Forensify
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
A skill your agent uses when /compliance:analyze-cve is invoked with --jira= or --jql= and needs the CVE ID, image name, branch, and enriched ticket context from a Jira issue.
$ npx skills add openshift-eng/ai-helpers --skill jira-cve-extraction -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install openshift-eng/ai-helpers jira-cve-extraction --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/compliance/skills/jira-cve-extraction .claude/skills/jira-cve-extraction && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "jira-cve-extraction" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/jira-cve-extraction into .claude/skills/jira-cve-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jira-cve-extraction", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/jira-cve-extractionType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add openshift-eng/ai-helpers --skill jira-cve-extraction -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install openshift-eng/ai-helpers jira-cve-extraction --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/compliance/skills/jira-cve-extraction .agents/skills/jira-cve-extraction && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "jira-cve-extraction" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/jira-cve-extraction into .agents/skills/jira-cve-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jira-cve-extraction", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openshift-eng/ai-helpers --skill jira-cve-extraction -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install openshift-eng/ai-helpers jira-cve-extraction --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/compliance/skills/jira-cve-extraction .cursor/skills/jira-cve-extraction && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "jira-cve-extraction" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/jira-cve-extraction into .cursor/skills/jira-cve-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jira-cve-extraction", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/openshift-eng/ai-helpers.git --path plugins/compliance/skills/jira-cve-extraction--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add openshift-eng/ai-helpers --skill jira-cve-extraction -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install openshift-eng/ai-helpers jira-cve-extraction --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/compliance/skills/jira-cve-extraction .gemini/skills/jira-cve-extraction && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "jira-cve-extraction" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/jira-cve-extraction into .gemini/skills/jira-cve-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jira-cve-extraction", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install openshift-eng/ai-helpers jira-cve-extractionInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add openshift-eng/ai-helpers --skill jira-cve-extraction -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/compliance/skills/jira-cve-extraction .github/skills/jira-cve-extraction && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "jira-cve-extraction" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/jira-cve-extraction into .github/skills/jira-cve-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jira-cve-extraction", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openshift-eng/ai-helpers --skill jira-cve-extraction -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install openshift-eng/ai-helpers jira-cve-extraction --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/compliance/skills/jira-cve-extraction .opencode/skills/jira-cve-extraction && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "jira-cve-extraction" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/compliance/skills/jira-cve-extraction into .opencode/skills/jira-cve-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "jira-cve-extraction", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
jira-cve-extractionA skill your agent uses when /compliance:analyze-cve is invoked with --jira= or --jql= and needs the CVE ID, image name, branch, and enriched ticket context from a Jira issue.
Jira Cve Extraction is an agent skill from openshift-eng/ai-helpers. Use when /compliance:analyze-cve is invoked with --jira= or --jql= and needs the CVE ID, image name, branch, and enriched ticket context from a Jira issue.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Vulnerability scanning. It works with Jira and Model Context Protocol. The repository describes itself as: Developer productivity tools for Claude Code & other AI assistants. The licence is Apache-2.0.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit a627176. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
JIRA_API_TOKENJIRA_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Jira Cve Extraction loads about 3.3k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 1,372 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from openshift-eng/ai-helpers at commit a627176, republished under its Apache-2.0 licence (© openshift-eng). 1,372 words, ~3,301 tokens.
.claude/skills/jira-cve-extraction/SKILL.md (or your agent's skills folder).Fetches a Jira ticket and extracts three things:
cve-intelligence-gathering)image-repo-mapping skill to resolve which repo to cloneKey insight: Security tracking tickets (e.g.
OCPBUGSCVE trackers) follow a consistent summary format:CVE-YYYY-NNNNN <component>: <description> [<version>]. Parsing the summary is the most reliable single extraction path and should always be tried first — it typically yields the CVE ID, image name, and branch in one step.
Use this skill when the user invokes /compliance:analyze-cve with --jira=PROJ-NNN or --jql="...".
Use the Atlassian Rovo MCP tools bundled with the jira plugin (or an equivalent Atlassian MCP server configured for this Claude Code instance):
getJiraIssue — fetch a single ticketsearchJiraIssuesUsingJql — fetch a batch of tickets (Phase 0.3 / idempotency lookups)editJiraIssue — update labels (idempotency marker)If the MCP server is unavailable: jira issue get <TICKET> and jira issue edit <TICKET> --label ... (from go-jira). Requires ~/.jira.d/config.yml configured for the target Jira instance.
Credential rule: Never print, echo, or log any token, password, or key value — not in shell commands, not in model responses, not in debug output. Reference credentials only via environment variable names (e.g.
$JIRA_API_TOKEN).
PROJECT-NNNNN e.g. OCPBUGS-12345, CNTRLPLANE-678Pattern: ^[A-Z]+-[0-9]+$
issue = getJiraIssue(issue_key="PROJ-12345")Fallback (jira-cli):
jira issue get PROJ-12345Error Handling:
AUTO_APPROVE=no, prompt user to authenticate and retry. IF AUTO_APPROVE=yes, exit with error — there is no credential to fix automatically.AUTO_APPROVE=no, ask the user to supply the CVE ID manually and skip the enrichment. IF AUTO_APPROVE=yes, exit with error (never gated — cannot fabricate ticket data).Inspect the ticket's labels list from the response above. Check whether ai-cve-analyzed is present (case-sensitive exact match). This check always runs here regardless of entry point (--jira= direct or --jql= batch mode) — it is the authoritative guard against re-processing.
labels = issue["fields"]["labels"] # list of strings
if "ai-cve-analyzed" in labels:
# Already processed — exit immediatelyIF label is present → Stop immediately and output:
⚠️ Skipping analysis — this ticket has already been processed by /compliance:analyze-cve.
Ticket: <JIRA_KEY>
Label: ai-cve-analyzed
To force a re-analysis, remove the label from the ticket and re-run.Return status: skipped and exit. Do not proceed with analysis.
IF label is absent → Continue to Step 3.
The ticket summary follows this common format:
CVE-YYYY-NNNNN <image-name>: <vulnerability description> [<branch-or-version>]Example:
CVE-2024-45338 openshift4/ose-operator-sdk-rhel9: some-lib: vulnerability description [openshift-4.17]Parse with:
^(CVE-\d{4}-\d{4,})\s+([\w/:\-\.@]+)\s*:.*\[([\w\.\-]+)\]
group 1 = CVE ID
group 2 = image name
group 3 = branch/versionThis is the primary and most reliable extraction path. If this succeeds, groups 1 and 2 are immediately available — no further searching needed for CVE ID or image name.
CVE_ID, IMAGE_NAME, BRANCH → skip to Step 5Try in order until both CVE_ID and IMAGE_NAME are found:
CVE ID fallbacks:
CVE ID custom field, if the project has one — always accurate when presentCVE-\d{4}-\d{4,} exactlyCVE-\d{4}-\d{4,} patternImage name fallbacks:
pscomponent: label — parse pscomponent:<image-name> from the labels list; strip the pscomponent: prefixDownstream Component Name custom field, if the project has one — dedicated field mapping directly to the affected imageopenshift4/, cert-manager/, external-secrets-operator/, zero-trust-workload-identity-manager/, redhat-user-workloads/)Multiple CVE IDs found: List all found. IF AUTO_APPROVE=no → ask the user which to analyze (or analyze all with confirmation). IF AUTO_APPROVE=yes → always exit with error listing the candidates and asking the caller to re-run with a direct <CVE-ID> argument (or a ticket/JQL that resolves to a single CVE). This case is never gated by AUTO_APPROVE — guessing which CVE to analyze is a correctness risk.
Decision Point:
AUTO_APPROVE=no, ask the user to supply it manually; if declined → Exit. IF AUTO_APPROVE=yes, there is no one to ask → Exit immediately with error (never gated by AUTO_APPROVE).IMAGE_NAME blank; Phase 0.7 will prompt the user for --repo= (or hard-fail if AUTO_APPROVE=yes, per its own rules) — this is never guessed.Read the following fields from the ticket response. Field names vary by Jira instance/project — look them up by display name if the custom field ID is unknown (e.g. via issue-type field metadata), rather than hardcoding an ID that may not match this instance.
| Field | Typical location | Notes |
|---|---|---|
| Status | fields.status.name | |
| Priority | fields.priority.name | Blocker/Critical → urgency escalation |
| Assignee | fields.assignee.displayName | |
| Components | fields.components[].name | |
| Labels | fields.labels[] | Full label list — needed intact for Step 4.5 of report-to-jira |
| Affects versions | fields.versions[].name | |
| Fix versions | fields.fixVersions[].name | |
| Target version | project-specific custom field (e.g. "Target Version") | |
| CVSS Score | custom field named "CVSS Score" | Format often 7.5 CVSS:3.1/AV:N/... — extract score and vector separately |
| CWE ID | custom field named "CWE ID" | e.g. CWE-409 |
| Embargo Status | custom field named "Embargo Status" | True/False — security-critical, see Step 5.5 |
| Downstream Component Name | custom field named "Downstream Component Name", if the project has one | Redundant image name source — cross-check against the summary/label extraction |
| Release Note Text | custom field named "Release Note Text" | May already describe the fix |
| Description | fields.description | Scan for workaround/mitigation keywords |
Scan description for workarounds: look for sections or sentences containing "workaround", "mitigation", "disable", "restrict" — extract the first ~300 chars of any such passage.
Linked issues:
issue["fields"]["issuelinks"] # each has inwardIssue/outwardIssue + type.nameRead the Embargo Status custom field from the ticket (if the project defines one).
True (case-insensitive) → immediately stop all processing and return:❌ Embargoed CVE — cannot proceed.
This ticket is marked as embargoed. Embargoed CVEs must not be
analysed, disclosed, or shared outside authorised channels.
Exit.False, empty, or the field does not exist on this project → Continue to Step 6.The BRANCH value extracted in Step 3/4 (e.g. openshift-4.17, ztwim-1.0) uses a different naming convention from actual git branches. Resolve it before Phase 0.7 clones anything — do not pass the raw Jira value straight to git clone -b.
Pattern A components (direct repo — Operator SDK, Ansible Operator, must-gather, Secrets Store CSI):
Jira BRANCH value | git_branch to use |
|---|---|
openshift-X.Y | release-X.Y (e.g. openshift-4.17 → release-4.17) |
openshift-X.Y.z | release-X.Y.z |
Anything else (e.g. ztwim-1.0, main) | Use verbatim — Pattern B components resolve their own release-repo branch inside image-repo-mapping |
Set git_branch to the resolved value and git_branch_source to jira_summary. Phase 0.7 uses git_branch directly for the -b flag when cloning a Pattern A repo. For a Pattern B component (cert-manager, ESO, ZTWIM), pass the raw BRANCH value through unchanged — image-repo-mapping's own branch table (e.g. cert-manager-X-Y → release-X.Y in the release repo) is what actually resolves it, and applying this Pattern A table first would corrupt it.
If BRANCH was not extracted (no Jira ticket, or the ticket didn't have a parseable version/branch token): leave git_branch unset — Phase 0.7 clones the repository's default branch and notes this in the report.
{
"skill": "jira-cve-extraction",
"status": "success",
"cve_id": "CVE-YYYY-NNNNN",
"image_name": "openshift4/ose-operator-sdk-rhel9",
"branch": "openshift-4.17",
"jira_context": {
"ticket_key": "PROJ-NNNNN",
"ticket_url": "https://<jira-host>/browse/PROJ-NNNNN",
"summary": "CVE-YYYY-NNNNN openshift4/ose-operator-sdk-rhel9: <lib>: <description> [openshift-4.17]",
"status": "New",
"priority": "Major",
"assignee": "<assignee-display-name>",
"components": ["<component>"],
"labels": ["CVE-YYYY-NNNNN", "SecurityTracking", "pscomponent:openshift4/ose-operator-sdk-rhel9"],
"affects_versions": ["4.17"],
"fix_versions": [],
"target_versions": [],
"cvss_score": "7.5",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"cwe_id": "CWE-NNN",
"embargo_status": "False",
"downstream_component_name": "openshift4/ose-operator-sdk-rhel9",
"internal_notes": "",
"release_note_text": "",
"linked_issues": []
},
"analysis_hints": {
"urgency_override": null,
"workaround_present": false,
"cve_extraction_source": "summary",
"image_extraction_source": "summary",
"git_branch": "release-4.17",
"git_branch_source": "jira_summary"
}
}cve_extraction_source values: summary, custom_field, label, description, user_provided
image_extraction_source values: summary, pscomponent_label, downstream_component_field, description, user_provided
| Situation | Action |
|---|---|
| Ticket not found (404) | Exit with error: "Ticket not found or access denied" |
| Auth failure | Prompt to authenticate and retry (or exit if AUTO_APPROVE=yes) |
| No CVE ID in ticket | AUTO_APPROVE=no: ask user to supply manually. AUTO_APPROVE=yes: exit with error (never gated). |
| No image name in ticket | Leave blank; Phase 0.7 will prompt for --repo= (or hard-fail if AUTO_APPROVE=yes) |
| Multiple CVEs | List all. AUTO_APPROVE=no: ask user which to analyze. AUTO_APPROVE=yes: exit with error (never gated). |
Embargo True | Stop immediately. Return error: "This ticket is under embargo. Embargoed CVEs must not be analysed or disclosed outside authorised channels. Exiting." |
Label ai-cve-analyzed present | Stop immediately. Return status: skipped — ticket already processed. |
Called from Phase 0.5 of the analyze-cve skill, only when --jira= or --jql= was provided.
Output is used as:
cve_id → Phase 1 (cve-intelligence-gathering)image_name → Phase 0.7 via the image-repo-mapping skill to resolve the clone URLanalysis_hints.git_branch → Phase 0.7 Step 3 — the -b flag for git clone (Pattern A) or the release-branch lookup (Pattern B)jira_context → Phase 1 (merged into vulnerability profile) + Phase 3 report "Jira Context" sectionjira_context.cvss_score + cvss_vector → seeds Phase 1 before NVD lookupanalysis_hints.urgency_override → can escalate the final risk levelanalysis_hints.workaround_present → noted in Phase 4 remediation planjira_context.ticket_key → becomes SOURCE_TICKET for report-to-jira (Phase 4) and create-fix-pr (Phase 6)© openshift-eng, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/compliance/skills/jira-cve-extraction of openshift-eng/ai-helpers.
Open the folder on GitHubat commit a627176
Jira Cve Extraction next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Jira Cve Extraction this skillopenshift-eng/ai-helpers | 120 | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| Forensifyalexgreensh/repo-forensics | 190 | — | ~2.5k | Automated safety check: Notes | Custom licence | |
| Upgrade Notesgetknit/knit | 133 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | |
| Security Assessmentamd/gaia | 1.6k | — | ~1.8k | Automated safety check: Pass | MIT | |
| Osv Dependency Scandeonmenezes/mantishack | 503 | — | ~298 | Automated safety check: Pass | Apache-2.0 | |
| Skill InspectorNVIDIA/SkillSpector | 20k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 |
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
getknit/knit
Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool.
amd/gaia
Assess a reported security vulnerability in GAIA and fill a PSIRT / JIRA triage: decide if it is valid & exploitable, whether it needs a CVE + bulletin, and produce the CVSS 4.0 score, CWE, and CVE…
deonmenezes/mantishack
Run osv-scanner via the mantisosvscanner MCP server for SCA (vulnerable dependency) findings
NVIDIA/SkillSpector
Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.
vulnersCom/api
A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.
openshift-eng/ai-helpers
Find and independently validate actionable reliability defects across OpenShift release jobs and presubmits, then export portable issue handoffs.
openshift-eng/ai-helpers
Fetch and address all PR review comments — categorize by priority, make code changes, post replies, and push.
openshift-eng/ai-helpers
Categorize Jira issues into Red Hat Sankey Activity Type categories using MCP Jira tools.
openshift-eng/ai-helpers
Decide whether a GitHub PR has unanswered authorized review comments or new required CI failures worth a follow-up agent.
openshift-eng/ai-helpers
Analyze OpenShift must-gather diagnostic data including cluster operators, pods, nodes, and network components.
openshift-eng/ai-helpers
Schema for the autodl JSON data file produced by payload-analysis for database ingestion — you must use this skill whenever generating the autodl JSON file
Works with
Categories
A skill your agent uses when /compliance:analyze-cve is invoked with --jira= or --jql= and needs the CVE ID, image name, branch, and enriched ticket context from a Jira issue. Jira Cve Extraction is an agent skill from openshift-eng/ai-helpers. Use when /compliance:analyze-cve is invoked with --jira= or --jql= and needs the CVE ID, image name, branch, and enriched ticket context from a Jira issue.
Jira Cve Extraction fits situations like: /compliance:analyze-cve is invoked with --jira=; --jql= and needs the CVE ID; enriched ticket context from a Jira issue.
Run `npx skills add openshift-eng/ai-helpers --skill jira-cve-extraction -a claude-code`. Or copy the skill folder (plugins/compliance/skills/jira-cve-extraction in openshift-eng/ai-helpers) into .claude/skills/jira-cve-extraction in your project. Claude Code loads it when a task matches its description.
Run `npx skills add openshift-eng/ai-helpers --skill jira-cve-extraction -a codex`. Or copy the skill folder (plugins/compliance/skills/jira-cve-extraction in openshift-eng/ai-helpers) into .agents/skills/jira-cve-extraction in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openshift-eng/ai-helpers --skill jira-cve-extraction -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/jira-cve-extraction, .gemini/skills/jira-cve-extraction, .github/skills/jira-cve-extraction and .opencode/skills/jira-cve-extraction in your project.
Going by SKILL.md and its folder, Jira Cve Extraction needs the command-line tools its instructions call (git) and credentials named JIRA_API_TOKEN and JIRA_KEY. Our summary lists: Python 3; A credential in JIRA_API_TOKEN; A credential in JIRA_KEY.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Jira Cve Extraction is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Jira Cve Extraction: Forensify (alexgreensh/repo-forensics, 190 stars), Upgrade Notes (getknit/knit, 133 stars), Security Assessment (amd/gaia, 1.6k stars) and Osv Dependency Scan (deonmenezes/mantishack, 503 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
openshift-eng (a GitHub organization) maintains it in openshift-eng/ai-helpers, which has 120 GitHub stars. The repository holds 118 skills in this directory. The repository was last updated on October 6, 2026.
Source: openshift-eng/ai-helpers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.