Security Advisory
MidnightBSD/src
Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING…
Full Go CVE analysis workflow. An agent skill from openshift-eng/ai-helpers.
$ npx skills add openshift-eng/ai-helpers --skill analyze-cve -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install openshift-eng/ai-helpers analyze-cve --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/compliance/skills/analyze-cve .claude/skills/analyze-cve && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "analyze-cve" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/analyze-cve into .claude/skills/analyze-cve/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyze-cve", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/analyze-cveType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add openshift-eng/ai-helpers --skill analyze-cve -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install openshift-eng/ai-helpers analyze-cve --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/compliance/skills/analyze-cve .agents/skills/analyze-cve && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "analyze-cve" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/analyze-cve into .agents/skills/analyze-cve/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyze-cve", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openshift-eng/ai-helpers --skill analyze-cve -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install openshift-eng/ai-helpers analyze-cve --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/compliance/skills/analyze-cve .cursor/skills/analyze-cve && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "analyze-cve" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/analyze-cve into .cursor/skills/analyze-cve/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyze-cve", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/openshift-eng/ai-helpers.git --path plugins/compliance/skills/analyze-cve--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add openshift-eng/ai-helpers --skill analyze-cve -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install openshift-eng/ai-helpers analyze-cve --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/compliance/skills/analyze-cve .gemini/skills/analyze-cve && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "analyze-cve" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/analyze-cve into .gemini/skills/analyze-cve/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyze-cve", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install openshift-eng/ai-helpers analyze-cveInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add openshift-eng/ai-helpers --skill analyze-cve -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/compliance/skills/analyze-cve .github/skills/analyze-cve && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "analyze-cve" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/analyze-cve into .github/skills/analyze-cve/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyze-cve", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openshift-eng/ai-helpers --skill analyze-cve -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install openshift-eng/ai-helpers analyze-cve --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/compliance/skills/analyze-cve .opencode/skills/analyze-cve && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "analyze-cve" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/analyze-cve into .opencode/skills/analyze-cve/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyze-cve", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
analyze-cveFull Go CVE analysis workflow. An agent skill from openshift-eng/ai-helpers.
Analyze Cve is an agent skill from openshift-eng/ai-helpers. Full Go CVE analysis workflow. Given a CVE identifier -- supplied directly, or resolved from a Jira ticket or JQL batch -- resolves and clones the affected repository, gathers vulnerability intelligence, analyzes codebase impact with govulncheck and call-graph reachability, generates a risk report, and optionally applies a fix and opens a GitHub pull request. Use when the user gives a CVE ID (CVE-YYYY-NNNNN), a Jira ticket (--jira=), or a JQL query (--jql=) for Go CVE triage; wants call-graph proof that a…
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/implementation.md`).
It sits in Security, covering Vulnerability scanning. It works with Jira and GitHub. The repository describes itself as: Developer productivity tools for Claude Code & other AI assistants. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit a627176. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
goclaudebrewapt-getghFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Analyze Cve loads about 2k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 206 tokens; SKILL.md has 736 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
generation (`brew install graphviz` or `sudo apt-get install graphviz`)Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from openshift-eng/ai-helpers at commit a627176, republished under its Apache-2.0 licence (© openshift-eng). 736 words, ~2,006 tokens.
.claude/skills/analyze-cve/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Performs comprehensive security vulnerability analysis for Go projects. Given a CVE identifier — supplied directly, or resolved from a Jira ticket — it resolves and clones the affected repository, gathers vulnerability intelligence, analyzes the codebase for impact, generates a risk report, optionally applies fixes, and optionally opens a GitHub pull request after a verified fix.
Explicit invocation uses the following argument syntax:
/compliance:analyze-cve <CVE-ID> [--repo=<url-or-component>] [--algo=vta|rta|cha|static] [--auto-approve=yes|no]
/compliance:analyze-cve --jira=<PROJ-NNN> [--repo=...] [--algo=...] [--auto-approve=yes|no]
/compliance:analyze-cve --jql="<JQL query>" [--repo=...] [--algo=...] [--auto-approve=yes|no]Repository resolution works in four ways, in priority order: (1) an explicit --repo= (full URL or short image/component name), (2) in direct-CVE mode only, exactly one pre-cloned repository already present in this workspace's repos/ directory when --repo= was not passed — in Jira/JQL mode that sole candidate is instead validated against the ticket's resolved image/branch before reuse, never assumed, (3) an image name extracted from a Jira ticket's summary/labels/custom fields when --jira=/--jql= was used, or (4) an interactive prompt for the repository URL or image name. See Phase 0.7 in the implementation reference for the full resolution and cloning logic.
Designed for both interactive use and headless execution (e.g. claude --print "/compliance:analyze-cve --jira=OCPBUGS-12345 --auto-approve=yes") for scheduled/periodic runs.
Exactly one of the following input modes is required:
<CVE-ID> — Direct CVE identifier (format: CVE-YYYY-NNNNN, case-insensitive). Use when you already know the CVE.--jira=PROJ-NNN — Jira ticket key (e.g. --jira=OCPBUGS-12345). This skill fetches the ticket and extracts the CVE ID, affected image name, and enrichment context (CVSS, CWE, priority, workarounds) from it.--jql="..." — JQL query (e.g. --jql="project = OCPBUGS AND labels = needs-cve-analysis"). Fetches a batch of matching issues, filters out any already labeled ai-cve-analyzed, and processes exactly one of the remainder per run (see Phase 0.3). Re-running the same JQL periodically works through the queue over multiple invocations.Optional flags:
--repo=<url-or-component>: Repository to analyze. Accepts:--repo=https://github.com/openshift/cert-manager-operator--repo=cert-manager-operator-rhel9 (resolved via the image-repo-mapping skill)--jira/--jql was used), then prompts the user.--algo (default: vta): Call graph construction algorithm.vta — Most precise, fewest false positives (recommended)rta — Good balance of precision and speedcha — Fast, less precisestatic — Fastest, least precise--auto-approve=yes|no (default: no): Run end-to-end without interactive approval prompts. See Autonomous Mode in the implementation reference. Intended for scheduled/headless runs.Read and follow references/implementation.md for the full phase-by-phase procedure once the arguments above are parsed — do not paraphrase or improvise it. It covers, in order:
AUTO_APPROVE decision table (what's gated vs. what always hard-fails)AI_HELPERS_WORKSPACE, FORK_ORGBasic CVE analysis against an explicit repo:
/compliance:analyze-cve CVE-2024-45338 --repo=https://github.com/openshift/cert-manager-operatorWith specific algorithm:
/compliance:analyze-cve CVE-2024-45338 --repo=https://github.com/openshift/cert-manager-operator --algo=rtaStarting from a Jira ticket (repo/branch resolved automatically from the ticket's image name):
/compliance:analyze-cve --jira=OCPBUGS-12345Unattended run from a JQL queue, applying fixes and opening a PR without prompts:
claude --print "/compliance:analyze-cve --jql=\"project = OCPBUGS AND labels = needs-cve-analysis ORDER BY created ASC\" --auto-approve=yes"All tools below are required. This skill exits with an error if any are missing.
# Install all required Go tools
go install golang.org/x/vuln/cmd/govulncheck@latest
go install golang.org/x/tools/cmd/callgraph@latest
go install golang.org/x/tools/cmd/digraph@latest
# git is also required (Phase 0.7 repository cloning) — install via your OS package managerOptional:
graphviz for visual call graph generation (brew install graphviz or sudo apt-get install graphviz)gh (GitHub CLI, authenticated via gh auth login) for Phase 6 pull-request creation. Missing gh does not fail Phase 0 — analysis and local fixes still run; Phase 6 is skipped until it's available.jira plugin's bundled Rovo MCP) or jira-cli for --jira=/--jql= input modes and posting reports back to JiraInternet access is recommended for CVE data fetching but not required if you can provide CVE details manually.
--repo=, Jira image-name mapping, or reusing a repo already cloned into .work/compliance/analyze-cve/repos/ by a previous run — see Phase 0.7. All analysis and fix-application phases run against that cloned REPO_DIR, not the directory this skill happened to be invoked from.--auto-approve=yes (see Autonomous Mode)..work/compliance/analyze-cve/, gitignored) and not committed to git — see Runtime Configuration to relocate this base directory.True, this skill stops immediately and outputs nothing about the ticket.© openshift-eng, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in plugins/compliance/skills/analyze-cve of openshift-eng/ai-helpers.
Open the folder on GitHubat commit a627176
Analyze Cve next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Analyze Cve this skillopenshift-eng/ai-helpers | 120 | — | ~2k | Automated safety check: Notes | Apache-2.0 | |
| Security AdvisoryMidnightBSD/src | 114 | — | ~2.2k | Automated safety check: Pass | Custom licence | |
| Security Vulnerability Analysiseclipse-ankaios/ankaios | 125 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Warp Vulnerability Triagewarpdotdev/warp | 65k | 1 repos | ~2.1k | Automated safety check: Pass | AGPL-3.0 | |
| Cve Doctorgetlago/lago-front | 163 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Deal With Security Advisorypaperclipai/paperclip | 99k | — | ~2k | Automated safety check: Pass | MIT |
MidnightBSD/src
Handle a security fix end to end for MidnightBSD src - triage a FreeBSD security advisory (FreeBSD-SA-) or CVE against this tree, port the fix to master and both stable branches, add the UPDATING…
eclipse-ankaios/ankaios
Analyze potential Ankaios security vulnerabilities from pasted reports, local evidence, or advisory URLs.
warpdotdev/warp
Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.
getlago/lago-front
Triage a CVE / Dependabot alert in a JS/TS project and recommend the least-invasive fix.
paperclipai/paperclip
Handle confidential GitHub Security Advisory response for Paperclip.
boostsecurityio/poutine
Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.
openshift-eng/ai-helpers
Find and independently validate actionable reliability defects across OpenShift release jobs and presubmits, then export portable issue handoffs.
openshift-eng/ai-helpers
Fetch and address all PR review comments — categorize by priority, make code changes, post replies, and push.
openshift-eng/ai-helpers
Categorize Jira issues into Red Hat Sankey Activity Type categories using MCP Jira tools.
openshift-eng/ai-helpers
Decide whether a GitHub PR has unanswered authorized review comments or new required CI failures worth a follow-up agent.
openshift-eng/ai-helpers
Analyze OpenShift must-gather diagnostic data including cluster operators, pods, nodes, and network components.
openshift-eng/ai-helpers
Schema for the autodl JSON data file produced by payload-analysis for database ingestion — you must use this skill whenever generating the autodl JSON file
Categories
Full Go CVE analysis workflow. An agent skill from openshift-eng/ai-helpers. Analyze Cve is an agent skill from openshift-eng/ai-helpers. Full Go CVE analysis workflow.
Analyze Cve fits situations like: the user gives a CVE ID (CVE-YYYY-NNNNN); A Jira ticket (--jira=); A JQL query (--jql=) for Go CVE triage; wants call-graph proof that a vulnerable function is reachable.
Run `npx skills add openshift-eng/ai-helpers --skill analyze-cve -a claude-code`. Or copy the skill folder (plugins/compliance/skills/analyze-cve in openshift-eng/ai-helpers) into .claude/skills/analyze-cve in your project. Claude Code loads it when a task matches its description.
Run `npx skills add openshift-eng/ai-helpers --skill analyze-cve -a codex`. Or copy the skill folder (plugins/compliance/skills/analyze-cve in openshift-eng/ai-helpers) into .agents/skills/analyze-cve in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openshift-eng/ai-helpers --skill analyze-cve -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyze-cve, .gemini/skills/analyze-cve, .github/skills/analyze-cve and .opencode/skills/analyze-cve in your project.
Going by SKILL.md and its folder, Analyze Cve needs the command-line tools its instructions call (go, claude, brew, apt-get and gh).
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Analyze Cve is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Analyze Cve: Security Advisory (MidnightBSD/src, 114 stars), Security Vulnerability Analysis (eclipse-ankaios/ankaios, 125 stars), Warp Vulnerability Triage (warpdotdev/warp, 65k stars) and Cve Doctor (getlago/lago-front, 163 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
openshift-eng (a GitHub organization) maintains it in openshift-eng/ai-helpers, which has 120 GitHub stars. The repository holds 118 skills in this directory. The repository was last updated on October 6, 2026.
Source: openshift-eng/ai-helpers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.