skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
mukul975/anthropic-cybersecurity-skills104 installs

performing-container-security-scanning-with-trivy

Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed secrets, and licences, generating CycloneDX or SPDX SBOMs. Use when integrating Trivy into CI/CD, deploying the Trivy Kubernetes operator, scanning non-image targets, or triaging results at scale. Keywords: Trivy, trivy k8s, operator, SBOM, CycloneDX, SPDX, misconfig, secret scanning. Do not use for a single Docker image scan - use scanning-docker-images-with-trivy.

How do I install this agent skill?

npx skills add https://github.com/mukul975/anthropic-cybersecurity-skills --skill performing-container-security-scanning-with-trivy
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    This skill provides a comprehensive interface for using Trivy, a well-known container security scanner. It includes a Python agent that automates vulnerability, secret, and misconfiguration scans, and provides documentation for CI/CD integration. The code uses secure methods for command execution and does not exhibit any malicious behavior.

  • Socketpass

    No alerts

  • Snykpass

    Risk: LOW · No issues

What does this agent skill do?

Performing Container Security Scanning with Trivy

Overview

Trivy is an open-source security scanner by Aqua Security that detects vulnerabilities in OS packages and language-specific dependencies, infrastructure-as-code misconfigurations, exposed secrets, and software license issues across container images, filesystems, Git repositories, and Kubernetes clusters. Trivy generates Software Bill of Materials (SBOM) in CycloneDX and SPDX formats for supply chain transparency. This skill covers comprehensive container image scanning, CI/CD pipeline integration, Kubernetes operator deployment, and scan result triage for security operations.

When to Use

  • When conducting security assessments that involve performing container security scanning with trivy
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • Trivy v0.50+ installed (binary, Docker, or Homebrew)
  • Docker daemon access for local image scanning
  • Container registry credentials for remote image scanning
  • CI/CD platform (GitHub Actions, GitLab CI, Jenkins) for pipeline integration
  • Kubernetes cluster for Trivy Operator deployment (optional)

Steps

Step 1: Scan Container Images

Run vulnerability and secret scanning against container images from local builds or remote registries. Configure severity thresholds and ignore unfixed vulnerabilities.

Step 2: Generate SBOM

Produce CycloneDX or SPDX SBOM documents from scanned images for supply chain compliance and vulnerability tracking across the software lifecycle.

Step 3: Scan IaC and Kubernetes Manifests

Detect misconfigurations in Dockerfiles, Kubernetes YAML, Terraform, and Helm charts using built-in policy checks aligned with CIS benchmarks.

Step 4: Integrate into CI/CD

Add Trivy scanning as a pipeline gate that blocks builds with critical/high vulnerabilities, generates SARIF reports for GitHub Advanced Security, and produces JUnit XML for test dashboards.

Expected Output

JSON/table report listing CVEs with severity, CVSS scores, fixed versions, affected packages, misconfiguration findings, and exposed secrets with file locations.

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/mukul975/anthropic-cybersecurity-skills/performing-container-security-scanning-with-trivy">View performing-container-security-scanning-with-trivy on skillZs</a>