用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/cxcscmu/SkillLearnBench --skill trivy-offline-scanning命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
基于 SOC 职业分类
| name | trivy-offline-scanning |
| description | Use Trivy for offline vulnerability scanning of dependency files like package-lock.json. |
Trivy can be used to scan dependency files (e.g. package-lock.json) offline without updating its database or querying the network for dependency analysis.
To scan a file like package-lock.json and output the results as a JSON file, use the following command:
trivy fs --skip-db-update --offline-scan --format json --output trivy-report.json <path-to-file>
fs: Scan a filesystem path or a specific file.--skip-db-update: Prevents Trivy from attempting to update the vulnerability database, crucial for offline scanning.--offline-scan: Prevents Trivy from issuing API requests to identify dependencies.--format json: Formats the output as JSON for easier programmatic parsing.--output trivy-report.json: Saves the output to the specified file.This approach ensures zero network calls during the analysis of dependency manifests.