vulnerability-scanner

Triage dependency, source, and artifact vulnerabilities into structured release decisions.

108|27|Updated Mar 26, 2026
One-click install
npx skills add https://github.com/diegosouzapw/omni-skills --skill vulnerability-scanner-diegosouzapw
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vulnerability-scanner
Source: https://github.com/diegosouzapw/omni-skills/tree/main/skills/vulnerability-scanner
Command: npx skills add https://github.com/diegosouzapw/omni-skills --skill vulnerability-scanner-diegosouzapw

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Vulnerability scanning workflows are often ad-hoc and noisy; this skill provides a repeatable framework to triage risks across dependencies, source patterns, archives, and release artifacts, turning scattered tool outputs into a clear remediation plan.

Core Features & Use Cases

  • Structured triage: classify findings into exploitable now, context-dependent, false positive, or accepted risk.
  • Deduplicate findings and drive clear release decisions with reproducible scan outputs and a compact packet format.
  • Supports release preflight, hardening passes, CI integration, and container review workflows, guiding operators from discovery to remediation.

Quick Start

Run a vulnerability scan workflow on your project to triage findings and decide release readiness.

Frequently Asked Questions about vulnerability-scanner

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I triage vulnerability scan findings for release preflight?

To triage vulnerability scan findings for release preflight, you classify risks into exploitable, context-dependent, false positive, or accepted risk categories. This structured process deduplicates findings to yield a clear release decision.

What is a reproducible vulnerability scanning workflow for dependencies?

A reproducible vulnerability scanning workflow for dependencies turns scattered tool outputs into a structured remediation plan. It uses reproducible scan packets and scripts to triage risks across Node packages, source patterns, and artifacts.

Can I use this vulnerability scanner for container review and hardening passes?

Yes, you can use this vulnerability scanner for container review and hardening passes. It supports triaging risks across release artifacts and containers, guiding operators from discovery to remediation during CI setups.

How do I deduplicate noisy vulnerability findings across source patterns and archives?

To deduplicate noisy vulnerability findings across source patterns and archives, you apply a structured triage framework. This process classifies findings and consolidates scattered tool outputs into a compact packet format.

What is the best way to generate an SBOM and triage dependency risks?

The best way to generate an SBOM and triage dependency risks is using a repeatable scanning framework. It enforces deduplication and structured classification to produce reproducible scan outputs for release readiness.