Agent skill

Image Repo Mapping

by openshift-eng in openshift-eng/ai-helpers

A skill your agent uses when resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary, pscomponent label, or Downstream Component Name field.

Apache-2.0Auto-check passedDevOps & Cloud

Install Image Repo Mapping

skills CLI
$ npx skills add openshift-eng/ai-helpers --skill image-repo-mapping -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openshift-eng/ai-helpers image-repo-mapping --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/compliance/skills/image-repo-mapping .claude/skills/image-repo-mapping && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
image-repo-mapping
GitHub stars
120
Token cost
~4.5k tokens
SKILL.md length
1,065 words
Files
1
Skills in repo
118
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary, pscomponent label, or Downstream Component Name field.

  • Works in 5 steps: Full GitHub URL supplied… → Exact image name match — look the image… → Prefix match — strip version suffixes… → …
  • Resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary
  • SKILL.md covers When to Use This Skill, Resolution Order, Two Repository Patterns and Image → Repository Map, plus 2 more sections
  • Calls git; reaches github.com

What it does

Image Repo Mapping is an agent skill from openshift-eng/ai-helpers. Use when resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary, pscomponent label, or Downstream Component Name field.

Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers and Vulnerability scanning. It works with GitHub, Jira, Ansible and Git. The repository describes itself as: Developer productivity tools for Claude Code & other AI assistants. The licence is Apache-2.0.

When your agent uses it

  • Resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary
  • Pscomponent label
  • Downstream Component Name field

Example prompts

  • “/image-repo-mapping”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Full GitHub URL supplied (--repo=https://github.com/...) → use directly, skip this skill.
  2. Exact image name match — look the image name up in the table below.
  3. Prefix match — strip version suffixes (e.g. -1-0, -1-12-4, -rhel9, -rhel8) and re-match.
  4. Keyword match — check the per-section keyword rules at the bottom of each group.
  5. NOT FOUND → Exit immediately with the error message below. Do not guess. Do not proceed with analysis.

What it can do on your machine

Read from SKILL.md and the folder at commit a627176. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Image Repo Mapping loads about 4.5k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 1,065 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~4.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openshift-eng/ai-helpers at commit a627176, republished under its Apache-2.0 licence (© openshift-eng). 1,065 words, ~4,515 tokens.

Download SKILL.mdSave it as .claude/skills/image-repo-mapping/SKILL.md (or your agent's skills folder).
name
image-repo-mapping
description
Use when resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary, pscomponent label, or Downstream Component Name field.

Image to Repository Mapping

Translates a container image name into the GitHub repository URL to clone for analysis. Image names appear in the ticket summary, pscomponent: labels, and the Downstream Component Name custom field.

When to Use This Skill

Use this skill when:

  • An image name has been extracted from a Jira ticket (summary, label, or custom field)
  • The user passes --repo=<image-name> using a short image name rather than a full GitHub URL
  • Phase 0.7 needs to determine which repository to clone

Resolution Order

Apply these in order and stop at the first match:

  1. Full GitHub URL supplied (--repo=https://github.com/...) → use directly, skip this skill.
  2. Exact image name match — look the image name up in the table below.
  3. Prefix match — strip version suffixes (e.g. -1-0, -1-12-4, -rhel9, -rhel8) and re-match.
  4. Keyword match — check the per-section keyword rules at the bottom of each group.
  5. NOT FOUND → Exit immediately with the error message below. Do not guess. Do not proceed with analysis.

Tip: Strip pkg:oci/ prefix before matching (e.g. pkg:oci/ose-ansible-operator → ose-ansible-operator).

Not-Found Exit

If no match is found after all steps above, stop immediately and output:

❌ Repository mapping not found for image: <image_name>

The image "<image_name>" is not in the known mapping table and could not
be resolved automatically.

To proceed, re-run with an explicit repository URL:

  --repo=https://github.com/org/repo

Or add the mapping to:
  plugins/compliance/skills/image-repo-mapping/SKILL.md

Do NOT continue analysis without a confirmed source repository.

Do NOT fall back to guessing, fuzzy matching, or prompting the user inline. Exit the command at this point.


Two Repository Patterns

Components fall into one of two patterns. The resolution output is different for each.

Pattern A — Direct repo

Clone the mapped repo directly at the mapped branch. Used by: Operator SDK, Ansible Operator, must-gather, Secrets Store CSI.

image → repo URL + branch
Pattern B — Release repo with git submodules

Some components use a dedicated -release repo that aggregates all component repos as git submodules. The release repo branch pins each submodule to the exact commit/tag used for that release. Used by: cert-manager, ZTWIM, ESO.

Resolution steps for Pattern B:

  1. Clone the release repo at the mapped release branch
  2. Read .gitmodules from that branch to find the submodule entry matching the target image
  3. Read the pinned commit from the release repo tree (git ls-tree HEAD <submodule-path>) — do not clone from the .gitmodules branch field alone
  4. Clone the component repo and check out that pinned commit for analysis
bash
# Step 1: Clone release repo at correct branch (per-run path under REPOS_BASE)
RELEASE_CLONE_DIR="${REPOS_BASE}/.release-clones/$(echo "${RELEASE_REPO_URL}" | sed -E 's#^[a-zA-Z]+://github\.com/##; s#\.git$##; s#/$##' | tr '/' '-')-${RELEASE_BRANCH}"
rm -rf "${RELEASE_CLONE_DIR}"
mkdir -p "$(dirname "${RELEASE_CLONE_DIR}")"
git clone --depth=1 -b "${RELEASE_BRANCH}" "${RELEASE_REPO_URL}" "${RELEASE_CLONE_DIR}"

# Step 2: Read .gitmodules
cat "${RELEASE_CLONE_DIR}/.gitmodules"

# Step 3: Extract submodule path + url from .gitmodules
# Step 4: Read pinned commit from release repo tree
PINNED_COMMIT=$(git -C "${RELEASE_CLONE_DIR}" ls-tree HEAD "${SUBMODULE_PATH}" | awk '{print $3}')
if [ -z "${PINNED_COMMIT}" ]; then
  echo "ERROR: no pinned commit found for ${SUBMODULE_PATH}"
  exit 1
fi

# Step 5: Clone component repo and checkout pinned commit (fetch SHA explicitly — shallow clone alone may miss it)
git clone "${COMPONENT_URL}" "${REPO_DIR}"
git -C "${REPO_DIR}" fetch origin "${PINNED_COMMIT}"
git -C "${REPO_DIR}" checkout "${PINNED_COMMIT}"

Jira branch → release branch naming for Pattern B:

Jira BRANCH valueRelease branch
cert-manager-X-Yrelease-X.Y in cert-manager-operator-release
external-secrets-X-Yrelease-X.Y in external-secrets-operator-release
ztwim-1.0release-1.0.0 in zero-trust-workload-identity-manager-release (one-time exception — team confirmed this was a branching mistake; future releases use release-X.Y)
ztwim-X.Y (any other)release-X.Y in zero-trust-workload-identity-manager-release

Note: Jira branch values use hyphens for separators (e.g. external-secrets-1-0) while release branches use dots (e.g. release-1.0). Strip the component prefix and convert the remaining hyphen-separated version to dot notation.


Image → Repository Map

Every image name here has appeared in real ticket summaries or labels. This table is intentionally scoped to the components this command has been validated against — extend it as new components come up (see the not-found exit message above).

cert-manager / jetstack — Pattern B (release repo + submodules)

Release repo: https://github.com/openshift/cert-manager-operator-release Submodules: cert-manager-operator, cert-manager, cert-manager-istio-csr Branch mapping: Jira cert-manager-X-Y → release-X.Y in the release repo

Clone the release repo at the correct branch, read .gitmodules to find the submodule URL and pinned ref for the target image, then clone that component at the pinned ref.

Image Name / PrefixSubmodule in .gitmodules
cert-manager/cert-manager-operator-rhel9, cert-manager/cert-manager-operator-bundle, cert-manager-operator-*cert-manager-operator
cert-manager/cert-manager-istio-csr-rhel9cert-manager-istio-csr
cert-manager/jetstack-cert-manager-*, jetstack-cert-manager-*, redhat-user-workloads/jetstack-cert-manager-*cert-manager
cert-manager-operator (operator + bundle only)
Image Name / PrefixGitHub Repository
cert-manager-operator-containerhttps://github.com/openshift/cert-manager-operator
cert-manager-operator-rhel9https://github.com/openshift/cert-manager-operator
cert-manager/cert-manager-operator-rhel9https://github.com/openshift/cert-manager-operator
cert-manager/cert-manager-operator-bundlehttps://github.com/openshift/cert-manager-operator
cert-manager-istio-csr
Image Name / PrefixGitHub Repository
cert-manager/cert-manager-istio-csr-rhel9https://github.com/openshift/cert-manager-istio-csr
jetstack-cert-manager
Image Name / PrefixGitHub Repository
cert-manager/jetstack-cert-manager-rhel9https://github.com/openshift/jetstack-cert-manager
cert-manager/jetstack-cert-manager-acmesolver-rhel9https://github.com/openshift/jetstack-cert-manager
jetstack-cert-manager-rhel9https://github.com/openshift/jetstack-cert-manager
jetstack-cert-manager-containerhttps://github.com/openshift/jetstack-cert-manager
jetstack-cert-manager-acmesolver-rhel9https://github.com/openshift/jetstack-cert-manager
jetstack-cert-manager-acmesolver-containerhttps://github.com/openshift/jetstack-cert-manager
redhat-user-workloads/jetstack-cert-manager-*https://github.com/openshift/jetstack-cert-manager

Namespace prefix match: cert-manager → requires full image name lookup above (multiple repos in this namespace). Keyword match: cert-manager-operator / cert-manager-operator-bundle → cert-manager-operator; cert-manager-istio-csr → cert-manager-istio-csr; jetstack-cert-manager → jetstack-cert-manager.


Operator SDK / Helm Operator (non-ansible images)
Image Name / PrefixGitHub Repository
operator-sdkhttps://github.com/openshift/ocp-release-operator-sdk
openshift4/ose-operator-sdk-rhel8https://github.com/openshift/ocp-release-operator-sdk
openshift4/ose-operator-sdk-rhel9https://github.com/openshift/ocp-release-operator-sdk
openshift-enterprise-operator-sdk-containerhttps://github.com/openshift/ocp-release-operator-sdk
openshift4/ose-helm-operatorhttps://github.com/openshift/ocp-release-operator-sdk
openshift4/ose-helm-rhel9-operatorhttps://github.com/openshift/ocp-release-operator-sdk
openshift-enterprise-helm-operator-containerhttps://github.com/openshift/ocp-release-operator-sdk
pkg:oci/ose-operator-sdk-rhel8https://github.com/openshift/ocp-release-operator-sdk
pkg:oci/ose-operator-sdk-rhel9https://github.com/openshift/ocp-release-operator-sdk
pkg:oci/ose-helm-operatorhttps://github.com/openshift/ocp-release-operator-sdk
pkg:oci/openshift-enterprise-helm-operatorhttps://github.com/openshift/ocp-release-operator-sdk

Show full SKILL.md (423 more words)Show less
Ansible Operator
Image Name / PrefixGitHub Repository
ansible-operator-pluginshttps://github.com/openshift/ansible-operator-plugins
openshift4/ose-ansible-operatorhttps://github.com/openshift/ansible-operator-plugins
openshift4/ose-ansible-rhel9-operatorhttps://github.com/openshift/ansible-operator-plugins
openshift-enterprise-ansible-operator-containerhttps://github.com/openshift/ansible-operator-plugins
pkg:oci/ose-ansible-operatorhttps://github.com/openshift/ansible-operator-plugins
pkg:oci/ose-ansible-rhel9-operatorhttps://github.com/openshift/ansible-operator-plugins

Keyword match: any image containing ansible-operator → https://github.com/openshift/ansible-operator-plugins


External Secrets Operator — Pattern B (release repo + submodules)

Release repo: https://github.com/openshift/external-secrets-operator-release Submodules: external-secrets-operator, external-secrets, bitwarden-sdk-server Branch mapping: Jira external-secrets-X-Y → release-X.Y in the release repo

Clone the release repo at the correct branch, read .gitmodules to find the submodule URL and pinned ref for the target image, then clone that component at the pinned ref.

Image Name / PrefixSubmodule in .gitmodules
external-secrets-operator/external-secrets-operator-rhel9, external-secrets-operator/external-secrets-operator-bundle, redhat-user-workloads/external-secrets-operator-*external-secrets-operator
external-secrets-operator/external-secrets-rhel9, redhat-user-workloads/external-secrets-1-0external-secrets
external-secrets-operator/bitwarden-sdk-server-rhel9, redhat-user-workloads/bitwarden-sdk-server-*bitwarden-sdk-server

Keyword match: external-secrets-operator / external-secrets-operator-bundle → submodule external-secrets-operator; bitwarden-sdk-server → submodule bitwarden-sdk-server; external-secrets-rhel9 / external-secrets-1-0 → submodule external-secrets.


Zero Trust / SPIFFE / SPIRE — Pattern B (release repo + submodules)

Release repo: https://github.com/openshift/zero-trust-workload-identity-manager-release Submodules: zero-trust-workload-identity-manager (spire-operator), spiffe-spire, spiffe-spire-controller-manager, spiffe-spiffe-csi Branch mapping: Jira ztwim-X.Y → release-X.Y in the release repo

Clone the release repo at the correct branch (--recurse-submodules is NOT needed — read .gitmodules manually and clone only the relevant submodule), then clone that component at the pinned ref.

Image Name / PrefixSubmodule in .gitmodules
zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9, *-operator-bundlezero-trust-workload-identity-manager
zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9, *spiffe-spire-server*, *spire-oidc*, redhat-user-workloads/spiffe-spire-*spiffe-spire
zero-trust-workload-identity-manager/spiffe-spire-controller-manager-rhel9spiffe-spire-controller-manager
zero-trust-workload-identity-manager/spiffe-csi-driver-rhel9, redhat-user-workloads/spiffe-csi-driver-*spiffe-spiffe-csi
zero-trust-workload-identity-manager/spiffe-helper-rhel9spiffe-spiffe-helper

The zero-trust-workload-identity-manager namespace spans four repositories — match on the full image name, not just the namespace prefix.

spire-operator (operator + bundle only)
Image Name / PrefixGitHub Repository
zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9https://github.com/openshift/spire-operator
zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-operator-bundlehttps://github.com/openshift/spire-operator
spiffe-spire (agent, server, OIDC discovery provider)
Image Name / PrefixGitHub Repository
zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9https://github.com/openshift/spiffe-spire
zero-trust-workload-identity-manager/spiffe-spire-server-rhel9https://github.com/openshift/spiffe-spire
zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9https://github.com/openshift/spiffe-spire
redhat-user-workloads/spiffe-spire-agent-*https://github.com/openshift/spiffe-spire
redhat-user-workloads/spiffe-spire-server-*https://github.com/openshift/spiffe-spire
redhat-user-workloads/spiffe-spire-oidc-discovery-provider-*https://github.com/openshift/spiffe-spire
spiffe-spire-controller-manager
Image Name / PrefixGitHub Repository
zero-trust-workload-identity-manager/spiffe-spire-controller-manager-rhel9https://github.com/openshift/spiffe-spire-controller-manager
spiffe-spiffe-csi (CSI driver)
Image Name / PrefixGitHub Repository
zero-trust-workload-identity-manager/spiffe-csi-driver-rhel9https://github.com/openshift/spiffe-spiffe-csi
redhat-user-workloads/spiffe-csi-driver-*https://github.com/openshift/spiffe-spiffe-csi
spiffe-spiffe-helper
Image Name / PrefixGitHub Repository
zero-trust-workload-identity-manager/spiffe-helper-rhel9https://github.com/openshift/spiffe-spiffe-helper

Namespace prefix match: zero-trust-workload-identity-manager → requires full image name lookup above (multiple repos in this namespace). Keyword match: spire-agent / spire-server / spire-oidc → https://github.com/openshift/spiffe-spire; spire-controller-manager → https://github.com/openshift/spiffe-spire-controller-manager; spiffe-csi-driver → https://github.com/openshift/spiffe-spiffe-csi; spiffe-helper → https://github.com/openshift/spiffe-spiffe-helper; zero-trust-workload-identity-manager (manager/bundle) → https://github.com/openshift/spire-operator.


must-gather
Image Name / PrefixGitHub Repository
openshift4/ose-must-gather-rhel9https://github.com/openshift/must-gather
openshift4/ose-support-log-gather-rhel9-operatorhttps://github.com/openshift/must-gather-operator

Secrets Store CSI

The namespace spans two repositories. The mustgather image is built from the operator repo.

secrets-store-csi-driver-operator (operator, bundle, mustgather)
Image Name / PrefixGitHub Repository
openshift4/ose-secrets-store-csi-driver-rhel9-operatorhttps://github.com/openshift/secrets-store-csi-driver-operator
openshift4/ose-secrets-store-csi-driver-operator-bundlehttps://github.com/openshift/secrets-store-csi-driver-operator
ose-secrets-store-csi-driver-operator-containerhttps://github.com/openshift/secrets-store-csi-driver-operator
openshift4/ose-secrets-store-csi-mustgather-rhel9https://github.com/openshift/secrets-store-csi-driver-operator
ose-secrets-store-csi-mustgather-containerhttps://github.com/openshift/secrets-store-csi-driver-operator
secrets-store-csi-driver (driver only)
Image Name / PrefixGitHub Repository
openshift4/ose-secrets-store-csi-driver-rhel9https://github.com/openshift/secrets-store-csi-driver
ose-secrets-store-csi-driver-containerhttps://github.com/openshift/secrets-store-csi-driver

Keyword match: secrets-store-csi-mustgather / secrets-store-csi-driver-operator / secrets-store-csi-driver-operator-bundle → secrets-store-csi-driver-operator; secrets-store-csi-driver-rhel9 (driver image, not operator) → secrets-store-csi-driver.


Return Value

Success:

json
{
  "skill": "image-repo-mapping",
  "status": "success",
  "resolved_repos": [
    {
      "image_name": "openshift4/ose-ansible-rhel9-operator",
      "repo_url": "https://github.com/openshift/ansible-operator-plugins",
      "clone_path": ".work/compliance/analyze-cve/repos/ansible-operator-plugins",
      "confidence": "exact_match",
      "match_method": "exact"
    }
  ],
  "unresolved": [],
  "resolution_method": "summary_image_name"
}

Not found (exit):

json
{
  "skill": "image-repo-mapping",
  "status": "not_found",
  "image_name": "<image_name>",
  "error": "No repository mapping found. Re-run with --repo=https://github.com/org/repo or add the mapping to image-repo-mapping/SKILL.md."
}

confidence: exact_match, prefix_match, keyword_match, user_provided


Integration with analyze-cve

Called from Phase 0.7 of the analyze-cve skill.

Input: image name extracted by jira-cve-extraction skill (from summary, pscomponent: label, or Downstream Component Name field), or the short name passed via --repo=<name> Output: (image_name, repo_url, clone_path) tuple passed to Phase 0.7 for cloning

© openshift-eng, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/compliance/skills/image-repo-mapping of openshift-eng/ai-helpers.

Open the folder on GitHubat commit a627176

Compare with similar skills

Image Repo Mapping next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Image Repo Mapping compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Image Repo Mapping this skillopenshift-eng/ai-helpers120—~4.5kAutomated safety check: PassApache-2.0
Scanning Containers With Trivy In Cicdmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Warp Vulnerability Triagewarpdotdev/warp65k1 repos~2.1kAutomated safety check: PassAGPL-3.0
Perplexity Server DeployescapeWu/perplexity-ai170—~662Automated safety check: NotesMIT
Triage Image Cvesactivepieces/activepieces25k—~3.6kAutomated safety check: PassCustom licence

Similar skills

  • Scanning Containers With Trivy In Cicd

    mukul975/Anthropic-Cybersecurity-Skills

    Integrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check passed
  • Perplexity Server Deploy

    escapeWu/perplexity-ai

    Deploys the perplexity-ai project to its production server by pushing main, fast-forwarding the server checkout, rebuilding the image there and verifying health.

    170 GitHub stars~662 tokensUpdated 12 days ago
    DevOps & CloudAuto-check: notes
  • Triage Image Cves

    activepieces/activepieces

    Scan an Activepieces Docker image with grype for OS/base-image (deb) and application (npm) CVEs of High/Critical severity.

    25k GitHub stars~3.6k tokensUpdated today
    SecurityAuto-check passed
  • Alibabacloud Ecs Sec Userspace

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

    148 GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes

More from openshift-eng/ai-helpers

All 118 skills in this repo
  • Investigate CI Reliability

    openshift-eng/ai-helpers

    Find and independently validate actionable reliability defects across OpenShift release jobs and presubmits, then export portable issue handoffs.

    120 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check passed
  • Address Review PR

    openshift-eng/ai-helpers

    Fetch and address all PR review comments — categorize by priority, make code changes, post replies, and push.

    120 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Categorize Activity Types

    openshift-eng/ai-helpers

    Categorize Jira issues into Red Hat Sankey Activity Type categories using MCP Jira tools.

    120 GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Has Review Work

    openshift-eng/ai-helpers

    Decide whether a GitHub PR has unanswered authorized review comments or new required CI failures worth a follow-up agent.

    120 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check passed
  • Must Gather Analyzer

    openshift-eng/ai-helpers

    Analyze OpenShift must-gather diagnostic data including cluster operators, pods, nodes, and network components.

    120 GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check passed
  • Payload Autodl JSON

    openshift-eng/ai-helpers

    Schema for the autodl JSON data file produced by payload-analysis for database ingestion — you must use this skill whenever generating the autodl JSON file

    120 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed

Questions about Image Repo Mapping

What does Image Repo Mapping do?

A skill your agent uses when resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary, pscomponent label, or Downstream Component Name field. Image Repo Mapping is an agent skill from openshift-eng/ai-helpers. Use when resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary, pscomponent label, or Downstream Component Name field.

When should I use Image Repo Mapping?

Image Repo Mapping fits situations like: resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary; pscomponent label; downstream Component Name field.

How do I install Image Repo Mapping in Claude Code?

Run `npx skills add openshift-eng/ai-helpers --skill image-repo-mapping -a claude-code`. Or copy the skill folder (plugins/compliance/skills/image-repo-mapping in openshift-eng/ai-helpers) into .claude/skills/image-repo-mapping in your project. Claude Code loads it when a task matches its description.

How do I install Image Repo Mapping in Codex?

Run `npx skills add openshift-eng/ai-helpers --skill image-repo-mapping -a codex`. Or copy the skill folder (plugins/compliance/skills/image-repo-mapping in openshift-eng/ai-helpers) into .agents/skills/image-repo-mapping in your project. Codex loads it when a task matches its description.

Can I use Image Repo Mapping in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openshift-eng/ai-helpers --skill image-repo-mapping -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/image-repo-mapping, .gemini/skills/image-repo-mapping, .github/skills/image-repo-mapping and .opencode/skills/image-repo-mapping in your project.

What does Image Repo Mapping need to run?

Going by SKILL.md and its folder, Image Repo Mapping needs the command-line tools its instructions call (git).

Does Image Repo Mapping access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Image Repo Mapping safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Image Repo Mapping use?

Image Repo Mapping is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Image Repo Mapping use?

About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Image Repo Mapping?

Skills that share tags, products or a category with Image Repo Mapping: Scanning Containers With Trivy In Cicd (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Warp Vulnerability Triage (warpdotdev/warp, 65k stars) and Perplexity Server Deploy (escapeWu/perplexity-ai, 170 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Image Repo Mapping?

openshift-eng (a GitHub organization) maintains it in openshift-eng/ai-helpers, which has 120 GitHub stars. The repository holds 118 skills in this directory. The repository was last updated on October 6, 2026.

Source: openshift-eng/ai-helpers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.