Agent skill

Analyze Cve

by openshift-eng in openshift-eng/ai-helpers

Full Go CVE analysis workflow. An agent skill from openshift-eng/ai-helpers.

Apache-2.0Auto-check: notesSecurity

Install Analyze Cve

skills CLI
$ npx skills add openshift-eng/ai-helpers --skill analyze-cve -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openshift-eng/ai-helpers analyze-cve --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/compliance/skills/analyze-cve .claude/skills/analyze-cve && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyze-cve
GitHub stars
120
Token cost
~2k tokens
SKILL.md length
736 words
Files
2 (incl. references)
Skills in repo
118
Repo updated
First seen
Licence
Apache-2.0

At a glance

Full Go CVE analysis workflow. An agent skill from openshift-eng/ai-helpers.

  • Works in 5 steps: Autonomous Mode — the full AUTO_APPROVE… → Security — Credential Handling — rules… → Runtime Configuration —… → …
  • The user gives a CVE ID (CVE-YYYY-NNNNN)
  • SKILL.md covers Arguments, Running This Skill, Examples and Prerequisites, plus 1 more section
  • Calls go, claude and brew; reaches github.com

What it does

Analyze Cve is an agent skill from openshift-eng/ai-helpers. Full Go CVE analysis workflow. Given a CVE identifier -- supplied directly, or resolved from a Jira ticket or JQL batch -- resolves and clones the affected repository, gathers vulnerability intelligence, analyzes codebase impact with govulncheck and call-graph reachability, generates a risk report, and optionally applies a fix and opens a GitHub pull request. Use when the user gives a CVE ID (CVE-YYYY-NNNNN), a Jira ticket (--jira=), or a JQL query (--jql=) for Go CVE triage; wants call-graph proof that a…

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/implementation.md`).

It sits in Security, covering Vulnerability scanning. It works with Jira and GitHub. The repository describes itself as: Developer productivity tools for Claude Code & other AI assistants. The licence is Apache-2.0.

When your agent uses it

  • The user gives a CVE ID (CVE-YYYY-NNNNN)
  • A Jira ticket (--jira=)
  • A JQL query (--jql=) for Go CVE triage
  • Wants call-graph proof that a vulnerable function is reachable

Example prompts

  • “analyze CVE”
  • “CVE impact”
  • “is this repo affected by CVE”
  • “/analyze-cve”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Autonomous Mode — the full AUTO_APPROVE decision table (what's gated vs. what always hard-fails)
  2. Security — Credential Handling — rules that apply to every command this skill runs
  3. Runtime Configuration — AI_HELPERS_WORKSPACE, FORK_ORG
  4. Implementation — Phase 0 (setup) through Phase 6 (PR creation), including the Repo Guard and each sub-skill's input/output contract
  5. Return Value — the report format this skill produces

What it can do on your machine

Read from SKILL.md and the folder at commit a627176. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go
    • claude
    • brew
    • apt-get
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Analyze Cve loads about 2k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 206 tokens; SKILL.md has 736 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~206
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~12k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:101
    generation (`brew install graphviz` or `sudo apt-get install graphviz`)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openshift-eng/ai-helpers at commit a627176, republished under its Apache-2.0 licence (© openshift-eng). 736 words, ~2,006 tokens.

Download SKILL.mdSave it as .claude/skills/analyze-cve/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
analyze-cve
description
Full Go CVE analysis workflow. Given a CVE identifier -- supplied directly, or resolved from a Jira ticket or JQL batch -- resolves and clones the affected repository, gathers vulnerability intelligence, analyzes codebase impact with govulncheck and call-graph reachability, generates a risk report, and optionally applies a fix and opens a GitHub pull request. Use when the user gives a CVE ID (CVE-YYYY-NNNNN), a Jira ticket (--jira=), or a JQL query (--jql=) for Go CVE triage; wants call-graph proof that a vulnerable function is reachable; or wants an automated fix and PR for a Go dependency vulnerability. Triggers on: 'analyze CVE', 'CVE impact', 'is this repo affected by CVE', 'Go vulnerability analysis', 'triage this Jira CVE ticket', 'fix this CVE and open a PR', or a bare CVE-YYYY-NNNNN identifier.

analyze-cve

Performs comprehensive security vulnerability analysis for Go projects. Given a CVE identifier — supplied directly, or resolved from a Jira ticket — it resolves and clones the affected repository, gathers vulnerability intelligence, analyzes the codebase for impact, generates a risk report, optionally applies fixes, and optionally opens a GitHub pull request after a verified fix.

Explicit invocation uses the following argument syntax:

/compliance:analyze-cve <CVE-ID> [--repo=<url-or-component>] [--algo=vta|rta|cha|static] [--auto-approve=yes|no]
/compliance:analyze-cve --jira=<PROJ-NNN> [--repo=...] [--algo=...] [--auto-approve=yes|no]
/compliance:analyze-cve --jql="<JQL query>" [--repo=...] [--algo=...] [--auto-approve=yes|no]

Repository resolution works in four ways, in priority order: (1) an explicit --repo= (full URL or short image/component name), (2) in direct-CVE mode only, exactly one pre-cloned repository already present in this workspace's repos/ directory when --repo= was not passed — in Jira/JQL mode that sole candidate is instead validated against the ticket's resolved image/branch before reuse, never assumed, (3) an image name extracted from a Jira ticket's summary/labels/custom fields when --jira=/--jql= was used, or (4) an interactive prompt for the repository URL or image name. See Phase 0.7 in the implementation reference for the full resolution and cloning logic.

Designed for both interactive use and headless execution (e.g. claude --print "/compliance:analyze-cve --jira=OCPBUGS-12345 --auto-approve=yes") for scheduled/periodic runs.

Arguments

Exactly one of the following input modes is required:

  • <CVE-ID> — Direct CVE identifier (format: CVE-YYYY-NNNNN, case-insensitive). Use when you already know the CVE.
  • --jira=PROJ-NNN — Jira ticket key (e.g. --jira=OCPBUGS-12345). This skill fetches the ticket and extracts the CVE ID, affected image name, and enrichment context (CVSS, CWE, priority, workarounds) from it.
  • --jql="..." — JQL query (e.g. --jql="project = OCPBUGS AND labels = needs-cve-analysis"). Fetches a batch of matching issues, filters out any already labeled ai-cve-analyzed, and processes exactly one of the remainder per run (see Phase 0.3). Re-running the same JQL periodically works through the queue over multiple invocations.

Optional flags:

  • --repo=<url-or-component>: Repository to analyze. Accepts:
    • A full GitHub URL: --repo=https://github.com/openshift/cert-manager-operator
    • A short image/component name: --repo=cert-manager-operator-rhel9 (resolved via the image-repo-mapping skill)
    • If omitted, Phase 0.7 checks for exactly one pre-cloned repo in this workspace first, then resolves from the Jira ticket's image name (if --jira/--jql was used), then prompts the user.
  • --algo (default: vta): Call graph construction algorithm.
    • vta — Most precise, fewest false positives (recommended)
    • rta — Good balance of precision and speed
    • cha — Fast, less precise
    • static — Fastest, least precise
  • --auto-approve=yes|no (default: no): Run end-to-end without interactive approval prompts. See Autonomous Mode in the implementation reference. Intended for scheduled/headless runs.

Running This Skill

Read and follow references/implementation.md for the full phase-by-phase procedure once the arguments above are parsed — do not paraphrase or improvise it. It covers, in order:

  1. Autonomous Mode — the full AUTO_APPROVE decision table (what's gated vs. what always hard-fails)
  2. Security — Credential Handling — rules that apply to every command this skill runs
  3. Runtime Configuration — AI_HELPERS_WORKSPACE, FORK_ORG
  4. Implementation — Phase 0 (setup) through Phase 6 (PR creation), including the Repo Guard and each sub-skill's input/output contract
  5. Return Value — the report format this skill produces
Show full SKILL.md (296 more words)Show less

Examples

  1. Basic CVE analysis against an explicit repo:

    /compliance:analyze-cve CVE-2024-45338 --repo=https://github.com/openshift/cert-manager-operator
  2. With specific algorithm:

    /compliance:analyze-cve CVE-2024-45338 --repo=https://github.com/openshift/cert-manager-operator --algo=rta
  3. Starting from a Jira ticket (repo/branch resolved automatically from the ticket's image name):

    /compliance:analyze-cve --jira=OCPBUGS-12345
  4. Unattended run from a JQL queue, applying fixes and opening a PR without prompts:

    bash
    claude --print "/compliance:analyze-cve --jql=\"project = OCPBUGS AND labels = needs-cve-analysis ORDER BY created ASC\" --auto-approve=yes"

Prerequisites

All tools below are required. This skill exits with an error if any are missing.

bash
# Install all required Go tools
go install golang.org/x/vuln/cmd/govulncheck@latest
go install golang.org/x/tools/cmd/callgraph@latest
go install golang.org/x/tools/cmd/digraph@latest

# git is also required (Phase 0.7 repository cloning) — install via your OS package manager

Optional:

  • graphviz for visual call graph generation (brew install graphviz or sudo apt-get install graphviz)
  • gh (GitHub CLI, authenticated via gh auth login) for Phase 6 pull-request creation. Missing gh does not fail Phase 0 — analysis and local fixes still run; Phase 6 is skipped until it's available.
  • An Atlassian MCP server (e.g. the jira plugin's bundled Rovo MCP) or jira-cli for --jira=/--jql= input modes and posting reports back to Jira

Internet access is recommended for CVE data fetching but not required if you can provide CVE details manually.

Notes

  • Focuses on Go-specific vulnerabilities.
  • Resolves and clones the target repository automatically — via --repo=, Jira image-name mapping, or reusing a repo already cloned into .work/compliance/analyze-cve/repos/ by a previous run — see Phase 0.7. All analysis and fix-application phases run against that cloned REPO_DIR, not the directory this skill happened to be invoked from.
  • Falls back to user-provided information if internet access fails.
  • Does NOT make changes, commits, or pull requests without explicit approval — either interactive, or given once upfront via --auto-approve=yes (see Autonomous Mode).
  • Reports are saved locally (.work/compliance/analyze-cve/, gitignored) and not committed to git — see Runtime Configuration to relocate this base directory.
  • Never process or disclose embargoed CVEs — if a Jira ticket's Embargo Status is True, this skill stops immediately and outputs nothing about the ticket.

© openshift-eng, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/compliance/skills/analyze-cve of openshift-eng/ai-helpers.

  • SKILL.md
  • references/implementation.md

Open the folder on GitHubat commit a627176

Compare with similar skills

Analyze Cve next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Analyze Cve compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Analyze Cve this skillopenshift-eng/ai-helpers120—~2kAutomated safety check: NotesApache-2.0
Security AdvisoryMidnightBSD/src114—~2.2kAutomated safety check: PassCustom licence
Security Vulnerability Analysiseclipse-ankaios/ankaios125—~1.5kAutomated safety check: PassApache-2.0
Warp Vulnerability Triagewarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0
Cve Doctorgetlago/lago-front163—~2.9kAutomated safety check: PassMIT
Deal With Security Advisorypaperclipai/paperclip99k—~2kAutomated safety check: PassMIT

Similar skills

  • Security Advisory

    MidnightBSD/src

    Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING…

    114 GitHub stars~2.2k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Security Vulnerability Analysis

    eclipse-ankaios/ankaios

    Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.

    125 GitHub stars~1.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed
  • Cve Doctor

    getlago/lago-front

    Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix.

    163 GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check passed
  • Deal With Security Advisory

    paperclipai/paperclip

    Handle confidential GitHub Security Advisory response for Paperclip.

    99k GitHub stars~2k tokensUpdated today
    SecurityAuto-check passed
  • Snapshot

    boostsecurityio/poutine

    Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

    523 GitHub stars~214 tokensUpdated 2 days ago
    SecurityAuto-check passed

More from openshift-eng/ai-helpers

All 118 skills in this repo
  • Investigate CI Reliability

    openshift-eng/ai-helpers

    Find and independently validate actionable reliability defects across OpenShift release jobs and presubmits, then export portable issue handoffs.

    120 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Address Review PR

    openshift-eng/ai-helpers

    Fetch and address all PR review comments — categorize by priority, make code changes, post replies, and push.

    120 GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Categorize Activity Types

    openshift-eng/ai-helpers

    Categorize Jira issues into Red Hat Sankey Activity Type categories using MCP Jira tools.

    120 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Has Review Work

    openshift-eng/ai-helpers

    Decide whether a GitHub PR has unanswered authorized review comments or new required CI failures worth a follow-up agent.

    120 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Must Gather Analyzer

    openshift-eng/ai-helpers

    Analyze OpenShift must-gather diagnostic data including cluster operators, pods, nodes, and network components.

    120 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • Payload Autodl JSON

    openshift-eng/ai-helpers

    Schema for the autodl JSON data file produced by payload-analysis for database ingestion — you must use this skill whenever generating the autodl JSON file

    120 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Analyze Cve

What does Analyze Cve do?

Full Go CVE analysis workflow. An agent skill from openshift-eng/ai-helpers. Analyze Cve is an agent skill from openshift-eng/ai-helpers. Full Go CVE analysis workflow.

When should I use Analyze Cve?

Analyze Cve fits situations like: the user gives a CVE ID (CVE-YYYY-NNNNN); A Jira ticket (--jira=); A JQL query (--jql=) for Go CVE triage; wants call-graph proof that a vulnerable function is reachable.

How do I install Analyze Cve in Claude Code?

Run `npx skills add openshift-eng/ai-helpers --skill analyze-cve -a claude-code`. Or copy the skill folder (plugins/compliance/skills/analyze-cve in openshift-eng/ai-helpers) into .claude/skills/analyze-cve in your project. Claude Code loads it when a task matches its description.

How do I install Analyze Cve in Codex?

Run `npx skills add openshift-eng/ai-helpers --skill analyze-cve -a codex`. Or copy the skill folder (plugins/compliance/skills/analyze-cve in openshift-eng/ai-helpers) into .agents/skills/analyze-cve in your project. Codex loads it when a task matches its description.

Can I use Analyze Cve in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openshift-eng/ai-helpers --skill analyze-cve -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyze-cve, .gemini/skills/analyze-cve, .github/skills/analyze-cve and .opencode/skills/analyze-cve in your project.

What does Analyze Cve need to run?

Going by SKILL.md and its folder, Analyze Cve needs the command-line tools its instructions call (go, claude, brew, apt-get and gh).

Does Analyze Cve access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Analyze Cve safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Analyze Cve use?

Analyze Cve is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Analyze Cve use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.7k tokens, read only when the agent opens those files.

What are the alternatives to Analyze Cve?

Skills that share tags, products or a category with Analyze Cve: Security Advisory (MidnightBSD/src, 114 stars), Security Vulnerability Analysis (eclipse-ankaios/ankaios, 125 stars), Warp Vulnerability Triage (warpdotdev/warp, 65k stars) and Cve Doctor (getlago/lago-front, 163 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Analyze Cve?

openshift-eng (a GitHub organization) maintains it in openshift-eng/ai-helpers, which has 120 GitHub stars. The repository holds 118 skills in this directory. The repository was last updated on October 6, 2026.

Source: openshift-eng/ai-helpers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.