Sca Trivy
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
Agent skill
Integrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and…
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill scanning-containers-with-trivy-in-cicd -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills scanning-containers-with-trivy-in-cicd --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/scanning-containers-with-trivy-in-cicd .claude/skills/scanning-containers-with-trivy-in-cicd && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "scanning-containers-with-trivy-in-cicd" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/scanning-containers-with-trivy-in-cicd into .claude/skills/scanning-containers-with-trivy-in-cicd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scanning-containers-with-trivy-in-cicd", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/scanning-containers-with-trivy-in-cicdType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill scanning-containers-with-trivy-in-cicd -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills scanning-containers-with-trivy-in-cicd --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/scanning-containers-with-trivy-in-cicd .agents/skills/scanning-containers-with-trivy-in-cicd && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "scanning-containers-with-trivy-in-cicd" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/scanning-containers-with-trivy-in-cicd into .agents/skills/scanning-containers-with-trivy-in-cicd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scanning-containers-with-trivy-in-cicd", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill scanning-containers-with-trivy-in-cicd -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills scanning-containers-with-trivy-in-cicd --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/scanning-containers-with-trivy-in-cicd .cursor/skills/scanning-containers-with-trivy-in-cicd && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "scanning-containers-with-trivy-in-cicd" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/scanning-containers-with-trivy-in-cicd into .cursor/skills/scanning-containers-with-trivy-in-cicd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scanning-containers-with-trivy-in-cicd", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/scanning-containers-with-trivy-in-cicd--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill scanning-containers-with-trivy-in-cicd -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills scanning-containers-with-trivy-in-cicd --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/scanning-containers-with-trivy-in-cicd .gemini/skills/scanning-containers-with-trivy-in-cicd && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "scanning-containers-with-trivy-in-cicd" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/scanning-containers-with-trivy-in-cicd into .gemini/skills/scanning-containers-with-trivy-in-cicd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scanning-containers-with-trivy-in-cicd", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills scanning-containers-with-trivy-in-cicdInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill scanning-containers-with-trivy-in-cicd -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/scanning-containers-with-trivy-in-cicd .github/skills/scanning-containers-with-trivy-in-cicd && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "scanning-containers-with-trivy-in-cicd" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/scanning-containers-with-trivy-in-cicd into .github/skills/scanning-containers-with-trivy-in-cicd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scanning-containers-with-trivy-in-cicd", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill scanning-containers-with-trivy-in-cicd -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills scanning-containers-with-trivy-in-cicd --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/scanning-containers-with-trivy-in-cicd .opencode/skills/scanning-containers-with-trivy-in-cicd && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "scanning-containers-with-trivy-in-cicd" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/scanning-containers-with-trivy-in-cicd into .opencode/skills/scanning-containers-with-trivy-in-cicd/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scanning-containers-with-trivy-in-cicd", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
scanning-containers-with-trivy-in-cicdIntegrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and…
Scanning Containers With Trivy In Cicd is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Integrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and to enforce severity-based quality gates that block vulnerable images from being deployed. Use when building Docker images in CI/CD and needing automated vulnerability scanning and pass/fail gates before registry push or production deployment.
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).
It sits in DevOps & Cloud, covering CI/CD, Containers and Vulnerability scanning. It works with Trivy, Docker and Git. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
trivyFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Scanning Containers With Trivy In Cicd loads about 2.7k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 120 tokens; SKILL.md has 609 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 609 words, ~2,696 tokens.
.claude/skills/scanning-containers-with-trivy-in-cicd/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.Do not use for runtime container security monitoring (use Falco), for scanning running containers in production (use runtime agents), or when only scanning application source code without containerization (use SAST tools).
Set up a GitHub Actions workflow that builds a Docker image and scans it with Trivy before pushing to a container registry.
# .github/workflows/container-security.yml
name: Container Security Scan
on:
push:
branches: [main]
pull_request:
branches: [main]
paths:
- 'Dockerfile'
- 'docker-compose*.yml'
- 'src/**'
- 'requirements*.txt'
- 'package*.json'
jobs:
build-and-scan:
runs-on: ubuntu-latest
permissions:
security-events: write
contents: read
steps:
- uses: actions/checkout@v4
- name: Build Docker image
run: docker build -t app:${{ github.sha }} .
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@0.28.0
with:
image-ref: 'app:${{ github.sha }}'
format: 'sarif'
output: 'trivy-results.sarif'
severity: 'CRITICAL,HIGH'
exit-code: '1'
ignore-unfixed: true
- name: Upload Trivy scan results
uses: github/codeql-action/upload-sarif@v3
if: always()
with:
sarif_file: 'trivy-results.sarif'
category: 'trivy-container'
- name: Run Trivy misconfiguration scanner
uses: aquasecurity/trivy-action@0.28.0
with:
scan-type: 'config'
scan-ref: '.'
format: 'table'
exit-code: '1'
severity: 'CRITICAL,HIGH'Trivy detects common Dockerfile security issues such as running as root, using latest tags, and exposing unnecessary ports.
# Scan Dockerfile for misconfigurations
trivy config --severity HIGH,CRITICAL ./Dockerfile
# Scan with custom policy directory
trivy config --policy ./security-policies --severity MEDIUM,HIGH,CRITICAL .
# Example secure Dockerfile practices Trivy checks for:
# - USER instruction present (not running as root)
# - HEALTHCHECK instruction defined
# - Base image uses specific tag, not :latest
# - No secrets in ENV or ARG instructions
# - COPY preferred over ADD# .gitlab-ci.yml
stages:
- build
- scan
- push
variables:
TRIVY_CACHE_DIR: .trivycache/
build:
stage: build
script:
- docker build -t $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA .
- docker save $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA -o image.tar
artifacts:
paths:
- image.tar
trivy-scan:
stage: scan
image:
name: aquasec/trivy:latest
entrypoint: [""]
cache:
paths:
- .trivycache/
script:
- trivy image
--input image.tar
--exit-code 1
--severity CRITICAL,HIGH
--ignore-unfixed
--format json
--output trivy-report.json
- trivy image
--input image.tar
--severity CRITICAL,HIGH,MEDIUM
--format table
artifacts:
reports:
container_scanning: trivy-report.json
paths:
- trivy-report.json
allow_failure: false
push:
stage: push
needs: [trivy-scan]
script:
- docker load -i image.tar
- docker push $CI_REGISTRY_IMAGE:$CI_COMMIT_SHAManage false positives and accepted risks through Trivy's ignore file and VEX statements.
# .trivyignore.yaml
vulnerabilities:
- id: CVE-2023-44487 # HTTP/2 rapid reset - mitigated at load balancer
statement: "Mitigated by WAF rate limiting at ingress layer"
expires: 2026-06-01
- id: CVE-2024-21626 # runc container escape - patched in base image update
statement: "Tracked in JIRA-SEC-1234, base image update scheduled"
expires: 2026-03-15
misconfigurations:
- id: DS002 # User not set - required for init containers
paths:
- "docker/init-container/Dockerfile"
statement: "Init container requires root for volume permission setup"Cache the Trivy vulnerability database in CI/CD to reduce scan times and enable air-gapped environments.
# GitHub Actions with database caching
- name: Cache Trivy DB
uses: actions/cache@v4
with:
path: /tmp/trivy-db
key: trivy-db-${{ hashFiles('.github/workflows/container-security.yml') }}
restore-keys: trivy-db-
- name: Run Trivy with cached DB
uses: aquasecurity/trivy-action@0.28.0
with:
image-ref: 'app:${{ github.sha }}'
cache-dir: /tmp/trivy-db
format: 'json'
output: 'trivy-results.json'
severity: 'CRITICAL,HIGH'
exit-code: '1'# Air-gapped: Download DB manually and mount
trivy image --download-db-only --cache-dir /path/to/cache
# Transfer cache to air-gapped system
trivy image --skip-db-update --cache-dir /path/to/cache myimage:tagUse Trivy to generate Software Bill of Materials alongside vulnerability scanning.
# Generate SBOM in CycloneDX format
trivy image --format cyclonedx --output sbom.cdx.json app:latest
# Generate SBOM in SPDX format
trivy image --format spdx-json --output sbom.spdx.json app:latest
# Scan SBOM for vulnerabilities (decouple generation from scanning)
trivy sbom sbom.cdx.json --severity CRITICAL,HIGH
# Scan with license detection
trivy image --scanners vuln,license --severity HIGH,CRITICAL app:latest| Term | Definition |
|---|---|
| CVE | Common Vulnerabilities and Exposures — standardized identifiers for publicly known security vulnerabilities |
| Vulnerability DB | Trivy's regularly updated database aggregating CVE data from NVD, vendor advisories, and language-specific sources |
| Misconfiguration | Security-relevant configuration issue in Dockerfiles, Kubernetes manifests, or IaC templates |
| SBOM | Software Bill of Materials — complete inventory of all components and dependencies in a container image |
| Ignore Unfixed | Flag to skip CVEs without available patches, reducing noise from vulnerabilities with no actionable fix |
| VEX | Vulnerability Exploitability eXchange — machine-readable statements about whether a vulnerability is exploitable in context |
| Exit Code | Non-zero return code from Trivy when findings exceed the severity threshold, used to fail CI/CD pipelines |
Context: A team builds multi-stage Docker images and needs to scan the final production image before pushing to ECR, while also scanning the build stage for supply chain risks.
Approach:
--target production for the final stage--severity CRITICAL,HIGH --exit-code 1 --ignore-unfixed to block on exploitable issuesPitfalls: Scanning only the final stage misses vulnerable packages that were present in build stages and may have influenced the build. Run trivy fs on the build context separately. Caching the Trivy DB too aggressively (weekly) means newly published CVEs take days to appear in scans.
Trivy Container Scan Report
=============================
Image: app:a1b2c3d4
Base Image: python:3.12-slim-bookworm
Scan Date: 2026-02-23
DB Version: 2026-02-23T00:15:00Z
VULNERABILITY SUMMARY:
Total: 47
Critical: 2
High: 5
Medium: 18
Low: 22
Unfixed: 8 (excluded from gate)
CRITICAL FINDINGS:
CVE-2025-12345 libssl3 3.0.11-1 3.0.13-1 OpenSSL buffer overflow
CVE-2025-67890 curl 7.88.1-10 7.88.1-12 curl HSTS bypass
HIGH FINDINGS:
CVE-2025-11111 zlib1g 1.2.13 1.2.13.1 zlib heap buffer overflow
CVE-2025-22222 python3.12 3.12.1 3.12.3 CPython path traversal
CVE-2025-33333 requests 2.31.0 2.32.0 requests SSRF in redirects
MISCONFIGURATION:
DS002 [HIGH] Dockerfile: USER instruction not set (running as root)
DS026 [MEDIUM] Dockerfile: No HEALTHCHECK defined
QUALITY GATE: FAILED (2 Critical, 5 High findings)© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (scripts, references, assets) in skills/scanning-containers-with-trivy-in-cicd of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Scanning Containers With Trivy In Cicd next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Scanning Containers With Trivy In Cicd this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Sca TrivyAgentSecOps/SecOpsAgentKit | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Custom licence | |
| DefectDojo Vulnerability ManagementAgentSecOps/SecOpsAgentKit | 220 | — | ~2.3k | Automated safety check: Pass | Custom licence | |
| Infrastructure Setuppavel-molyanov/molyanov-ai-dev | 297 | — | ~1.9k | Automated safety check: Notes | MIT | |
| Container Scanning with GrypeAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~2.5k | Automated safety check: Pass | Custom licence | |
| DockerEliasOulkadi/shokunin | 114 | — | ~3.8k | Automated safety check: Notes | MIT |
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
AgentSecOps/SecOpsAgentKit
Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.
pavel-molyanov/molyanov-ai-dev
Provides project infrastructure conventions and review criteria for local setup, Docker, Git hooks, CI/CD, service delivery, release artifacts, monitoring, backups, and operations.
AgentSecOps/SecOpsAgentKit
Scans container images, filesystems and SBOMs with Grype for known vulnerabilities, ranks them by CVSS, EPSS and CISA KEV, and wires scans into CI/CD thresholds.
EliasOulkadi/shokunin
Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and…
gotempsh/temps
Deploy applications to the Temps platform with automatic framework detection, Dockerfile generation, and container orchestration.
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Categories
Integrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and…. Scanning Containers With Trivy In Cicd is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Integrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and to enforce severity-based quality gates that block vulnerable images from being deployed.
Scanning Containers With Trivy In Cicd fits situations like: building Docker images in CI/CD and needing automated vulnerability scanning and pass/fail gates before registry push; production deployment.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill scanning-containers-with-trivy-in-cicd -a claude-code`. Or copy the skill folder (skills/scanning-containers-with-trivy-in-cicd in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/scanning-containers-with-trivy-in-cicd in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill scanning-containers-with-trivy-in-cicd -a codex`. Or copy the skill folder (skills/scanning-containers-with-trivy-in-cicd in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/scanning-containers-with-trivy-in-cicd in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill scanning-containers-with-trivy-in-cicd -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/scanning-containers-with-trivy-in-cicd, .gemini/skills/scanning-containers-with-trivy-in-cicd, .github/skills/scanning-containers-with-trivy-in-cicd and .opencode/skills/scanning-containers-with-trivy-in-cicd in your project.
Going by SKILL.md and its folder, Scanning Containers With Trivy In Cicd needs Python for the scripts in its folder and the command-line tools its instructions call (trivy). Our summary lists: Python 3; Docker.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Scanning Containers With Trivy In Cicd is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Scanning Containers With Trivy In Cicd: Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars), DefectDojo Vulnerability Management (AgentSecOps/SecOpsAgentKit, 220 stars), Infrastructure Setup (pavel-molyanov/molyanov-ai-dev, 297 stars) and Container Scanning with Grype (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.