Official agent skill

Fix Image Cves

by kubernetes-sigs in kubernetes-sigs/cloud-provider-azure

Scan a built container image with Trivy, classify fixable Go-module and base-image CVEs, apply dependency and Dockerfile fixes, and verify the result with file checks and an optional image rescan.

OfficialApache-2.0Auto-check passedSecurity

Install Fix Image Cves

skills CLI
$ npx skills add kubernetes-sigs/cloud-provider-azure --skill fix-image-cves -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kubernetes-sigs/cloud-provider-azure fix-image-cves --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kubernetes-sigs/cloud-provider-azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/fix-image-cves .claude/skills/fix-image-cves && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fix-image-cves
GitHub stars
294
Token cost
~818 tokens
SKILL.md length
316 words
Files
3 (incl. scripts)
Skills in repo
12
Repo updated
First seen
Licence
Apache-2.0

At a glance

Scan a built container image with Trivy, classify fixable Go-module and base-image CVEs, apply dependency and Dockerfile fixes, and verify the result with file checks and an optional image rescan.

  • Works in 6 steps: Scan the built image, specifying the… → Review the plan before changing files… → Preview and apply. Append one → …
  • The user wants to fix CVEs in a container image
  • SKILL.md covers Workflow and Failures and Reporting
  • Runs Python scripts from its folder; calls python3

What it does

Fix Image Cves is an agent skill from kubernetes-sigs/cloud-provider-azure, published by the product's own GitHub organization. Scan a built container image with Trivy, classify fixable Go-module and base-image CVEs, apply dependency and Dockerfile fixes, and verify the result with file checks and an optional image rescan. Use when the user wants to fix CVEs in a container image, scan for vulnerabilities, or mentions Trivy, CVE remediation, image security, or dependency vulnerabilities.

Its SKILL.md is about 820 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts (for example `scripts/fix_image_cves.py` and `scripts/test_fix_image_cves.py`).

It sits in Security, covering Vulnerability scanning and Containers. It works with Docker, Kubernetes and Trivy. The repository describes itself as: Cloud provider for Azure. The licence is Apache-2.0.

When your agent uses it

  • The user wants to fix CVEs in a container image
  • Scan for vulnerabilities
  • CVE remediation
  • Dependency vulnerabilities

Example prompts

  • “/fix-image-cves”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Scan the built image, specifying the owning module and runtime Dockerfile,
  2. Review the plan before changing files and choose any required image targets
  3. Preview and apply. Append one
  4. Verify the source changes
  5. Rebuild the image outside this helper, then rescan that rebuilt image
  6. Record results before starting another scan. Clean up after success or an

What it can do on your machine

Read from SKILL.md and the folder at commit 0201852. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fix Image Cves loads about 818 tokens when it runs. Until then it costs about 95 tokens; SKILL.md has 316 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~818

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from kubernetes-sigs/cloud-provider-azure at commit 0201852, republished under its Apache-2.0 licence (© kubernetes-sigs). 316 words, ~818 tokens.

Download SKILL.mdSave it as .claude/skills/fix-image-cves/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
fix-image-cves
description
Scan a built container image with Trivy, classify fixable Go-module and base-image CVEs, apply dependency and Dockerfile fixes, and verify the result with file checks and an optional image rescan. Use when the user wants to fix CVEs in a container image, scan for vulnerabilities, or mentions Trivy, CVE remediation, image security, or dependency vulnerabilities.

Fix Image CVEs

Use scripts/fix_image_cves.py for dependency selection, source updates, and verification. The helper implements the lowest-fixed-version policy and manages module, vendor, and license updates; it does not build or push images.

Run from the repository root, replacing <SKILL_DIR> with this skill directory. When running elsewhere, add --repo <worktree> to each command.

Workflow

  1. Scan the built image, specifying the owning module and runtime Dockerfile, then inspect the plan:

    bash
    python3 <SKILL_DIR>/scripts/fix_image_cves.py scan <image> \
      --module-root <module-dir> --dockerfile <Dockerfile>
    python3 <SKILL_DIR>/scripts/fix_image_cves.py plan
  2. Review the plan before changing files and choose any required image targets:

    • Select a locally installed Go version satisfying the repository and planned Go directives; do not rely on automatic toolchain downloads.
    • For a Go directive bump, update older builders for every affected Dockerfile to a stable Go version at least as new as the target. Preserve the builder's registry, repository, and OS variant. Include both Dockerfile:builder and cloud-node-manager.Dockerfile:builder when the root module needs new builders.
    • For runtime CVEs, select a fixed base image. Verify target-platform support and the actual digest for every image target; these are agent decisions.
  3. Preview and apply. Append one --base-image-target <Dockerfile>:<stage>=<image>@sha256:<digest> per chosen target to both commands; use builder or runtime for the stage. Omit the option when no image change is needed.

    bash
    python3 <SKILL_DIR>/scripts/fix_image_cves.py apply --dry-run
    python3 <SKILL_DIR>/scripts/fix_image_cves.py apply
  4. Verify the source changes:

    bash
    python3 <SKILL_DIR>/scripts/fix_image_cves.py verify
  5. Rebuild the image outside this helper, then rescan that rebuilt image:

    bash
    python3 <SKILL_DIR>/scripts/fix_image_cves.py verify \
      --rescan --image <rebuilt-image>
  6. Record results before starting another scan. Clean up after success or an intentional workflow reset:

    bash
    python3 <SKILL_DIR>/scripts/fix_image_cves.py clean
Show full SKILL.md (84 more words)Show less

Failures and Reporting

  • If the helper stops, preserve its evidence and any partial changes, report the cause, and resolve it before retrying. Do not edit saved state to bypass checks.
  • Report Go toolchain findings (stdlib/toolchain) and findings without a fixed version as residual risks; the helper does not auto-fix them. Unsupported fixable findings require manual remediation and must not be reported as clean.
  • Distinguish file checks from rebuilt-image verification. A rescan verifies the planned CVEs, not that the entire image is free of vulnerabilities.

© kubernetes-sigs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in .agents/skills/fix-image-cves of kubernetes-sigs/cloud-provider-azure.

  • SKILL.md
  • scripts/fix_image_cves.py
  • scripts/test_fix_image_cves.py

Open the folder on GitHubat commit 0201852

Compare with similar skills

Fix Image Cves next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fix Image Cves compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fix Image Cves this skillkubernetes-sigs/cloud-provider-azure294—~818Automated safety check: PassApache-2.0
Container Securityhardw00t/ai-security-arsenal104—~2.8kAutomated safety check: PassNone
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Scanning Kubernetes Manifests With Kubesecmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
Cyberowlaikarimhabush/cyberowl263—~2.5kAutomated safety check: PassMIT

Similar skills

  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    104 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Scanning Kubernetes Manifests With Kubesec

    mukul975/Anthropic-Cybersecurity-Skills

    Scores Kubernetes resource manifests with Kubesec to flag misconfiguration and privilege-escalation risk before deployment, mapping each finding back to the securityContext change that fixes it.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated today
    SecurityAuto-check passed
  • Container Security Hardening

    sickn33/agentic-awesome-skills

    Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

    47k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes

More from kubernetes-sigs/cloud-provider-azure

All 12 skills in this repo
  • Run E2E Test

    kubernetes-sigs/cloud-provider-azure

    Official

    Parse a Go e2e test from tests/e2e/, translate each step to kubectl and az CLI commands, and interactively replay the test against a live cluster.

    294 GitHub stars~3.8k tokensUpdated today
    Auto-check passed
  • Build Images

    kubernetes-sigs/cloud-provider-azure

    Official

    Build cloud-provider-azure container images through the repo Makefile with explicit IMAGETAG and IMAGEREGISTRY inputs, optional make flag overrides, and opt-in bounded Docker or Podman retries.

    294 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Cherry Pick PR

    kubernetes-sigs/cloud-provider-azure

    Official

    Cherry-pick a merged pull request onto a release branch with Prow-style branch naming, manual conflict resolution, targeted validation, and GitHub PR creation.

    294 GitHub stars~636 tokensUpdated today
    Auto-check passed
  • Create Release Note Doc PR

    kubernetes-sigs/cloud-provider-azure

    Official

    Generate or update the documentation-site release note for a given tag, commit it on a branch, push it to a writable remote, and open a GitHub PR to the docs branch.

    294 GitHub stars~768 tokensUpdated today
    Auto-check passed
  • Create Release Tags

    kubernetes-sigs/cloud-provider-azure

    Official

    Create and optionally push the next Kubernetes-style release tag (vX.Y.Z) from a release-X.Y branch by resolving the remote branch tip, computing the next patch tag, and tagging the commit directly…

    294 GitHub stars~574 tokensUpdated today
    Auto-check passed
  • Cve Remediator V2

    kubernetes-sigs/cloud-provider-azure

    Official

    Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the…

    294 GitHub stars~2.5k tokensUpdated today
    Auto-check passed

Categories

Questions about Fix Image Cves

What does Fix Image Cves do?

Scan a built container image with Trivy, classify fixable Go-module and base-image CVEs, apply dependency and Dockerfile fixes, and verify the result with file checks and an optional image rescan. Fix Image Cves is an agent skill from kubernetes-sigs/cloud-provider-azure, published by the product's own GitHub organization. Scan a built container image with Trivy, classify fixable Go-module and base-image CVEs, apply dependency and Dockerfile fixes, and verify the result with file checks and an optional image rescan.

When should I use Fix Image Cves?

Fix Image Cves fits situations like: the user wants to fix CVEs in a container image; scan for vulnerabilities; CVE remediation; dependency vulnerabilities.

How do I install Fix Image Cves in Claude Code?

Run `npx skills add kubernetes-sigs/cloud-provider-azure --skill fix-image-cves -a claude-code`. Or copy the skill folder (.agents/skills/fix-image-cves in kubernetes-sigs/cloud-provider-azure) into .claude/skills/fix-image-cves in your project. Claude Code loads it when a task matches its description.

How do I install Fix Image Cves in Codex?

Run `npx skills add kubernetes-sigs/cloud-provider-azure --skill fix-image-cves -a codex`. Or copy the skill folder (.agents/skills/fix-image-cves in kubernetes-sigs/cloud-provider-azure) into .agents/skills/fix-image-cves in your project. Codex loads it when a task matches its description.

Can I use Fix Image Cves in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kubernetes-sigs/cloud-provider-azure --skill fix-image-cves -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fix-image-cves, .gemini/skills/fix-image-cves, .github/skills/fix-image-cves and .opencode/skills/fix-image-cves in your project.

What does Fix Image Cves need to run?

Going by SKILL.md and its folder, Fix Image Cves needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Fix Image Cves access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Fix Image Cves safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Fix Image Cves use?

Fix Image Cves is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fix Image Cves use?

About 818 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fix Image Cves?

Skills that share tags, products or a category with Fix Image Cves: Container Security (hardw00t/ai-security-arsenal, 104 stars), Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars), Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Scanning Kubernetes Manifests With Kubesec (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fix Image Cves?

kubernetes-sigs (a GitHub organization, an official publisher) maintains it in kubernetes-sigs/cloud-provider-azure, which has 294 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 9, 2026.

Source: kubernetes-sigs/cloud-provider-azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.