pytm
81Build pytm Threat Models as Code
Threat modeling often becomes outdated and disconnected from architecture changes. This skill helps create pytm models, STRIDE analysis, and diagram workflows for security reviews and CI.
Scan Dependencies and Containers with Trivy
Security teams need consistent visibility into vulnerable components, images, and infrastructure configuration. This skill provides practical Trivy workflows for assessment, reporting, and remediation.
This skill is part of a pack
Install the whole pack to get every skill the task needs, in one command.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "sca-trivy" from https://skillstore.io/skills/agentsecops-sca-trivy.md and its manifest at https://skillstore.io/api/skills/agentsecops-sca-trivy/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "sca-trivy". Review a Trivy container scan with critical findings.
Expected outcome:
Using "sca-trivy". Plan dependency scanning for a Node.js repository.
Expected outcome:
Using "sca-trivy". Prepare an SBOM workflow for a release image.
Expected outcome:
All 73 static findings are false positives caused by Markdown code fences, inline code, reference links, and documented configuration paths. Semantic review found mutable CI references, credential exposure guidance, and an ineffective custom-policy gate. These examples require hardening before publication.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
https://skillstore.io/skills/agentsecops-sca-trivy/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/agentsecops-sca-trivy?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/agentsecops-sca-trivy?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/agentsecops-sca-trivy/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/agentsecops-sca-trivy.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>AgentSecOps. (2026). sca-trivy security audit report (audit version 9) [Author version 0.1.0]. Skillstore. https://skillstore.io/skills/agentsecops-sca-trivy/audits/9@techreport{agentsecops-agentsecops-sca-trivy-2026,
author = {AgentSecOps},
title = {sca-trivy security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/agentsecops-sca-trivy/audits/9},
note = {Author version 0.1.0}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "sca-trivy security audit report (audit version 9)"
version: "0.1.0"
type: report
authors:
- name: "AgentSecOps"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/agentsecops-sca-trivy/audits/9"
identifiers:
- type: other
value: "skillstore:agentsecops-sca-trivy:audit:9"
description: "Skillstore immutable audit report identifier"
Scan application manifests, prioritize vulnerable packages, and identify fixed versions before release.
Add Trivy scanning, SARIF reporting, severity thresholds, and controlled exceptions to a delivery pipeline.
Generate SBOMs and summarize vulnerability or license findings for governance reviews.
Scan the current project with Trivy for HIGH and CRITICAL dependency vulnerabilities. Summarize affected packages, fixed versions, and recommended updates.
Assess container image [image:tag] with Trivy. Prioritize exploitable vulnerabilities and recommend patched packages or a safer base image.
Review [IaC path] with Trivy configuration scanning. Group misconfigurations by severity and propose precise changes without modifying files.
Design a CI security gate for [platform] using Trivy SARIF output, immutable action references, severity thresholds, exceptions, and artifact retention.
Author
AgentSecOpsLicense
MIT
Author version
v0.1.0
Skillstore revision
r2
Ref
181fdefcafd96b041926e61c4b2e306ca7e7820e
Maintenance freshness
7/24/2026
Usage
12 downloads ยท 317 views
File structure
๐ SKILL.md
Build pytm Threat Models as Code
Threat modeling often becomes outdated and disconnected from architecture changes. This skill helps create pytm models, STRIDE analysis, and diagram workflows for security reviews and CI.
Secure Dockerfiles with Hadolint
Dockerfile mistakes can create insecure and unreliable container images. This skill provides Hadolint workflows, rule guidance, remediation examples, and reusable CI configurations.
Run Authorized Nuclei Security Scans
Known vulnerabilities and misconfigurations can escape manual review. This skill guides authorized Nuclei scans, template selection, validation, and reporting.
Audit Code with Semgrep
Security flaws can remain hidden across large, multilingual repositories. This skill guides focused Semgrep scans, triage, custom rules, CI gates, and standards-aligned remediation.
Automate OWASP ZAP DAST Scans
Security teams need repeatable runtime testing before releases. This skill guides authorized OWASP ZAP scans, authentication setup, API testing, and CI reporting.
Scan Python Code with Bandit
Python security flaws can reach production unnoticed. This skill guides Bandit scans, prioritization, CI integration, and remediation with CWE and OWASP references.
Scan Dependency Security Risks
by sickn33
Dependency vulnerabilities and license risks are difficult to track across ecosystems. This skill guides scanning, prioritization, SBOM creation, and remediation planning.
Analyze Project Security Risks
by Cornjebus
Security reviews are slow when dependency, container, and IaC data are spread across a repository. This skill inventories assets, checks OSV.dev, and drafts prioritized remediation reports.
Audit Code for Security Risks
by Barnhardt-Enterprises-Inc
Security-sensitive code is easy to ship with hidden flaws in authentication, input handling, and secrets. This skill gives Claude, Codex, and Claude Code structured security references and scanner guidance for safer reviews.
Audit Dependency Security and License Risk
by sickn33
Dependency risk is hard to prioritize across vulnerabilities, licenses, updates, and supply chain signals. This skill guides Claude, Codex, and Claude Code through structured audits and remediation plans.
Validate Project Security
by ByronWilliamsCPA
Security reviews can miss secrets, weak configuration, and dependency risk. This skill guides Claude, Codex, and Claude Code through structured checks and remediation planning.
Review Vulnerability Risk with OWASP Guidance
by sickn33
Security reviews often miss context when findings are listed without attack paths or business risk. This skill combines OWASP guidance, local checks, and prioritization prompts for actionable security work.