Agent skill

Fix Cve

by openshift-eng in openshift-eng/ai-helpers

Patch a Go dependency to fix a CVE using the appropriate strategy based on Go version compatibility.

Apache-2.0Auto-check passedSecurity

Install Fix Cve

skills CLI
$ npx skills add openshift-eng/ai-helpers --skill fix-cve -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openshift-eng/ai-helpers fix-cve --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/golang/skills/fix-cve .claude/skills/fix-cve && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fix-cve
GitHub stars
120
Token cost
~2.2k tokens
SKILL.md length
1,079 words
Files
1
Skills in repo
118
Repo updated
First seen
Licence
Apache-2.0

At a glance

Patch a Go dependency to fix a CVE using the appropriate strategy based on Go version compatibility.

  • Works in 6 steps: Find all affected go.mod files → Sync vendor for each affected module… → Handle macOS toolchain issues → …
  • The user wants to fix a CVE by updating a Go module
  • SKILL.md covers Parameters, Strategy selection, Standard update workflow and Hard stops — when to STOP and…, plus 2 more sections
  • Calls go, make and git; reaches github.com

What it does

Fix Cve is an agent skill from openshift-eng/ai-helpers. Patch a Go dependency to fix a CVE using the appropriate strategy based on Go version compatibility. Use when the user wants to fix a CVE by updating a Go module, replacing it with a patched fork, or applying a security patch across all go.mod files in a Go project. Triggers on: 'patch CVE', 'fix CVE', 'replace grpc', 'update vulnerable dependency', 'security patch go module', or any mention of CVE + Go dependency replacement.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning. It works with Go and gRPC. The repository describes itself as: Developer productivity tools for Claude Code & other AI assistants. The licence is Apache-2.0.

When your agent uses it

  • The user wants to fix a CVE by updating a Go module
  • Replacing it with a patched fork
  • Applying a security patch across all go.mod files in a Go project
  • Update vulnerable dependency

Example prompts

  • “patch CVE”
  • “fix CVE”
  • “replace grpc”
  • “/fix-cve”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Find all affected go.mod files
  2. Sync vendor for each affected module (CRITICAL)
  3. Handle macOS toolchain issues
  4. Run repo checks
  5. Commit
  6. Optionally create a PR

What it can do on your machine

Read from SKILL.md and the folder at commit a627176. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go
    • make
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fix Cve loads about 2.2k tokens when it runs. Until then it costs about 110 tokens; SKILL.md has 1,079 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~110
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openshift-eng/ai-helpers at commit a627176, republished under its Apache-2.0 licence (© openshift-eng). 1,079 words, ~2,155 tokens.

Download SKILL.mdSave it as .claude/skills/fix-cve/SKILL.md (or your agent's skills folder).
name
fix-cve
description
Patch a Go dependency to fix a CVE using the appropriate strategy based on Go version compatibility. Use when the user wants to fix a CVE by updating a Go module, replacing it with a patched fork, or applying a security patch across all go.mod files in a Go project. Triggers on: 'patch CVE', 'fix CVE', 'replace grpc', 'update vulnerable dependency', 'security patch go module', or any mention of CVE + Go dependency replacement.

fix-cve

Patch a Go module dependency to fix a CVE. The skill determines the right strategy based on Go version compatibility between the project and the fix, then applies the minimum changes needed.

Parameters

  • module (required): The Go module to patch, e.g. google.golang.org/grpc
  • fix-version (required): The upstream version that contains the CVE fix, e.g. v1.75.1 — or a URL to the release/advisory with version info
  • cve (required): The CVE identifier, e.g. CVE-2026-33186
  • ticket (required): The Jira/bug ticket, e.g. OCPBUGS-83972

If any required parameter is missing, ask the user before proceeding.

Strategy selection

The fix follows one of three paths depending on Go version compatibility. Determine which path to take BEFORE making any changes.

Gather version info
  1. Read the project's Go version from the root go.mod (go directive), e.g. go 1.23.6
  2. Determine the Go version required by the CVE fix. Either:
    • Fetch the upstream fix version's go.mod to check its go directive
    • Parse it from the release page or advisory the user provided
  3. Extract the major.minor from both (e.g. 1.23 from go 1.23.6)
Path A: Direct upstream update (project Go >= fix Go)

Condition: The project's Go version is equal or higher than what the fix requires. The fix can be applied by simply updating the dependency to the upstream version that contains the patch.

Example: Project uses go 1.25.0, fix requires go 1.23.1 → direct update works.

Action: Update the module version in go.mod to the fix version (or latest patched version), then follow the standard update workflow (Step 3 onwards).

Path B: Bump Go patch version (same minor, lower patch)

Condition: The project's Go is on the same minor version as the fix but a lower patch. Bumping the patch version (Z in X.Y.Z) within go.mod is safe enough to unlock the fix.

Example: Project uses go 1.23.1, fix requires go 1.23.7 → bump to go 1.23.7 in go.mod and update the dependency.

Action: Update the go directive in go.mod to the required patch version, then update the module and follow the standard update workflow. Report the Go patch bump to the user but don't block on it.

Path C: Use openshift-sustaining fork (project Go minor < fix Go minor)

Condition: The project's Go minor version is lower than what the upstream fix requires. Bumping Go minor on a release branch is not acceptable — we need a backported patch.

Example: Project uses go 1.22.1, upstream fix requires go 1.23.0 → need a fork.

The openshift-sustaining team maintains patched forks of common libraries at lower Go versions for exactly this case. These live under https://github.com/openshift-sustaining/ and follow a naming pattern like v1.71.3-sec.1 (component version + security patch suffix).

Action:

  1. STOP and ask the user for the replacement module URL. Suggest checking https://github.com/openshift-sustaining/<module-name>/releases for available patched versions matching the project's Go minor.
  2. Once the user provides the fork URL/version, fetch its go.mod to verify its Go version is compatible.
  3. Add a replace directive in each affected go.mod pointing to the fork.
  4. Follow the standard update workflow (Step 3 onwards).

The replace directive format:

text
// <CVE number>
replace <original-module> => <fork-module> <fork-version>

Standard update workflow

Once the strategy is determined and the go.mod changes are made, follow these steps in exact order.

Step 1: Find all affected go.mod files
bash
find . -name "go.mod" -not -path "*/vendor/*"

For each go.mod, check if it references the target module:

bash
grep "<module>" path/to/go.mod

Report which are affected. Only modify affected ones. Apply the same change (version bump or replace directive) to each.

Step 2: Sync vendor for each affected module (CRITICAL)

This is the most important step. The vendor directory MUST be updated BEFORE running any repo-level checks like make update. Without this, codegen tools that use go/packages with -mod=vendor fail with cryptic errors like Hit an unsupported type invalid type because the new module code isn't in vendor yet.

For each affected go.mod, from its directory:

bash
GO111MODULE=on GOWORK=off GOFLAGS="" go mod tidy
GO111MODULE=on GOWORK=off GOFLAGS="" go mod vendor

GOWORK=off prevents Go workspace interference. GOFLAGS="" prevents inheriting -mod=vendor which blocks downloads.

go mod tidy may bump transitive dependencies — this is expected (MVS).

After tidy, verify the go directive in each go.mod was NOT bumped. If it was, STOP and tell the user — a transitive dependency is forcing a Go version bump.

Show full SKILL.md (404 more words)Show less
Step 3: Handle macOS toolchain issues

If the project's Go version is old enough to have dyld issues on modern macOS (typically Go < 1.22.5 on macOS Sequoia/Tahoe), use GOTOOLCHAIN to compile with a newer Go while preserving module semantics:

bash
GOTOOLCHAIN=go1.23.6 make update

This compiles using Go 1.23.6 but respects the go 1.22.x directive in the module. Delete stale binaries in hack/tools/bin/ before running if switching toolchain versions.

Step 4: Run repo checks

Inspect the Makefile for update and verify targets:

bash
grep -E "^(update|verify):" Makefile

Run in order:

bash
make update
make verify

If either fails:

  • Verify Step 2 completed for ALL affected modules
  • Verify Go version / toolchain is correct
  • Check for stale binaries in hack/tools/bin/ — delete and rebuild
  • Read the error — don't retry blindly. STOP and report to the user.

After success, verify changes:

bash
git diff --stat
Step 5: Commit
text
fix(deps): <action> <module-name> to fix <CVE>

<TICKET>

<Description of what was done and why.>
<One-line description of the vulnerability.>

Where <action> is:

  • Path A: update
  • Path B: bump go version and update
  • Path C: replace

Use git commit -s for sign-off if required.

Step 6: Optionally create a PR

Before any push or PR action:

  • Ask the user for explicit permission to push and open the PR.
  • Confirm the current branch is not main or master.
  • Never use force push flags (-f, --force, --force-with-lease).
  • Discover remotes via git remote -v; do not assume names like origin.

Format for OpenShift:

text
[<branch>] <TICKET>: fix <CVE> by <action> <module-name>

Include in the PR body:

  • CVE ID and description
  • Link to Jira ticket
  • Link to advisory (GHSA)
  • Link to the fix (upstream commit or fork release)

Hard stops — when to STOP and ask

  1. Path C triggered: The project's Go minor is lower than the fix requires. Ask the user for the openshift-sustaining fork URL.
  2. Go directive bumped after tidy: A transitive dependency forced a Go version change.
  3. make update or make verify fail: Report the error, don't retry blindly.

Troubleshooting

"Hit an unsupported type invalid type" from codegen

The vendor doesn't have the new module code. Ensure go mod tidy && go mod vendor ran for the root module BEFORE make update.

dyld: missing LC_UUID on macOS

Use GOTOOLCHAIN=go1.23.6 to compile with a newer Go. Delete stale hack/tools/bin/* first.

go work sync bumps workspace modules

Expected when using Go workspaces. The bumps in api/go.mod etc. are normal.

vendor/modules.txt mismatch

Run go mod vendor again for the affected module.

Examples

Path A — direct update (project Go 1.25.0, fix needs Go 1.23):

text
/golang:fix-cve module="google.golang.org/grpc" fix-version="v1.75.1" cve="CVE-2026-33186" ticket="OCPBUGS-83972"

Path C — fork replace (project Go 1.22.1, fix needs Go 1.23):

text
/golang:fix-cve module="google.golang.org/grpc" fix-version="v1.75.1" cve="CVE-2026-33186" ticket="OCPBUGS-83972"

→ Skill detects Go mismatch, asks user for fork, user provides github.com/openshift-sustaining/grpc-go v1.71.3-sec.1, skill applies replace directive.

© openshift-eng, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/golang/skills/fix-cve of openshift-eng/ai-helpers.

Open the folder on GitHubat commit a627176

Compare with similar skills

Fix Cve next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fix Cve compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fix Cve this skillopenshift-eng/ai-helpers120—~2.2kAutomated safety check: PassApache-2.0
Golang Pkg Go Devcontext-labs/whip1.1k2 repos~3kAutomated safety check: PassMIT
Docsboostsecurityio/poutine523—~336Automated safety check: PassApache-2.0
Cve Remediator V2kubernetes-sigs/cloud-provider-azure294—~2.5kAutomated safety check: PassApache-2.0
Snapshotboostsecurityio/poutine523—~214Automated safety check: PassApache-2.0
Update Vulndbboostsecurityio/poutine523—~173Automated safety check: PassApache-2.0

Similar skills

  • Golang Pkg Go Dev

    context-labs/whip

    Golang package/module docs via godig, a pkg.go.dev API client (CLI + MCP) — APIs, symbols, versions, importers, licenses, vulnerabilities.

    1.1k GitHub starsUsed in 2 repos~3k tokens
    SecurityAuto-check passed
  • Docs

    boostsecurityio/poutine

    Update project documentation when features are added or changed.

    523 GitHub stars~336 tokensUpdated yesterday
    SecurityAuto-check passed
  • Cve Remediator V2

    kubernetes-sigs/cloud-provider-azure

    Official

    Raise Go modules to caller-supplied minimum fixed versions from CVE/GO findings in any format, per tracked module root, sync go.mod/go.sum and root vendor/, audit the source module graphs, run the…

    294 GitHub stars~2.5k tokensUpdated today
    SecurityAuto-check passed
  • Snapshot

    boostsecurityio/poutine

    Run snapshot regression tests after changes to OPA rules, scanners, analyzers, or formatters to detect output regressions.

    523 GitHub stars~214 tokensUpdated yesterday
    SecurityAuto-check passed
  • Update Vulndb

    boostsecurityio/poutine

    Update the embedded build platform vulnerability database from the CVE Project's cvelistV5 repository.

    523 GitHub stars~173 tokensUpdated yesterday
    SecurityAuto-check passed
  • Ghost Scan Deps

    ghostsecurity/skills

    Ghost Security - Software Composition Analysis (SCA) scanner.

    408 GitHub stars~1.3k tokensUpdated 9 days ago
    SecurityAuto-check: notes

More from openshift-eng/ai-helpers

All 118 skills in this repo
  • Investigate CI Reliability

    openshift-eng/ai-helpers

    Find and independently validate actionable reliability defects across OpenShift release jobs and presubmits, then export portable issue handoffs.

    120 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Address Review PR

    openshift-eng/ai-helpers

    Fetch and address all PR review comments — categorize by priority, make code changes, post replies, and push.

    120 GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Categorize Activity Types

    openshift-eng/ai-helpers

    Categorize Jira issues into Red Hat Sankey Activity Type categories using MCP Jira tools.

    120 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Has Review Work

    openshift-eng/ai-helpers

    Decide whether a GitHub PR has unanswered authorized review comments or new required CI failures worth a follow-up agent.

    120 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Must Gather Analyzer

    openshift-eng/ai-helpers

    Analyze OpenShift must-gather diagnostic data including cluster operators, pods, nodes, and network components.

    120 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • Payload Autodl JSON

    openshift-eng/ai-helpers

    Schema for the autodl JSON data file produced by payload-analysis for database ingestion — you must use this skill whenever generating the autodl JSON file

    120 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Fix Cve

What does Fix Cve do?

Patch a Go dependency to fix a CVE using the appropriate strategy based on Go version compatibility. Fix Cve is an agent skill from openshift-eng/ai-helpers. Patch a Go dependency to fix a CVE using the appropriate strategy based on Go version compatibility.

When should I use Fix Cve?

Fix Cve fits situations like: the user wants to fix a CVE by updating a Go module; replacing it with a patched fork; applying a security patch across all go.mod files in a Go project; update vulnerable dependency.

How do I install Fix Cve in Claude Code?

Run `npx skills add openshift-eng/ai-helpers --skill fix-cve -a claude-code`. Or copy the skill folder (plugins/golang/skills/fix-cve in openshift-eng/ai-helpers) into .claude/skills/fix-cve in your project. Claude Code loads it when a task matches its description.

How do I install Fix Cve in Codex?

Run `npx skills add openshift-eng/ai-helpers --skill fix-cve -a codex`. Or copy the skill folder (plugins/golang/skills/fix-cve in openshift-eng/ai-helpers) into .agents/skills/fix-cve in your project. Codex loads it when a task matches its description.

Can I use Fix Cve in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openshift-eng/ai-helpers --skill fix-cve -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fix-cve, .gemini/skills/fix-cve, .github/skills/fix-cve and .opencode/skills/fix-cve in your project.

What does Fix Cve need to run?

Going by SKILL.md and its folder, Fix Cve needs the command-line tools its instructions call (go, make and git).

Does Fix Cve access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Fix Cve safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fix Cve use?

Fix Cve is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fix Cve use?

About 2.2k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fix Cve?

Skills that share tags, products or a category with Fix Cve: Golang Pkg Go Dev (context-labs/whip, 1.1k stars), Docs (boostsecurityio/poutine, 523 stars), Cve Remediator V2 (kubernetes-sigs/cloud-provider-azure, 294 stars) and Snapshot (boostsecurityio/poutine, 523 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fix Cve?

openshift-eng (a GitHub organization) maintains it in openshift-eng/ai-helpers, which has 120 GitHub stars. The repository holds 118 skills in this directory. The repository was last updated on October 6, 2026.

Source: openshift-eng/ai-helpers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.