build and unit each need at least one check, or a gap instead ({"group": "unit", "reason": "..."}), never both. If a refresh is needed, give "refresh": {"argv": [...], "cwd": "."} or a licenses gap. A refresh may change only LICENSES/.

Publish (P):

json
{"host": "github.com", "base_repo": "kubernetes-sigs/cloud-provider-azure", "base_remote": "upstream",
 "base": "master", "head_repo": "<you>/cloud-provider-azure", "remote": "origin",
 "head": "cve-fix-otel", "title": "chore: bump otel for CVE-2026-81870", "body_file": "/tmp/pr-body.md"}

The head must be a dedicated branch, and remote URLs must match exactly, with no ports. A fork head must be a personal, direct fork of the base with the same repository name.

Give title without a release tag. For a release-X.Y base the runtime publishes [release-X.Y] <title>, for example [release-1.33] chore: bump otel for CVE-2026-81870; a leading tag that already names the base is not repeated. A leading [release-...] tag that does not name the base branch, a repeated tag, or a tag-only title blocks the run.

The body file must keep each #### heading of the checkout's .github/PULL_REQUEST_TEMPLATE.md exactly once; without that template the run cannot publish. Fill the kind, issue, release-note and other required sections. The runtime replaces everything under "What this PR does / why we need it:" with a fixed intro and one line per proved fix (see Report), for example:

markdown
Raises Go dependencies in the source module graphs to at least the reported fixed versions:
- CVE-2026-81870: go.opentelemetry.io/otel/sdk v1.45.0

A fix in a root other than . ends with the root, such as (health-probe-proxy). "Special notes for your reviewer:" gets only the Unresolved: (residual and pruned rows) and Not run (accepted): (gap groups and reasons) lists that apply, or stays empty. Check names, argv, logs and other diagnostics stay in the local report.

Show full SKILL.md (348 more words)Show less

Run

bash
python3 <SKILL_DIR>/scripts/cve_remediator_v2.py --repo <checkout> --findings F.json [--go <go>] --dry-run
python3 <SKILL_DIR>/scripts/cve_remediator_v2.py --repo <checkout> --findings F.json [--go <go>] --validation V.json --local-only
python3 <SKILL_DIR>/scripts/cve_remediator_v2.py --repo <checkout> --findings F.json [--go <go>] --validation V.json --publish P.json --gh <absolute-gh>

Report

  • Status and exit code:
    • exit 0: dry-run, validated, no-change or published
    • exit 2: blocked, before any source change (ref fetches and Go caches may still have changed)
    • exit 1: failed; stage and remaining_state say where it failed and what was left behind
    • Nothing is rolled back. A rerun on a clean tree repeats everything.
  • Rows: raised and satisfied mean the floor is met. residual and pruned stay unresolved.
  • PR: a new PR is ready for review; an existing PR keeps its draft or ready state and is never converted. A known PR appears in publication.pr as soon as it is found or created, and verified becomes true only after readback passes; readback also checks the exact title, and the body ignoring CRLF and trailing whitespace. publication.title and publication.fixes record the published title and the proved fixes.
  • Proved fixes: a raised or satisfied row is listed only if its own floor is newly met: its baseline is below the floor and selected_after meets it. A row already met at the baseline is not listed, even when another row's higher floor lifted the module. The baseline is selected_before; when the checkout already has PR-range commits (for example on a rerun), it is the merge-base graphs, which the selected Go lists from copies of the merge base's committed go.mod and go.sum files outside the checkout (Go may download module metadata into its cache). A missing root or module, or a replaced module, proves nothing.
  • Refusals: title and body-file problems block (exit 2) before generation. The run fails at stage range, before any commit or push and keeping the generated changes, when no fix is proved or the merge-base graphs cannot be listed safely: for example an untidy go.mod, a go.mod or go.sum that is not a regular file, or a directory replacement outside the copied layout. A genuine no-change run still exits 0.
  • What to claim: each selected minimum is met, or the module is no longer selected, in the resolved source module graphs, and the listed checks passed. Never claim CVEs are cleared or images or deployments verified.

© kubernetes-sigs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts) in .agents/skills/cve-remediator-v2 of kubernetes-sigs/cloud-provider-azure.

  • SKILL.md
  • scripts/cve_remediator_v2.py
  • scripts/license_refresh_tidy.py
  • scripts/test_cve_remediator_v2.py
  • scripts/test_license_refresh_tidy.py
  • scripts/test_publication.py

Open the folder on GitHubat commit 0201852

Compare with similar skills

Cve Remediator V2 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cve Remediator V2 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cve Remediator V2 this skillkubernetes-sigs/cloud-provider-azure294—~2.5kAutomated safety check: PassApache-2.0
Golang Pkg Go Devcontext-labs/whip1.1k2 repos~3kAutomated safety check: PassMIT
Cyberowlaikarimhabush/cyberowl263—~2.5kAutomated safety check: PassMIT
Docsboostsecurityio/poutine523—~336Automated safety check: PassApache-2.0
Snapshotboostsecurityio/poutine523—~214Automated safety check: PassApache-2.0
Update Vulndbboostsecurityio/poutine523—~173Automated safety check: PassApache-2.0

Similar skills

  • Golang Pkg Go Dev

    context-labs/whip

    Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities.

    1.1k GitHub starsUsed in 2 repos~3k tokens
    SecurityAuto-check passed
  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated today
    SecurityAuto-check passed
  • Docs

    boostsecurityio/poutine

    Update project documentation when features are added or changed.

    523 GitHub stars~336 tokensUpdated yesterday
    SecurityAuto-check passed
  • Snapshot

    boostsecurityio/poutine

    Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

    523 GitHub stars~214 tokensUpdated yesterday
    SecurityAuto-check passed
  • Update Vulndb

    boostsecurityio/poutine

    Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository.

    523 GitHub stars~173 tokensUpdated yesterday
    SecurityAuto-check passed
  • Ghost Scan Deps

    ghostsecurity/skills

    Ghost Security - Software Composition Analysis (SCA) scanner.

    409 GitHub stars~1.3k tokensUpdated 13 days ago
    SecurityAuto-check: notes

More from kubernetes-sigs/cloud-provider-azure

All 12 skills in this repo
  • Run E2E Test

    kubernetes-sigs/cloud-provider-azure

    Official

    Parse a Go e2e test from tests/e2e/, translate each step to kubectl and az CLI commands, and interactively replay the test against a live cluster.

    294 GitHub stars~3.8k tokensUpdated 2 days ago
    Auto-check passed
  • Build Images

    kubernetes-sigs/cloud-provider-azure

    Official

    Build cloud-provider-azure container images through the repo Makefile with explicit IMAGETAG and IMAGEREGISTRY inputs, optional make flag overrides, and opt-in bounded Docker or Podman retries.

    294 GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check passed
  • Cherry Pick PR

    kubernetes-sigs/cloud-provider-azure

    Official

    Cherry-pick a merged pull request onto a release branch with Prow-style branch naming, manual conflict resolution, targeted validation, and GitHub PR creation.

    294 GitHub stars~636 tokensUpdated 2 days ago
    Auto-check passed
  • Create Release Note Doc PR

    kubernetes-sigs/cloud-provider-azure

    Official

    Generate or update the documentation-site release note for a given tag, commit it on a branch, push it to a writable remote, and open a GitHub PR to the docs branch.

    294 GitHub stars~768 tokensUpdated 2 days ago
    Auto-check passed
  • Create Release Tags

    kubernetes-sigs/cloud-provider-azure

    Official

    Create and optionally push the next Kubernetes-style release tag (vX.Y.Z) from a release-X.Y branch by resolving the remote branch tip, computing the next patch tag, and tagging the commit directly…

    294 GitHub stars~574 tokensUpdated 2 days ago
    Auto-check passed
  • Debug E2E Pipeline

    kubernetes-sigs/cloud-provider-azure

    Official

    Fetch and analyze Prow e2e pipeline failures for cloud-provider-azure.

    294 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Cve Remediator V2

What does Cve Remediator V2 do?

Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the…. Cve Remediator V2 is an agent skill from kubernetes-sigs/cloud-provider-azure, published by the product's own GitHub organization.sum and root vendor/, audit the source module graphs, run the given checks, and publish a PR, all enforced by one script.

When should I use Cve Remediator V2?

Cve Remediator V2 fits situations like: the user gives vulnerability findings (a table; records) naming the affected component; the CVE/GO ID and the fixed version; wants source-only Go dependency bumps without building.

How do I install Cve Remediator V2 in Claude Code?

Run `npx skills add kubernetes-sigs/cloud-provider-azure --skill cve-remediator-v2 -a claude-code`. Or copy the skill folder (.agents/skills/cve-remediator-v2 in kubernetes-sigs/cloud-provider-azure) into .claude/skills/cve-remediator-v2 in your project. Claude Code loads it when a task matches its description.

How do I install Cve Remediator V2 in Codex?

Run `npx skills add kubernetes-sigs/cloud-provider-azure --skill cve-remediator-v2 -a codex`. Or copy the skill folder (.agents/skills/cve-remediator-v2 in kubernetes-sigs/cloud-provider-azure) into .agents/skills/cve-remediator-v2 in your project. Codex loads it when a task matches its description.

Can I use Cve Remediator V2 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kubernetes-sigs/cloud-provider-azure --skill cve-remediator-v2 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cve-remediator-v2, .gemini/skills/cve-remediator-v2, .github/skills/cve-remediator-v2 and .opencode/skills/cve-remediator-v2 in your project.

What does Cve Remediator V2 need to run?

Going by SKILL.md and its folder, Cve Remediator V2 needs Python for the scripts in its folder and the command-line tools its instructions call (python3, make and go). Our summary lists: Python 3.

Does Cve Remediator V2 access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cve Remediator V2 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Cve Remediator V2 use?

Cve Remediator V2 is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cve Remediator V2 use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cve Remediator V2?

Skills that share tags, products or a category with Cve Remediator V2: Golang Pkg Go Dev (context-labs/whip, 1.1k stars), Cyberowlai (karimhabush/cyberowl, 263 stars), Docs (boostsecurityio/poutine, 523 stars) and Snapshot (boostsecurityio/poutine, 523 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cve Remediator V2?

kubernetes-sigs (a GitHub organization, an official publisher) maintains it in kubernetes-sigs/cloud-provider-azure, which has 294 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 9, 2026.

Source: kubernetes-sigs/cloud-provider-azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.