Agent skill

Triage Coverity

by netdata in netdata/netdata

Inspect or review Coverity Scan defects and saved CID bundles; fetch live findings or apply verified triage decisions when requested.

GPL-3.0Auto-check passedDevOps & Cloud

Install Triage Coverity

skills CLI
$ npx skills add netdata/netdata --skill triage-coverity -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install netdata/netdata triage-coverity --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/triage-coverity .claude/skills/triage-coverity && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
triage-coverity
GitHub stars
81k
Token cost
~1.4k tokens
SKILL.md length
648 words
Files
12 (incl. scripts)
Skills in repo
27
Repo updated
First seen
Licence
GPL-3.0

At a glance

Inspect or review Coverity Scan defects and saved CID bundles; fetch live findings or apply verified triage decisions when requested.

  • Coverity triage helpers
  • SKILL.md covers Pick The Task, Local Evidence, Apply Decisions and Maintaining This Skill
  • Runs Shell and Python scripts from its folder; calls bash and python3
  • Not general scan-build

What it does

Triage Coverity is an agent skill from netdata/netdata. Inspect or review Coverity Scan defects and saved CID bundles; fetch live findings or apply verified triage decisions when requested. Use for Coverity triage helpers, not general scan-build or CI setup.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including scripts (for example `operations.md`, `review.md` and `scripts/_lib.sh`).

It sits in DevOps & Cloud. The repository describes itself as: The fastest path to AI-powered full stack observability, even for lean teams. The licence is GPL-3.0.

When your agent uses it

  • Coverity triage helpers
  • Not general scan-build

Example prompts

  • “/triage-coverity”

Requirements

  • Python 3
  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit 2c378f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 9 files in scripts/ (Shell and Python), which the agent can run.

    Shell commands in SKILL.md call:

    • bash
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Triage Coverity loads about 1.4k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 648 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from netdata/netdata at commit 2c378f0, republished under its GPL-3.0 licence (© netdata). 648 words, ~1,416 tokens.

Download SKILL.mdSave it as .claude/skills/triage-coverity/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.
name
triage-coverity
description
Inspect or review Coverity Scan defects and saved CID bundles; fetch live findings or apply verified triage decisions when requested. Use for Coverity triage helpers, not general scan-build or CI setup.

Coverity Scan Triage

Review defects against current source and use the shipped helpers for the project's unofficial browser JSON API. Commands run from the repository root; references starting with ./ are relative to this skill directory.

Pick The Task

TaskLoad
Review saved defects or explain a CID./review.md; current source and the saved bundle
Prepare a local review bundleLocal Evidence below and ./scripts/prepare-defect.sh
Fetch live tables or defect details./operations.md#session-setup and ./operations.md#fetch-and-resolve
Apply verified classificationsApply Decisions below, ./review.md#verdicts and ./operations.md
Change or review a helperThe helper, its callers and ./scripts/_lib.sh; relevant reference sections

Authorization follows AGENTS.md#when-a-sow-is-required; review scope and evidence follow AGENTS.md#review. A request to inspect or review does not authorize remote triage updates or source fixes. Reuse authorization already provided for the current scope. Loading this skill MUST NOT start live authentication, keepalive or remote updates.

Use the requested CID set and review approach. Ask only for material missing scope or model preferences; do not ask again for decisions already made. A local bundle or source review needs neither cookies nor a keepalive. A small batch SHOULD use a proportionate review. The skill does not prescribe a model pipeline: manual, single-model and multiple-model reviews remain valid under project policy and the user's chosen tools. For an authorized multiple-model review, idea generation, source analysis and independent verification MAY be separate roles.

Local Evidence

Use .local/audits/coverity/ for this workflow. Helpers detect the repository root through Git; fetch helpers also accept explicit output paths. Keep each defect's notes, reports, proposed comment, fix draft and validation evidence under triage/<scope>/cid-<N>/, rather than at the repository root.

The local bundler reads raw/<scope>-all.json and details/<scope>/cid-<N>.json (with a legacy details/cid-<N>.json fallback). Set coverity_cid to the requested positive CID and coverity_scope to its local scope name, such as outstanding:

bash
bash .agents/skills/triage-coverity/scripts/prepare-defect.sh \
  "${coverity_cid:?set the CID}" "${coverity_scope:?set the local scope}"

It creates defect-summary.json (table row), defect-details.json (trace/checker/CWE data), source-context.c (roughly 150 lines around the main event), and TODO.md (notes). Existing files are retained; --force MAY regenerate these outputs when replacement is intended. Scope defaults to outstanding when omitted from this helper. Coverity's displayFile and main-event line are hints: inspect the current function when refactoring has moved it.

Show full SKILL.md (297 more words)Show less

Apply Decisions

Use ./review.md#verdicts to choose a supported verdict and record the CID, source evidence and intended attributes. Before an authorized update, confirm the configured project and current defect/classification. For other local scope names (dismissed, fixed, unclassified, etc.), the finalize helper warns and still posts; it does not verify that the old classification disagrees or that the update is authorized.

Set coverity_verdict and coverity_comment_file from the verified decision. Comments MUST be ASCII: use -- and straight quotes. The update helper rejects non-ASCII before posting; the historical WAF observations are in ./operations.md#diagnose-failures.

bash
bash .agents/skills/triage-coverity/scripts/finalize-defect.sh \
  "${coverity_cid:?set the CID}" "${coverity_verdict:?set the verified verdict}" \
  "${coverity_scope:?set the local scope}" "${coverity_comment_file:?set the comment file}"

A confirmed bug defaults to Bug / Fix Required. The optional fifth argument is a fix commit SHA; supply it only when evidence establishes that the fix was submitted. A merely local commit is not submission evidence. For true-bug verdicts, this argument selects Fix Submitted and appends Fix commit: <sha> to the comment. The helper trusts the caller's reference; it does not check submission or whether the fix addresses the CID.

False-positive and cosmetic verdicts keep their Ignore action. CODE_GONE and NEEDS_HUMAN print a skip message and exit without authentication or an update. The attribute enum, JSON value types and low-level explicit-attribute interface belong to ./scripts/update-triage.sh; verdict/action and impact/severity mapping belong to ./scripts/finalize-defect.sh. Follow ./operations.md#update-details for severity inputs and response verification.

Maintaining This Skill

Run python3 .agents/skills/triage-coverity/scripts/test_finalize.py for isolated verdict-to-payload checks. It needs Python 3, Bash, Git and jq; real helper code runs in a disposable repository with synthetic settings and a fake curl. No live account is used. Shell helpers also need a bash -n check when changed.

Operational discovery capture follows AGENTS.md#knowledge-capture. Preserve useful view/endpoint behavior, session and WAF failure clues, analyzer-model exceptions and attribute mappings in the relevant reference or helper owner. Separate local client guarantees from observations that need confirmation against the current service.

© netdata, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 11 other files (scripts) in .agents/skills/triage-coverity of netdata/netdata.

  • SKILL.md
  • operations.md
  • review.md
  • scripts/_lib.sh
  • scripts/fetch-details.sh
  • scripts/fetch-table.sh
  • scripts/finalize-defect.sh
  • scripts/keepalive.sh
  • scripts/prepare-defect.sh
  • scripts/resolve-cid-to-diid.sh
  • scripts/test_finalize.py
  • scripts/update-triage.sh

Open the folder on GitHubat commit 2c378f0

Compare with similar skills

Triage Coverity next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Triage Coverity compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Triage Coverity this skillnetdata/netdata81k—~1.4kAutomated safety check: PassGPL-3.0
Monitor CInrwl/nx29k6 repos~4.7kAutomated safety check: PassMIT
Terraform and OpenTofu Guideagentscope-ai/QwenPaw35k6 repos~4.2kAutomated safety check: PassApache-2.0
Vercel Optimize Auditvercel-labs/agent-skills32k9 repos~4.3kAutomated safety check: PassNone
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence

Similar skills

  • Monitor CI

    nrwl/nx

    Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.

    29k GitHub starsUsed in 6 repos~4.7k tokens
    DevOps & CloudAuto-check passed
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    35k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 9 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub starsUsed in 1 repo~3.1k tokens
    DevOps & CloudAuto-check passed

More from netdata/netdata

All 27 skills in this repo
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Repo Mirror Sources

    netdata/netdata

    Inspect Netdata-org source checkouts under NETDATAREPOSDIR, or set up and synchronize that mirror when requested.

    81k GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • Triage Agent Events

    netdata/netdata

    Investigate Netdata crashes, panics and fatals from agent-events captures or authorized fleet queries.

    81k GitHub stars~2.4k tokensUpdated today
    Auto-check: notes
  • Triage Codacy

    netdata/netdata

    Inspect, analyze, troubleshoot, or review Codacy findings and local analyzer/API helpers.

    81k GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • Triage Sonarqube

    netdata/netdata

    Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.

    81k GitHub stars~2.8k tokensUpdated today
    Auto-check: notes
  • Create, review or validate Netdata Prometheus chart profiles, exporter dashboard design, collection policy and stock semantic proofs.

    81k GitHub stars~4.7k tokensUpdated today
    Auto-check passed

Categories

Questions about Triage Coverity

What does Triage Coverity do?

Inspect or review Coverity Scan defects and saved CID bundles; fetch live findings or apply verified triage decisions when requested. Triage Coverity is an agent skill from netdata/netdata. Inspect or review Coverity Scan defects and saved CID bundles; fetch live findings or apply verified triage decisions when requested.

When should I use Triage Coverity?

Triage Coverity fits situations like: coverity triage helpers; not general scan-build.

How do I install Triage Coverity in Claude Code?

Run `npx skills add netdata/netdata --skill triage-coverity -a claude-code`. Or copy the skill folder (.agents/skills/triage-coverity in netdata/netdata) into .claude/skills/triage-coverity in your project. Claude Code loads it when a task matches its description.

How do I install Triage Coverity in Codex?

Run `npx skills add netdata/netdata --skill triage-coverity -a codex`. Or copy the skill folder (.agents/skills/triage-coverity in netdata/netdata) into .agents/skills/triage-coverity in your project. Codex loads it when a task matches its description.

Can I use Triage Coverity in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add netdata/netdata --skill triage-coverity -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/triage-coverity, .gemini/skills/triage-coverity, .github/skills/triage-coverity and .opencode/skills/triage-coverity in your project.

What does Triage Coverity need to run?

Going by SKILL.md and its folder, Triage Coverity needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (bash and python3). Our summary lists: Python 3; A Bash shell.

Does Triage Coverity access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Triage Coverity safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Triage Coverity use?

Triage Coverity is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Triage Coverity use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Triage Coverity?

Skills that share tags, products or a category with Triage Coverity: Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 35k stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Openclaw Live Updater (openclaw/openclaw, 392k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Triage Coverity?

netdata (a GitHub organization) maintains it in netdata/netdata, which has 80,838 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 8, 2026.

Source: netdata/netdata on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.