用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/G1Joshi/Agent-Skills --skill trivy命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | trivy |
| description | Trivy container security scanner. Use for container security. |
Trivy (by Aqua Security) is a comprehensive and versatile security scanner. It is famous for being incredibly fast, easy to install (single binary), and covering a wide range of targets (Containers, Filesystem, Git repos, AWS).
# Scan a container image
trivy image python:3.4-alpine
# Scan local filesystem (dependencies + secrets + misconfigs)
trivy fs .
# Scan a git repo
trivy repo https://github.com/knqyf263/trivy
Trivy runs multiple scanners in parallel:
Trivy can run standalone (Download DB -> Scan) or in Client/Server mode (Server holds DB, Client connects) for faster CI runs.
Do:
.trivyignore: To suppress false positives or accepted risks.FROM image is clean (e.g., use alpine or distroless).trivy image --format cyclonedx to export an SBOM for compliance.Don't:
| Error | Cause | Solution |
|---|---|---|
DB Download Error | Rate limiting / Network. | Use TRIVY_OFFLINE_SCAN=true if using --skip-db-update inside a restricted network. |
API Rate Limit | GitHub API limit. | Set GITHUB_TOKEN env var for Trivy to use. |