一键导入
explain
Explain OpenACA findings, Agent BOM entries, scan output, severity, confidence, source provenance, and suggested next steps.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Explain OpenACA findings, Agent BOM entries, scan output, severity, confidence, source provenance, and suggested next steps.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
Generate fast local OpenACA inventory from Claude Code endpoint or project configuration without running advisory lookups.
Run OpenACA scans from Claude Code when the user asks to scan agent components, check Claude Code configuration, inspect MCP servers/plugins/skills/hooks, or assess agent supply-chain risk.
Configure, check, or run explicit OpenACA Cloud sync for a Claude Code endpoint.
Guide agent supply-chain triage after Claude Code MCP, plugin, skill, hook, command, or settings changes.
Generate an OpenACA Agent BOM when the user asks for a bill of materials, Agent BOM, inventory export, or structured list of agent components.
基于 SOC 职业分类
| name | explain |
| description | Explain OpenACA findings, Agent BOM entries, scan output, severity, confidence, source provenance, and suggested next steps. |
| argument-hint | [finding text, advisory id, or BOM component] |
| allowed-tools | ["Bash","Read"] |
Use this skill when the user asks what an OpenACA finding means, why a component was reported, how severe an issue is, or what to do next.
For each finding, explain:
For Agent BOM entries, explain inventory and composition only. Do not turn a BOM entry into a vulnerability unless scan output or an advisory match supports that conclusion.
If the user provides a BOM and wants current advisory matching:
uvx --isolated --from openaca openaca scan bom --input openaca-agent-bom.json -v
scan bom returns advisory matches only. Posture findings need live
configuration (autoapprove lists, remote-auth, endpoint overrides)
that isn't preserved in the BOM — if the user asks about hygiene
findings on a BOM, point them at scan endpoint --include-posture
or scan repo --include-posture instead.
If the user wants a fresh endpoint scan (include posture so the explanation can cover hygiene findings, not just advisory matches):
uvx --isolated --from openaca openaca scan endpoint -v --project . --include-posture
If uvx is unavailable but openaca is installed, use the same command
without the uvx prefix.
Be precise about evidence. "No findings" means no enabled OpenACA rule matched in the scanned scope; it does not prove a component is safe. Avoid overstating posture findings as confirmed compromise.