Agent skill

Jira Cve Extraction

by openshift-eng in openshift-eng/ai-helpers

A skill your agent uses when /compliance:analyze-cve is invoked with --jira= or --jql= and needs the CVE ID, image name, branch, and enriched ticket context from a Jira issue.

Apache-2.0Auto-check passedSecurity

Install Jira Cve Extraction

skills CLI
$ npx skills add openshift-eng/ai-helpers --skill jira-cve-extraction -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openshift-eng/ai-helpers jira-cve-extraction --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/compliance/skills/jira-cve-extraction .claude/skills/jira-cve-extraction && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
jira-cve-extraction
GitHub stars
120
Token cost
~3.3k tokens
SKILL.md length
1,372 words
Files
1
Skills in repo
118
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when /compliance:analyze-cve is invoked with --jira= or --jql= and needs the CVE ID, image name, branch, and enriched ticket context from a Jira issue.

  • Works in 8 steps: Validate Ticket Format → Fetch the Ticket → 5: Idempotency Check — Already Processed? → …
  • /compliance:analyze-cve is invoked with --jira=
  • SKILL.md covers When to Use This Skill, Prerequisites, Implementation Steps and Error Handling, plus 1 more section
  • Calls git; needs JIRA_API_TOKEN and JIRA_KEY

What it does

Jira Cve Extraction is an agent skill from openshift-eng/ai-helpers. Use when /compliance:analyze-cve is invoked with --jira= or --jql= and needs the CVE ID, image name, branch, and enriched ticket context from a Jira issue.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning. It works with Jira and Model Context Protocol. The repository describes itself as: Developer productivity tools for Claude Code & other AI assistants. The licence is Apache-2.0.

When your agent uses it

  • /compliance:analyze-cve is invoked with --jira=
  • --jql= and needs the CVE ID
  • Enriched ticket context from a Jira issue

Example prompts

  • “/jira-cve-extraction”

Requirements

  • Python 3
  • A credential in JIRA_API_TOKEN
  • A credential in JIRA_KEY

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Validate Ticket Format
  2. Fetch the Ticket
  3. 5: Idempotency Check — Already Processed?
  4. Extract CVE ID and Image Name from Summary
  5. Fallback Extraction (when summary doesn't match)
  6. Extract Additional Context Fields
  7. 5: Embargo Check — MUST run before returning
  8. Compile and Return

What it can do on your machine

Read from SKILL.md and the folder at commit a627176. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • JIRA_API_TOKEN
    • JIRA_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Jira Cve Extraction loads about 3.3k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 1,372 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openshift-eng/ai-helpers at commit a627176, republished under its Apache-2.0 licence (© openshift-eng). 1,372 words, ~3,301 tokens.

Download SKILL.mdSave it as .claude/skills/jira-cve-extraction/SKILL.md (or your agent's skills folder).
name
jira-cve-extraction
description
Use when `/compliance:analyze-cve` is invoked with `--jira=` or `--jql=` and needs the CVE ID, image name, branch, and enriched ticket context from a Jira issue.

Jira CVE Extraction

Fetches a Jira ticket and extracts three things:

  1. CVE ID — passed to Phase 1 (cve-intelligence-gathering)
  2. Image name — passed to Phase 0.7 via the image-repo-mapping skill to resolve which repo to clone
  3. Enriched context — CVSS, CWE, priority, target versions, workarounds — embedded in the Phase 3 report and used to seed the CVE profile

Key insight: Security tracking tickets (e.g. OCPBUGS CVE trackers) follow a consistent summary format: CVE-YYYY-NNNNN <component>: <description> [<version>]. Parsing the summary is the most reliable single extraction path and should always be tried first — it typically yields the CVE ID, image name, and branch in one step.

When to Use This Skill

Use this skill when the user invokes /compliance:analyze-cve with --jira=PROJ-NNN or --jql="...".


Prerequisites

Preferred: Atlassian MCP

Use the Atlassian Rovo MCP tools bundled with the jira plugin (or an equivalent Atlassian MCP server configured for this Claude Code instance):

  • getJiraIssue — fetch a single ticket
  • searchJiraIssuesUsingJql — fetch a batch of tickets (Phase 0.3 / idempotency lookups)
  • editJiraIssue — update labels (idempotency marker)
Fallback: jira-cli

If the MCP server is unavailable: jira issue get <TICKET> and jira issue edit <TICKET> --label ... (from go-jira). Requires ~/.jira.d/config.yml configured for the target Jira instance.

Credential rule: Never print, echo, or log any token, password, or key value — not in shell commands, not in model responses, not in debug output. Reference credentials only via environment variable names (e.g. $JIRA_API_TOKEN).


Implementation Steps

Step 1: Validate Ticket Format
PROJECT-NNNNN   e.g. OCPBUGS-12345, CNTRLPLANE-678

Pattern: ^[A-Z]+-[0-9]+$

  • IF invalid → Return error: "Invalid Jira ticket format. Expected PROJECT-NNNNN."
  • IF valid → Continue
Step 2: Fetch the Ticket
python
issue = getJiraIssue(issue_key="PROJ-12345")

Fallback (jira-cli):

bash
jira issue get PROJ-12345

Error Handling:

  • 404 / not found → "Ticket not found. Verify the key and your access."
  • Auth failure → IF AUTO_APPROVE=no, prompt user to authenticate and retry. IF AUTO_APPROVE=yes, exit with error — there is no credential to fix automatically.
  • Network down → IF AUTO_APPROVE=no, ask the user to supply the CVE ID manually and skip the enrichment. IF AUTO_APPROVE=yes, exit with error (never gated — cannot fabricate ticket data).

Step 2.5: Idempotency Check — Already Processed?

Inspect the ticket's labels list from the response above. Check whether ai-cve-analyzed is present (case-sensitive exact match). This check always runs here regardless of entry point (--jira= direct or --jql= batch mode) — it is the authoritative guard against re-processing.

python
labels = issue["fields"]["labels"]   # list of strings
if "ai-cve-analyzed" in labels:
    # Already processed — exit immediately

IF label is present → Stop immediately and output:

⚠️ Skipping analysis — this ticket has already been processed by /compliance:analyze-cve.

Ticket:  <JIRA_KEY>
Label:   ai-cve-analyzed

To force a re-analysis, remove the label from the ticket and re-run.

Return status: skipped and exit. Do not proceed with analysis.

IF label is absent → Continue to Step 3.


Step 3: Extract CVE ID and Image Name from Summary

The ticket summary follows this common format:

CVE-YYYY-NNNNN <image-name>: <vulnerability description> [<branch-or-version>]

Example:

CVE-2024-45338 openshift4/ose-operator-sdk-rhel9: some-lib: vulnerability description [openshift-4.17]

Parse with:

^(CVE-\d{4}-\d{4,})\s+([\w/:\-\.@]+)\s*:.*\[([\w\.\-]+)\]
  group 1 = CVE ID
  group 2 = image name
  group 3 = branch/version

This is the primary and most reliable extraction path. If this succeeds, groups 1 and 2 are immediately available — no further searching needed for CVE ID or image name.

  • IF summary matches → set CVE_ID, IMAGE_NAME, BRANCH → skip to Step 5
  • IF summary does not match → continue to Step 4

Step 4: Fallback Extraction (when summary doesn't match)

Try in order until both CVE_ID and IMAGE_NAME are found:

CVE ID fallbacks:

  1. A dedicated CVE ID custom field, if the project has one — always accurate when present
  2. Labels — look for a label matching CVE-\d{4}-\d{4,} exactly
  3. Description body — scan for CVE-\d{4}-\d{4,} pattern

Image name fallbacks:

  1. pscomponent: label — parse pscomponent:<image-name> from the labels list; strip the pscomponent: prefix
  2. Downstream Component Name custom field, if the project has one — dedicated field mapping directly to the affected image
  3. Description body — scan for known image name prefixes (openshift4/, cert-manager/, external-secrets-operator/, zero-trust-workload-identity-manager/, redhat-user-workloads/)

Multiple CVE IDs found: List all found. IF AUTO_APPROVE=no → ask the user which to analyze (or analyze all with confirmation). IF AUTO_APPROVE=yes → always exit with error listing the candidates and asking the caller to re-run with a direct <CVE-ID> argument (or a ticket/JQL that resolves to a single CVE). This case is never gated by AUTO_APPROVE — guessing which CVE to analyze is a correctness risk.

Decision Point:

  • IF no CVE ID found anywhere → IF AUTO_APPROVE=no, ask the user to supply it manually; if declined → Exit. IF AUTO_APPROVE=yes, there is no one to ask → Exit immediately with error (never gated by AUTO_APPROVE).
  • IF no image name found → leave IMAGE_NAME blank; Phase 0.7 will prompt the user for --repo= (or hard-fail if AUTO_APPROVE=yes, per its own rules) — this is never guessed.

Step 5: Extract Additional Context Fields

Read the following fields from the ticket response. Field names vary by Jira instance/project — look them up by display name if the custom field ID is unknown (e.g. via issue-type field metadata), rather than hardcoding an ID that may not match this instance.

FieldTypical locationNotes
Statusfields.status.name
Priorityfields.priority.nameBlocker/Critical → urgency escalation
Assigneefields.assignee.displayName
Componentsfields.components[].name
Labelsfields.labels[]Full label list — needed intact for Step 4.5 of report-to-jira
Affects versionsfields.versions[].name
Fix versionsfields.fixVersions[].name
Target versionproject-specific custom field (e.g. "Target Version")
CVSS Scorecustom field named "CVSS Score"Format often 7.5 CVSS:3.1/AV:N/... — extract score and vector separately
CWE IDcustom field named "CWE ID"e.g. CWE-409
Embargo Statuscustom field named "Embargo Status"True/False — security-critical, see Step 5.5
Downstream Component Namecustom field named "Downstream Component Name", if the project has oneRedundant image name source — cross-check against the summary/label extraction
Release Note Textcustom field named "Release Note Text"May already describe the fix
Descriptionfields.descriptionScan for workaround/mitigation keywords

Scan description for workarounds: look for sections or sentences containing "workaround", "mitigation", "disable", "restrict" — extract the first ~300 chars of any such passage.

Linked issues:

python
issue["fields"]["issuelinks"]  # each has inwardIssue/outwardIssue + type.name

Show full SKILL.md (505 more words)Show less
Step 5.5: Embargo Check — MUST run before returning

Read the Embargo Status custom field from the ticket (if the project defines one).

  • IF value is True (case-insensitive) → immediately stop all processing and return:
    ❌ Embargoed CVE — cannot proceed.
    
    This ticket is marked as embargoed. Embargoed CVEs must not be
    analysed, disclosed, or shared outside authorised channels.
    
    Exit.
    Do NOT output any CVE details, CVSS scores, image names, or other ticket data.
  • IF value is False, empty, or the field does not exist on this project → Continue to Step 6.

Branch Resolution

The BRANCH value extracted in Step 3/4 (e.g. openshift-4.17, ztwim-1.0) uses a different naming convention from actual git branches. Resolve it before Phase 0.7 clones anything — do not pass the raw Jira value straight to git clone -b.

Pattern A components (direct repo — Operator SDK, Ansible Operator, must-gather, Secrets Store CSI):

Jira BRANCH valuegit_branch to use
openshift-X.Yrelease-X.Y (e.g. openshift-4.17 → release-4.17)
openshift-X.Y.zrelease-X.Y.z
Anything else (e.g. ztwim-1.0, main)Use verbatim — Pattern B components resolve their own release-repo branch inside image-repo-mapping

Set git_branch to the resolved value and git_branch_source to jira_summary. Phase 0.7 uses git_branch directly for the -b flag when cloning a Pattern A repo. For a Pattern B component (cert-manager, ESO, ZTWIM), pass the raw BRANCH value through unchanged — image-repo-mapping's own branch table (e.g. cert-manager-X-Y → release-X.Y in the release repo) is what actually resolves it, and applying this Pattern A table first would corrupt it.

If BRANCH was not extracted (no Jira ticket, or the ticket didn't have a parseable version/branch token): leave git_branch unset — Phase 0.7 clones the repository's default branch and notes this in the report.


Step 6: Compile and Return
json
{
  "skill": "jira-cve-extraction",
  "status": "success",
  "cve_id": "CVE-YYYY-NNNNN",
  "image_name": "openshift4/ose-operator-sdk-rhel9",
  "branch": "openshift-4.17",
  "jira_context": {
    "ticket_key": "PROJ-NNNNN",
    "ticket_url": "https://<jira-host>/browse/PROJ-NNNNN",
    "summary": "CVE-YYYY-NNNNN openshift4/ose-operator-sdk-rhel9: <lib>: <description> [openshift-4.17]",
    "status": "New",
    "priority": "Major",
    "assignee": "<assignee-display-name>",
    "components": ["<component>"],
    "labels": ["CVE-YYYY-NNNNN", "SecurityTracking", "pscomponent:openshift4/ose-operator-sdk-rhel9"],
    "affects_versions": ["4.17"],
    "fix_versions": [],
    "target_versions": [],
    "cvss_score": "7.5",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "cwe_id": "CWE-NNN",
    "embargo_status": "False",
    "downstream_component_name": "openshift4/ose-operator-sdk-rhel9",
    "internal_notes": "",
    "release_note_text": "",
    "linked_issues": []
  },
  "analysis_hints": {
    "urgency_override": null,
    "workaround_present": false,
    "cve_extraction_source": "summary",
    "image_extraction_source": "summary",
    "git_branch": "release-4.17",
    "git_branch_source": "jira_summary"
  }
}

cve_extraction_source values: summary, custom_field, label, description, user_provided image_extraction_source values: summary, pscomponent_label, downstream_component_field, description, user_provided


Error Handling

SituationAction
Ticket not found (404)Exit with error: "Ticket not found or access denied"
Auth failurePrompt to authenticate and retry (or exit if AUTO_APPROVE=yes)
No CVE ID in ticketAUTO_APPROVE=no: ask user to supply manually. AUTO_APPROVE=yes: exit with error (never gated).
No image name in ticketLeave blank; Phase 0.7 will prompt for --repo= (or hard-fail if AUTO_APPROVE=yes)
Multiple CVEsList all. AUTO_APPROVE=no: ask user which to analyze. AUTO_APPROVE=yes: exit with error (never gated).
Embargo TrueStop immediately. Return error: "This ticket is under embargo. Embargoed CVEs must not be analysed or disclosed outside authorised channels. Exiting."
Label ai-cve-analyzed presentStop immediately. Return status: skipped — ticket already processed.

Integration with Parent Command

Called from Phase 0.5 of the analyze-cve skill, only when --jira= or --jql= was provided.

Output is used as:

  • cve_id → Phase 1 (cve-intelligence-gathering)
  • image_name → Phase 0.7 via the image-repo-mapping skill to resolve the clone URL
  • analysis_hints.git_branch → Phase 0.7 Step 3 — the -b flag for git clone (Pattern A) or the release-branch lookup (Pattern B)
  • jira_context → Phase 1 (merged into vulnerability profile) + Phase 3 report "Jira Context" section
  • jira_context.cvss_score + cvss_vector → seeds Phase 1 before NVD lookup
  • analysis_hints.urgency_override → can escalate the final risk level
  • analysis_hints.workaround_present → noted in Phase 4 remediation plan
  • jira_context.ticket_key → becomes SOURCE_TICKET for report-to-jira (Phase 4) and create-fix-pr (Phase 6)

© openshift-eng, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/compliance/skills/jira-cve-extraction of openshift-eng/ai-helpers.

Open the folder on GitHubat commit a627176

Compare with similar skills

Jira Cve Extraction next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Jira Cve Extraction compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Jira Cve Extraction this skillopenshift-eng/ai-helpers120—~3.3kAutomated safety check: PassApache-2.0
Forensifyalexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesCustom licence
Upgrade Notesgetknit/knit133—~1.2kAutomated safety check: PassGPL-3.0
Security Assessmentamd/gaia1.6k—~1.8kAutomated safety check: PassMIT
Osv Dependency Scandeonmenezes/mantishack503—~298Automated safety check: PassApache-2.0
Skill InspectorNVIDIA/SkillSpector20k—~1.8kAutomated safety check: PassApache-2.0

Similar skills

  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    190 GitHub stars~2.5k tokensUpdated 13 days ago
    SecurityAuto-check: notes
  • Upgrade Notes

    getknit/knit

    Read the vendor's breaking changes, deprecations, migration notes and CVEs for every version between the one pinned now and the one being moved to, through the whatsnew MCP server's upgradenotes tool.

    133 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check passed
  • Assess a reported security vulnerability in GAIA and fill a PSIRT / JIRA triage: decide if it is valid & exploitable, whether it needs a CVE + bulletin, and produce the CVSS 4.0 score, CWE, and CVE…

    1.6k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Osv Dependency Scan

    deonmenezes/mantishack

    Run osv-scanner via the mantisosvscanner MCP server for SCA (vulnerable dependency) findings

    503 GitHub stars~298 tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Skill Inspector

    NVIDIA/SkillSpector

    Official

    Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

    20k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.

    376 GitHub stars~2.3k tokensUpdated 11 days ago
    SecurityAuto-check passed

More from openshift-eng/ai-helpers

All 118 skills in this repo
  • Investigate CI Reliability

    openshift-eng/ai-helpers

    Find and independently validate actionable reliability defects across OpenShift release jobs and presubmits, then export portable issue handoffs.

    120 GitHub stars~1.9k tokensUpdated 3 days ago
    Auto-check passed
  • Address Review PR

    openshift-eng/ai-helpers

    Fetch and address all PR review comments — categorize by priority, make code changes, post replies, and push.

    120 GitHub stars~2.9k tokensUpdated 3 days ago
    Auto-check passed
  • Categorize Activity Types

    openshift-eng/ai-helpers

    Categorize Jira issues into Red Hat Sankey Activity Type categories using MCP Jira tools.

    120 GitHub stars~2.4k tokensUpdated 3 days ago
    Auto-check passed
  • Has Review Work

    openshift-eng/ai-helpers

    Decide whether a GitHub PR has unanswered authorized review comments or new required CI failures worth a follow-up agent.

    120 GitHub stars~1.9k tokensUpdated 3 days ago
    Auto-check passed
  • Must Gather Analyzer

    openshift-eng/ai-helpers

    Analyze OpenShift must-gather diagnostic data including cluster operators, pods, nodes, and network components.

    120 GitHub stars~2.3k tokensUpdated 3 days ago
    Auto-check passed
  • Payload Autodl JSON

    openshift-eng/ai-helpers

    Schema for the autodl JSON data file produced by payload-analysis for database ingestion — you must use this skill whenever generating the autodl JSON file

    120 GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Jira Cve Extraction

What does Jira Cve Extraction do?

A skill your agent uses when /compliance:analyze-cve is invoked with --jira= or --jql= and needs the CVE ID, image name, branch, and enriched ticket context from a Jira issue. Jira Cve Extraction is an agent skill from openshift-eng/ai-helpers. Use when /compliance:analyze-cve is invoked with --jira= or --jql= and needs the CVE ID, image name, branch, and enriched ticket context from a Jira issue.

When should I use Jira Cve Extraction?

Jira Cve Extraction fits situations like: /compliance:analyze-cve is invoked with --jira=; --jql= and needs the CVE ID; enriched ticket context from a Jira issue.

How do I install Jira Cve Extraction in Claude Code?

Run `npx skills add openshift-eng/ai-helpers --skill jira-cve-extraction -a claude-code`. Or copy the skill folder (plugins/compliance/skills/jira-cve-extraction in openshift-eng/ai-helpers) into .claude/skills/jira-cve-extraction in your project. Claude Code loads it when a task matches its description.

How do I install Jira Cve Extraction in Codex?

Run `npx skills add openshift-eng/ai-helpers --skill jira-cve-extraction -a codex`. Or copy the skill folder (plugins/compliance/skills/jira-cve-extraction in openshift-eng/ai-helpers) into .agents/skills/jira-cve-extraction in your project. Codex loads it when a task matches its description.

Can I use Jira Cve Extraction in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openshift-eng/ai-helpers --skill jira-cve-extraction -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/jira-cve-extraction, .gemini/skills/jira-cve-extraction, .github/skills/jira-cve-extraction and .opencode/skills/jira-cve-extraction in your project.

What does Jira Cve Extraction need to run?

Going by SKILL.md and its folder, Jira Cve Extraction needs the command-line tools its instructions call (git) and credentials named JIRA_API_TOKEN and JIRA_KEY. Our summary lists: Python 3; A credential in JIRA_API_TOKEN; A credential in JIRA_KEY.

Does Jira Cve Extraction access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Jira Cve Extraction safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Jira Cve Extraction use?

Jira Cve Extraction is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Jira Cve Extraction use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Jira Cve Extraction?

Skills that share tags, products or a category with Jira Cve Extraction: Forensify (alexgreensh/repo-forensics, 190 stars), Upgrade Notes (getknit/knit, 133 stars), Security Assessment (amd/gaia, 1.6k stars) and Osv Dependency Scan (deonmenezes/mantishack, 503 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Jira Cve Extraction?

openshift-eng (a GitHub organization) maintains it in openshift-eng/ai-helpers, which has 120 GitHub stars. The repository holds 118 skills in this directory. The repository was last updated on October 6, 2026.

Source: openshift-eng/ai-helpers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.