Trivy audit
Performing offline security audits on package-lock.json files using Trivy.From its SKILL.md
npx -y skills add cxcscmu/SkillLearnBench --skill trivy-auditAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
SKILL.md
0.5 KB, 100 tokens by cl100k_base, as published. Nobody here has run it
Purpose
Identify vulnerabilities in node.js projects by scanning package-lock.json with Trivy.
Workflow
- Ensure the Trivy database is available (e.g., at
~/.cache/trivy/db/trivy.db). - Run scan in offline mode:
trivy fs --offline --db-repository /root/.cache/trivy/db package-lock.json --format json --output report.json - Parse the output for HIGH/CRITICAL vulnerabilities.
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.