trivy-security
mguttmann/code-audit-suite/skills/trivy-security/SKILL.md
This skill should be used when the user asks to "run Trivy", "scan dependencies", "check for CVEs", "SCA scan", "Schwachstellen prüfen", "Abhängigkeiten prüfen", "scan a container image", "check Dockerfile/IaC", "generate an SBOM", "Lizenz-Scan", or wants to find vulnerable dependencies, misconfigurations, hardcoded secrets and license issues. Runs Trivy in Docker against a directory or image and drives every finding to zero, processed directly in Claude Code (no dashboard).
Skill0 starsChanged 4 months ago
---
name: trivy-security
description: This skill should be used when the user asks to "run Trivy", "scan dependencies", "check for CVEs", "SCA scan", "Schwachstellen prüfen", "Abhängigkeiten prüfen", "scan a container image", "check Dockerfile/IaC", "generate an SBOM", "Lizenz-Scan", or wants to find vulnerable dependencies, misconfigurations, hardcoded secrets and license issues. Runs Trivy in Docker against a directory or image and drives every finding to zero, processed directly in Claude Code (no dashboard).
version: 0.1.0
---
# Trivy Security
## Purpose
Trivy is the **broad** security scanner that closes SonarQube's biggest blind
spots. SonarQube has effectively no real SCA (no dependency-CVE tracking), no
container/OS-layer scanning, no deep IaC misconfiguration analysis, and no
license inventory. Trivy covers all of these in one binary and its findings are
read and fixed directly in Claude Code.
**This is the single broad scanner — by design, no separate skills exist for
Grype, Syft, OSV-Scanner, Checkmarx KICS, Checkov, or Dockle**, because Trivy
already covers dependency CVEs, SBOM, IaC misconfig, container/OS layers,
secrets and licenses. Avoid running those in parallel; they would duplicate
Trivy.
## What Trivy scans (the delta to SonarQube)
- **vuln** — known CVEs in application dependencies (lockfiles) AND OS packages.
- **secret** — hardcoded credentials/tokens (broader ruleset than SonarQube).
- **misconfig** — IaC misconfiguration: Terraform, Kubernetes, Helm,
Dockerfile, CloudFormation, ARM (includes the former tfsec engine).
- **license** — declared dependency licenses, for policy review.
## Core Workflow (drive to zero)
Run from the project directory and fix until the scan exits clean.
1. **Scan** (human-readable table):
```bash
~/.claude/skills/trivy-security/scripts/scan.sh [TARGET_DIR]
```
2. **Parse machine-readable output** when needed:
```bash
TRIVY_FORMAT=json ~/.claude/skills/trivy-security/scripts/scan.sh [TARGET_DIR]
```
3. **Fix each finding by type:**
- **Vulnerability:** upgrade the dependency to the `Fixed Version` Trivy
reports. If no fix exists, pin/replace the dependency or document the
accepted risk with `.trivyignore`.
- **Misconfig:** correct the IaC (least privilege, no `:latest`, drop root,
resource limits, encryption flags).
- **Secret:** remove the secret AND rotate it (a committed secret is
compromised), then load it from env/secret manager.
- **License:** review against policy; replace dependencies with disallowed
licenses (e.g. GPL/AGPL in proprietary code).
4. **Re-run** until exit code 0 (no findings at the configured severity).
## Scanning a built container image
```bash
docker run --rm -v trivy-cache:/root/.cache/ \
-v /var/run/docker.sock:/var/run/docker.sock \
aquasec/trivy:latest image <image-name>:<tag> --exit-code 1
```
## Notes
- The first run downloads the vulnerability DB; it is cached in the
`trivy-cache` Docker volume for subsequent runs.
- Suppress verified false positives with a `.trivyignore` file (one CVE/ID per
line) — not by lowering severity. Justify each entry.
- The license scanner can be noisy; set `TRIVY_SCANNERS=vuln,secret,misconfig`
for security-only runs, or review licenses separately.
## Resources
- **`scripts/scan.sh`** — runs `trivy fs` with all scanners against a directory,
cached DB, exit 1 on findings. Env: `TRIVY_FORMAT`, `TRIVY_SEVERITY`,
`TRIVY_SCANNERS`.
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
Posts are public.Sign in to post
No one has posted yet. Be the first.

