A skill your agent uses when resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary, pscomponent label, or Downstream Component Name field.
Install the "image-repo-mapping" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/image-repo-mapping into .claude/skills/image-repo-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "image-repo-mapping", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add openshift-eng/ai-helpers --skill image-repo-mapping -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "image-repo-mapping" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/image-repo-mapping into .agents/skills/image-repo-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "image-repo-mapping", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add openshift-eng/ai-helpers --skill image-repo-mapping -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "image-repo-mapping" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/image-repo-mapping into .cursor/skills/image-repo-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "image-repo-mapping", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add openshift-eng/ai-helpers --skill image-repo-mapping -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "image-repo-mapping" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/image-repo-mapping into .gemini/skills/image-repo-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "image-repo-mapping", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add openshift-eng/ai-helpers --skill image-repo-mapping -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "image-repo-mapping" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/image-repo-mapping into .github/skills/image-repo-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "image-repo-mapping", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add openshift-eng/ai-helpers --skill image-repo-mapping -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "image-repo-mapping" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/image-repo-mapping into .opencode/skills/image-repo-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "image-repo-mapping", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
image-repo-mapping
GitHub stars
120
Token cost
~4.5k tokens
SKILL.md length
1,065 words
Files
1
Skills in repo
118
Repo updated
First seen
Licence
Apache-2.0
At a glance
A skill your agent uses when resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary, pscomponent label, or Downstream Component Name field.
Works in 5 steps: Full GitHub URL supplied… → Exact image name match — look the image… → Prefix match — strip version suffixes… → …
Resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary
SKILL.md covers When to Use This Skill, Resolution Order, Two Repository Patterns and Image → Repository Map, plus 2 more sections
Calls git; reaches github.com
What it does
Image Repo Mapping is an agent skill from openshift-eng/ai-helpers. Use when resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary, pscomponent label, or Downstream Component Name field.
Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Containers and Vulnerability scanning. It works with GitHub, Jira, Ansible and Git. The repository describes itself as: Developer productivity tools for Claude Code & other AI assistants. The licence is Apache-2.0.
When your agent uses it
Resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary
Pscomponent label
Downstream Component Name field
Example prompts
“/image-repo-mapping”
Workflow steps
5 steps, taken from the first numbered list in SKILL.md.
1Full GitHub URL supplied (--repo=https://github.com/...) → use directly, skip this skill.
2Exact image name match — look the image name up in the table below.
3Prefix match — strip version suffixes (e.g. -1-0, -1-12-4, -rhel9, -rhel8) and re-match.
4Keyword match — check the per-section keyword rules at the bottom of each group.
5NOT FOUND → Exit immediately with the error message below. Do not guess. Do not proceed with analysis.
What it can do on your machine
Read from SKILL.md and the folder at commit a627176. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
git
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
github.com
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Image Repo Mapping loads about 4.5k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 1,065 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~49
When it runs· the whole SKILL.md, loaded when a task matches
~4.5k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/image-repo-mapping/SKILL.md (or your agent's skills folder).
name
image-repo-mapping
description
Use when resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary, pscomponent label, or Downstream Component Name field.
Image to Repository Mapping
Translates a container image name into the GitHub repository URL to clone for analysis. Image names appear in the ticket summary, pscomponent: labels, and the Downstream Component Name custom field.
When to Use This Skill
Use this skill when:
An image name has been extracted from a Jira ticket (summary, label, or custom field)
The user passes --repo=<image-name> using a short image name rather than a full GitHub URL
Phase 0.7 needs to determine which repository to clone
Resolution Order
Apply these in order and stop at the first match:
Full GitHub URL supplied (--repo=https://github.com/...) → use directly, skip this skill.
Exact image name match — look the image name up in the table below.
Prefix match — strip version suffixes (e.g. -1-0, -1-12-4, -rhel9, -rhel8) and re-match.
Keyword match — check the per-section keyword rules at the bottom of each group.
NOT FOUND → Exit immediately with the error message below. Do not guess. Do not proceed with analysis.
Tip: Strip pkg:oci/ prefix before matching (e.g. pkg:oci/ose-ansible-operator → ose-ansible-operator).
Not-Found Exit
If no match is found after all steps above, stop immediately and output:
❌ Repository mapping not found for image: <image_name>
The image "<image_name>" is not in the known mapping table and could not
be resolved automatically.
To proceed, re-run with an explicit repository URL:
--repo=https://github.com/org/repo
Or add the mapping to:
plugins/compliance/skills/image-repo-mapping/SKILL.md
Do NOT continue analysis without a confirmed source repository.
Do NOT fall back to guessing, fuzzy matching, or prompting the user inline. Exit the command at this point.
Two Repository Patterns
Components fall into one of two patterns. The resolution output is different for each.
Pattern A — Direct repo
Clone the mapped repo directly at the mapped branch. Used by: Operator SDK, Ansible Operator, must-gather, Secrets Store CSI.
image → repo URL + branch
Pattern B — Release repo with git submodules
Some components use a dedicated -release repo that aggregates all component repos as git submodules. The release repo branch pins each submodule to the exact commit/tag used for that release. Used by: cert-manager, ZTWIM, ESO.
Resolution steps for Pattern B:
Clone the release repo at the mapped release branch
Read .gitmodules from that branch to find the submodule entry matching the target image
Read the pinned commit from the release repo tree (git ls-tree HEAD <submodule-path>) — do not clone from the .gitmodules branch field alone
Clone the component repo and check out that pinned commit for analysis
bash
# Step 1: Clone release repo at correct branch (per-run path under REPOS_BASE)
RELEASE_CLONE_DIR="${REPOS_BASE}/.release-clones/$(echo "${RELEASE_REPO_URL}" | sed -E 's#^[a-zA-Z]+://github\.com/##; s#\.git$##; s#/$##' | tr '/' '-')-${RELEASE_BRANCH}"
rm -rf "${RELEASE_CLONE_DIR}"
mkdir -p "$(dirname "${RELEASE_CLONE_DIR}")"
git clone --depth=1 -b "${RELEASE_BRANCH}" "${RELEASE_REPO_URL}" "${RELEASE_CLONE_DIR}"
# Step 2: Read .gitmodules
cat "${RELEASE_CLONE_DIR}/.gitmodules"
# Step 3: Extract submodule path + url from .gitmodules
# Step 4: Read pinned commit from release repo tree
PINNED_COMMIT=$(git -C "${RELEASE_CLONE_DIR}" ls-tree HEAD "${SUBMODULE_PATH}" | awk '{print $3}')
if [ -z "${PINNED_COMMIT}" ]; then
echo "ERROR: no pinned commit found for ${SUBMODULE_PATH}"
exit 1
fi
# Step 5: Clone component repo and checkout pinned commit (fetch SHA explicitly — shallow clone alone may miss it)
git clone "${COMPONENT_URL}" "${REPO_DIR}"
git -C "${REPO_DIR}" fetch origin "${PINNED_COMMIT}"
git -C "${REPO_DIR}" checkout "${PINNED_COMMIT}"
Jira branch → release branch naming for Pattern B:
Jira BRANCH value
Release branch
cert-manager-X-Y
release-X.Y in cert-manager-operator-release
external-secrets-X-Y
release-X.Y in external-secrets-operator-release
ztwim-1.0
release-1.0.0 in zero-trust-workload-identity-manager-release(one-time exception — team confirmed this was a branching mistake; future releases use release-X.Y)
ztwim-X.Y (any other)
release-X.Y in zero-trust-workload-identity-manager-release
Note: Jira branch values use hyphens for separators (e.g. external-secrets-1-0) while release branches use dots (e.g. release-1.0). Strip the component prefix and convert the remaining hyphen-separated version to dot notation.
Image → Repository Map
Every image name here has appeared in real ticket summaries or labels. This table is intentionally scoped to the components this command has been validated against — extend it as new components come up (see the not-found exit message above).
cert-manager / jetstack — Pattern B (release repo + submodules)
Release repo:https://github.com/openshift/cert-manager-operator-releaseSubmodules:cert-manager-operator, cert-manager, cert-manager-istio-csrBranch mapping: Jira cert-manager-X-Y → release-X.Y in the release repo
Clone the release repo at the correct branch, read .gitmodules to find the submodule URL and pinned ref for the target image, then clone that component at the pinned ref.
Keyword match: any image containing ansible-operator → https://github.com/openshift/ansible-operator-plugins
External Secrets Operator — Pattern B (release repo + submodules)
Release repo:https://github.com/openshift/external-secrets-operator-releaseSubmodules:external-secrets-operator, external-secrets, bitwarden-sdk-serverBranch mapping: Jira external-secrets-X-Y → release-X.Y in the release repo
Clone the release repo at the correct branch, read .gitmodules to find the submodule URL and pinned ref for the target image, then clone that component at the pinned ref.
Zero Trust / SPIFFE / SPIRE — Pattern B (release repo + submodules)
Release repo:https://github.com/openshift/zero-trust-workload-identity-manager-releaseSubmodules:zero-trust-workload-identity-manager (spire-operator), spiffe-spire, spiffe-spire-controller-manager, spiffe-spiffe-csiBranch mapping: Jira ztwim-X.Y → release-X.Y in the release repo
Clone the release repo at the correct branch (--recurse-submodules is NOT needed — read .gitmodules manually and clone only the relevant submodule), then clone that component at the pinned ref.
{
"skill": "image-repo-mapping",
"status": "not_found",
"image_name": "<image_name>",
"error": "No repository mapping found. Re-run with --repo=https://github.com/org/repo or add the mapping to image-repo-mapping/SKILL.md."
}
Input: image name extracted by jira-cve-extraction skill (from summary, pscomponent: label, or Downstream Component Name field), or the short name passed via --repo=<name>Output:(image_name, repo_url, clone_path) tuple passed to Phase 0.7 for cloning
Image Repo Mapping next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Image Repo Mapping compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Image Repo Mapping this skillopenshift-eng/ai-helpers
Integrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and…
Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…
Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.
Deploys the perplexity-ai project to its production server by pushing main, fast-forwarding the server checkout, rebuilding the image there and verifying health.
Schema for the autodl JSON data file produced by payload-analysis for database ingestion — you must use this skill whenever generating the autodl JSON file
A skill your agent uses when resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary, pscomponent label, or Downstream Component Name field. Image Repo Mapping is an agent skill from openshift-eng/ai-helpers. Use when resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary, pscomponent label, or Downstream Component Name field.
When should I use Image Repo Mapping?
Image Repo Mapping fits situations like: resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary; pscomponent label; downstream Component Name field.
How do I install Image Repo Mapping in Claude Code?
Run `npx skills add openshift-eng/ai-helpers --skill image-repo-mapping -a claude-code`. Or copy the skill folder (plugins/compliance/skills/image-repo-mapping in openshift-eng/ai-helpers) into .claude/skills/image-repo-mapping in your project. Claude Code loads it when a task matches its description.
How do I install Image Repo Mapping in Codex?
Run `npx skills add openshift-eng/ai-helpers --skill image-repo-mapping -a codex`. Or copy the skill folder (plugins/compliance/skills/image-repo-mapping in openshift-eng/ai-helpers) into .agents/skills/image-repo-mapping in your project. Codex loads it when a task matches its description.
Can I use Image Repo Mapping in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openshift-eng/ai-helpers --skill image-repo-mapping -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/image-repo-mapping, .gemini/skills/image-repo-mapping, .github/skills/image-repo-mapping and .opencode/skills/image-repo-mapping in your project.
What does Image Repo Mapping need to run?
Going by SKILL.md and its folder, Image Repo Mapping needs the command-line tools its instructions call (git).
Does Image Repo Mapping access the network?
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Is Image Repo Mapping safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Image Repo Mapping use?
Image Repo Mapping is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Image Repo Mapping use?
About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Image Repo Mapping?
Skills that share tags, products or a category with Image Repo Mapping: Scanning Containers With Trivy In Cicd (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Warp Vulnerability Triage (warpdotdev/warp, 65k stars) and Perplexity Server Deploy (escapeWu/perplexity-ai, 170 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Image Repo Mapping?
openshift-eng (a GitHub organization) maintains it in openshift-eng/ai-helpers, which has 120 GitHub stars. The repository holds 118 skills in this directory. The repository was last updated on October 6, 2026.
Source: openshift-eng/ai-helpers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.