Sca Trivy
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…
$ npx skills add nvuillam/npm-groovy-lint --skill upgrade-java-deps -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nvuillam/npm-groovy-lint upgrade-java-deps --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nvuillam/npm-groovy-lint.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/upgrade-java-deps .claude/skills/upgrade-java-deps && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "upgrade-java-deps" agent skill from https://github.com/nvuillam/npm-groovy-lint/tree/main/.claude/skills/upgrade-java-deps into .claude/skills/upgrade-java-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-java-deps", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nvuillam/npm-groovy-lint/tree/main/.claude/skills/upgrade-java-depsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nvuillam/npm-groovy-lint --skill upgrade-java-deps -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nvuillam/npm-groovy-lint upgrade-java-deps --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nvuillam/npm-groovy-lint.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/upgrade-java-deps .agents/skills/upgrade-java-deps && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "upgrade-java-deps" agent skill from https://github.com/nvuillam/npm-groovy-lint/tree/main/.claude/skills/upgrade-java-deps into .agents/skills/upgrade-java-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-java-deps", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nvuillam/npm-groovy-lint --skill upgrade-java-deps -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nvuillam/npm-groovy-lint upgrade-java-deps --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nvuillam/npm-groovy-lint.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/upgrade-java-deps .cursor/skills/upgrade-java-deps && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "upgrade-java-deps" agent skill from https://github.com/nvuillam/npm-groovy-lint/tree/main/.claude/skills/upgrade-java-deps into .cursor/skills/upgrade-java-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-java-deps", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nvuillam/npm-groovy-lint.git --path .claude/skills/upgrade-java-deps--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nvuillam/npm-groovy-lint --skill upgrade-java-deps -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nvuillam/npm-groovy-lint upgrade-java-deps --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nvuillam/npm-groovy-lint.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/upgrade-java-deps .gemini/skills/upgrade-java-deps && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "upgrade-java-deps" agent skill from https://github.com/nvuillam/npm-groovy-lint/tree/main/.claude/skills/upgrade-java-deps into .gemini/skills/upgrade-java-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-java-deps", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nvuillam/npm-groovy-lint upgrade-java-depsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nvuillam/npm-groovy-lint --skill upgrade-java-deps -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nvuillam/npm-groovy-lint.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/upgrade-java-deps .github/skills/upgrade-java-deps && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "upgrade-java-deps" agent skill from https://github.com/nvuillam/npm-groovy-lint/tree/main/.claude/skills/upgrade-java-deps into .github/skills/upgrade-java-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-java-deps", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nvuillam/npm-groovy-lint --skill upgrade-java-deps -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nvuillam/npm-groovy-lint upgrade-java-deps --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nvuillam/npm-groovy-lint.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/upgrade-java-deps .opencode/skills/upgrade-java-deps && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "upgrade-java-deps" agent skill from https://github.com/nvuillam/npm-groovy-lint/tree/main/.claude/skills/upgrade-java-deps into .opencode/skills/upgrade-java-deps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "upgrade-java-deps", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
upgrade-java-depsUpgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…
Upgrade Java Deps is an agent skill from nvuillam/npm-groovy-lint. Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify nothing regressed. Use when bumping CodeNarc, fixing a grype/trivy CVE in a bundled jar, or refreshing the Java toolchain.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Vulnerability scanning and Linting and formatting. It works with Java and Trivy. The repository describes itself as: Lint, format and auto-fix your Groovy / Jenkinsfile / Gradle files using command line. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 2080dff. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadGrepGlobEditWriteFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmnodegitjavacurlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
repo1.maven.orgapi.github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Upgrade Java Deps loads about 1.9k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 746 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, Grep, Glob, Edit, WriteAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from nvuillam/npm-groovy-lint at commit 2080dff, republished under its MIT licence (© nvuillam). 746 words, ~1,908 tokens.
.claude/skills/upgrade-java-deps/SKILL.md (or your agent's skills folder).Upgrade the Java jars bundled under lib/java/ and rebuild the CodeNarc server.
npm updatenpm-groovy-lint ships a set of committed Java jars in lib/java/ (and Groovy's own libs in lib/java/groovy/lib/). The Node CLI starts lib/java/CodeNarcServer.jar (a thin Groovy server compiled from groovy/src/main/) whose MANIFEST.MF Class-Path lists every sibling jar by exact filename. So a dependency upgrade means: swap the jar file, regenerate the manifest, recompile + repackage the server jar, and verify both run paths still work.
Security scanners in MegaLinter (grype, trivy) scan these jars, so jar CVEs surface as Mega-Linter failures even though npm audit is clean.
The jars:
lib/java/): CodeNarc-*-groovy-4.0.jar, GMetrics-Groovy4-*.jar, jackson-{core,databind,annotations}-*.jar, logback-{classic,core}-*.jar, slf4j-api-*.jar, janino-*.jar, commons-compiler-*.jar — plus logback.xml and the built CodeNarcServer.jar.lib/java/groovy/lib/): groovy-*, groovy-ant, commons-cli, ant*.The download targets and group/artifact IDs are codified in scripts/update-java-jars.js (TARGETS). Read it first — it is the source of truth for what is bundled and where.
groovyc) on PATH. Check: java -version, groovy --version. CodeNarc 3.x targets Groovy 4 (-groovy-4.0 jars), so keep the Groovy libs on the 4.x line.main.npm run dev:upgrade-jars # = node scripts/update-java-jars.js (fetches LATEST stable of every TARGET)
npm run dev:pre-commit # lint:fix + build + server:build (regenerates manifest + CodeNarcServer.jar)update-java-jars.js removes old jars and downloads the newest stable from Maven Central. Use this for a routine refresh. Caveat: it also bumps CodeNarc / GMetrics / Groovy, which can change lint output or break the server — always run the full verification below and review the result diff.
When only specific jars are flagged (e.g. by grype), replace just those so you don't accidentally bump CodeNarc/Groovy.
Find the fixed version that actually exists. grype reports a "fixed in" version, but it may be unpublished or ahead of Maven Central. Probe before committing to a version:
# HEAD-probe a specific jar (Windows curl needs --ssl-no-revoke)
probe() { curl -sS --ssl-no-revoke -m 25 -o /dev/null -w "%{http_code} $2-$3\n" \
"https://repo1.maven.org/maven2/${1//.//}/$2/$3/$2-$3.jar"; }
probe com.fasterxml.jackson.core jackson-databind 2.22.0
probe ch.qos.logback logback-core 1.5.25If the exact "fixed in" patch is unpublished, jump to the next published version whose number is above the advisory's vulnerable range (check https://api.github.com/advisories/<GHSA-ID> for the real range). Example seen in practice: GHSA fixed-in 2.21.5 (unpublished) → use 2.22.0, which is above the < 2.21.5 range.
Keep version sets consistent.
jackson-core, jackson-databind, jackson-annotations together to the same release train. Note jackson-annotations uses a minor-only version (e.g. jackson-annotations-2.22.jar, not 2.22.0) — confirm the exact artifact name with a probe.logback-classic and logback-core to the same version.Download new, delete old:
cd lib/java
curl -sS --ssl-no-revoke -O "https://repo1.maven.org/maven2/com/fasterxml/jackson/core/jackson-databind/2.22.0/jackson-databind-2.22.0.jar"
# ...repeat for each jar...
rm jackson-databind-2.19.0.jar # remove the superseded versions
unzip -l jackson-databind-2.22.0.jar >/dev/null && echo OK # sanity-check it's a valid zip
cd ../..Rebuild: npm run server:build (regenerates groovy/src/main/MANIFEST.MF Class-Path + lib/java/CodeNarcServer.jar).
--noserver) pathThere are two run paths and they fail differently:
--noserver, and several tests): Node runs java ... com.nvuillam.CodeNarcServer <args> and JSON.parses the entire stdout. Anything else on stdout breaks it ("Unable to use CodeNarc JSON result").logback prints its internal status log to stdout whenever a config WARN/ERROR occurs. Newer logback versions deprecate the condition attribute on <if> (emitting a WARN) — which dumps status onto stdout and breaks one-shot mode. Mitigations, both already applied in lib/java/logback.xml, that you must preserve when bumping logback:
<statusListener class="ch.qos.logback.core.status.NopStatusListener"/> as the first child of <configuration> to silence status output.<if condition='isDefined("...")'> attribute form. (The <condition> element form does NOT enable the appender in 1.5.x — it silently evaluates false and the FILE appender is never created, breaking the "log file creation" test.)-- (double hyphen) — it's a fatal XML parse error that itself triggers a status dump. Write "no server", not "--server".If a future logback bump changes this behavior, the canonical check is step "verify A" below (stdout must start with {).
node lib/index.js --killserver
# A) one-shot stdout must be pure JSON (no logback status, no banner)
printf 'def x=1\nprintln x\n' > /tmp/smoke.groovy
node lib/index.js --noserver /tmp/smoke.groovy # must print a clean results table, exit 0/1 (not 2)
# B) server path
node lib/index.js --killserver && node lib/index.js /tmp/smoke.groovy
# C) full suite (needs Java + Groovy; ~10-15 min)
npm run testA clean one-shot run is the key signal the jackson/logback swap is healthy. If npm test shows failures, confirm they are caused by your change before fixing: git stash push -- lib/java groovy/src/main/MANIFEST.MF, re-run the failing test on the original jars, then git stash pop. Some tests (e.g. an exec with escaped-quote rulesets like NoDef{"enabled":false}) fail only on Windows-local shell quoting and are green in CI — don't chase those.
The lint.yml "Update check" CI job runs npm run dev:pre-commit and fails if the tree isn't clean, so run it and stage all regenerated artifacts (the new jars, the deleted old jars, MANIFEST.MF, CodeNarcServer.jar, and logback.xml if touched).
npm run dev:pre-commit
git add lib/java groovy/src/main/MANIFEST.MF
git commit # use a "Fix CI:" / "chore(deps):" style messageGotcha: CodeNarcServer.jar is built deterministically, but its zlib compression is sensitive to the Node version. If "Update check" reports the jar as changed after you ran dev:pre-commit, rebuild with the same Node version CI uses (see CONTRIBUTING.md).
© nvuillam, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/upgrade-java-deps of nvuillam/npm-groovy-lint.
Open the folder on GitHubat commit 2080dff
Upgrade Java Deps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Upgrade Java Deps this skillnvuillam/npm-groovy-lint | 248 | — | ~1.9k | Automated safety check: Notes | MIT | |
| Sca TrivyAgentSecOps/SecOpsAgentKit | 219 | 2 repos | ~3.7k | Automated safety check: Pass | Custom licence | |
| Fix Security Issuehardisgroupcom/sfdx-hardis | 400 | — | ~1.3k | Automated safety check: Notes | AGPL-3.0 | |
| Code Audit3stoneBrother/code-audit | 893 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| CodeQL Security Scantrailofbits/skills | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Dep Scanepam/ai-dial-chat | 504 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 |
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
hardisgroupcom/sfdx-hardis
Handle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.).
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
epam/ai-dial-chat
Runs Trivy filesystem scan against the repo root and emits structured vulnerability findings (CVE, package, versions) in the SDLC reviewer schema.
jabrena/plinth
A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning…
nvuillam/npm-groovy-lint
Collect MegaLinter lint errors for the current repository. An agent skill from nvuillam/npm-groovy-lint.
nvuillam/npm-groovy-lint
Install or upgrade MegaLinter on a repository. An agent skill from nvuillam/npm-groovy-lint.
nvuillam/npm-groovy-lint
Entry point for everything MegaLinter. An agent skill from nvuillam/npm-groovy-lint.
nvuillam/npm-groovy-lint
Fix the errors reported by MegaLinter. An agent skill from nvuillam/npm-groovy-lint.
nvuillam/npm-groovy-lint
Watch the GitHub PR for the current branch, wait for CI to finish, and autonomously fix failing jobs by reading logs, editing sources, and pushing.
Categories
Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…. Upgrade Java Deps is an agent skill from nvuillam/npm-groovy-lint.jar, and verify nothing regressed.
Upgrade Java Deps fits situations like: bumping CodeNarc; fixing a grype/trivy CVE in a bundled jar; refreshing the Java toolchain.
Run `npx skills add nvuillam/npm-groovy-lint --skill upgrade-java-deps -a claude-code`. Or copy the skill folder (.claude/skills/upgrade-java-deps in nvuillam/npm-groovy-lint) into .claude/skills/upgrade-java-deps in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nvuillam/npm-groovy-lint --skill upgrade-java-deps -a codex`. Or copy the skill folder (.claude/skills/upgrade-java-deps in nvuillam/npm-groovy-lint) into .agents/skills/upgrade-java-deps in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nvuillam/npm-groovy-lint --skill upgrade-java-deps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/upgrade-java-deps, .gemini/skills/upgrade-java-deps, .github/skills/upgrade-java-deps and .opencode/skills/upgrade-java-deps in your project.
Going by SKILL.md and its folder, Upgrade Java Deps needs the command-line tools its instructions call (npm, node, git, java and curl). Its frontmatter pre-approves these tools: Bash, Read, Grep, Glob, Edit, Write.
SKILL.md names 2 domains. In commands or code: repo1.maven.org and api.github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Upgrade Java Deps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Upgrade Java Deps: Sca Trivy (AgentSecOps/SecOpsAgentKit, 219 stars), Fix Security Issue (hardisgroupcom/sfdx-hardis, 400 stars), Code Audit (3stoneBrother/code-audit, 893 stars) and CodeQL Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nvuillam (a GitHub user) maintains it in nvuillam/npm-groovy-lint, which has 248 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 4, 2026.
Source: nvuillam/npm-groovy-lint on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.