sca-grype

Run Anchore Grype for SCA vulnerability scanning on filesystems and container images. Matches dependencies against multiple vulnerability databases (NVD, GitHub, OS advisories).

Safety Notice

This listing is imported from skills.sh public index metadata. Review upstream SKILL.md and repository scripts before running.

Copy this and send it to your AI assistant to learn

Install skill "sca-grype" with this command: npx skills add vchirrav/product-security-ai-skills/vchirrav-product-security-ai-skills-sca-grype

SCA Scan with Grype

You are a security engineer running Software Composition Analysis (SCA) using Grype to detect known vulnerabilities in dependencies and container images.

When to use

Use this skill when asked to scan a project or container image for dependency vulnerabilities. Grype supports both filesystem and container image scanning.

Prerequisites

  • Grype installed (curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sh -s -- -b /usr/local/bin)
  • Verify: grype version

Instructions

  1. Identify the target — Determine if scanning a directory or container image.

  2. Run the scan:

    Filesystem:

    grype dir:<target-path> -o json > grype-results.json
    

    Container image:

    grype <image-name>:<tag> -o json > grype-results.json
    
    • Filter by severity: grype dir:. --fail-on high -o json
    • Specific SBOM: grype sbom:sbom.json -o json
  3. Parse the results — Read JSON output and present findings:

| # | Severity | CVE | Package | Installed | Fixed | Type | Description |
|---|----------|-----|---------|-----------|-------|------|-------------|
  1. Summarize — Provide:
    • Total vulnerabilities by severity (Critical/High/Medium/Low/Negligible)
    • Actionable upgrade paths for Critical and High findings
    • Whether any vulnerabilities have known exploits

Source Transparency

This detail page is rendered from real SKILL.md content. Trust labels are metadata-based hints, not a safety guarantee.

Related Skills

Related by shared tags or category signals.

Security

network-scan-nmap

No summary provided by upstream source.

Repository SourceNeeds Review
Security

malware-scan-yara

No summary provided by upstream source.

Repository SourceNeeds Review
Security

mobile-security-mobsf

No summary provided by upstream source.

Repository SourceNeeds Review
Security

dast-nuclei

No summary provided by upstream source.

Repository SourceNeeds Review