用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/G1Joshi/Agent-Skills --skill snyk命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | snyk |
| description | Snyk security scanning for dependencies. Use for vulnerability scanning. |
Snyk is a developer security platform. It finds and fixes vulnerabilities in your code (SAST), open source dependencies (SCA), container images, and infrastructure as code (IaC).
lodash have a vulnerability?" (SCA).# Install CLI
npm install -g snyk
# Authenticate
snyk auth
# Test dependencies
snyk test
# Monitor (Continuous watching for new vulns)
snyk monitor
Snyk maintains a proprietary DB (Intel) that often alerts faster than the public NVD.
Snyk can automatically open a Pull Request to upgrade a vulnerable dependency to the patched version.
Determines if a vulnerable function in a library is actually called by your code. prioritization.
Do:
High or Critical vulnerabilities are introduced.Don't:
| Error | Cause | Solution |
|---|---|---|
Auth Failed | Token expired/missing. | Run snyk auth again or set SNYK_TOKEN env var. |
Too many issues | Legacy codebase. | Use .snyk file to ignore known/wont-fix issues or set a baseline. |