smithery/toan203

osv-ui

Security auditing skill for scanning CVE vulnerabilities across npm, Python, Go, and Rust projects using osv-ui. Opens a visual browser dashboard for human review, then applies fixes with explicit confirmation.

Installation

$ npx skills add smithery/toan203 --skill osv-ui

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Skill metadata

Parsed from SKILL.md frontmatter.

Version1.0.0

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 2,653 B
  • docs SUMMARY.md 224 B

History

  1. First recorded snapshot · 0 installs

SKILL.md

osv-ui — CVE Audit Skill

Use this skill whenever the user asks to:

  • Audit, scan, or check dependencies for vulnerabilities or CVEs
  • Find security issues in their npm, Python, Go, or Rust project
  • Get a visual security report or dashboard
  • Fix or upgrade vulnerable packages
  • Replace or complement npm audit, pip-audit, Snyk, or Dependabot

When to activate

Activate when the user mentions any of:

  • "audit", "scan", "CVE", "vulnerability", "security", "dependabot", "snyk"
  • "check my packages", "upgrade guide", "fix vulnerabilities"
  • "npm audit", "pip-audit", "cargo audit", "govulncheck"
  • "is my project secure?", "any known issues in my deps?"

Workflow

1 — Scan

# Single service
npx osv-ui --no-open --json ./osv-report.json

# Multiple services
npx osv-ui ./frontend ./api ./worker --no-open --json ./osv-report.json

# Auto-discover
npx osv-ui --discover --no-open --json ./osv-report.json

2 — Present summary

Parse osv-report.json and show:

📊 [project]: [N] packages · 🔴 Critical: N · 🟠 High: N · 🟡 Moderate: N · 🔵 Low: N · Risk: N/100
Top CVEs: [list top 5 by severity with fix version]

3 — Always offer the visual dashboard

"Want to review in a visual dashboard before I apply any fixes?"

npx osv-ui [same paths]
# Opens http://localhost:2003

4 — Show fix commands, get confirmation

Show what will change. NEVER apply without explicit user "yes".

npm install [email protected]      # fixes 4 CVEs
npm install [email protected]    # fixes 3 CVEs

5 — Apply and verify

# Apply fixes
npm install [package@version]

# Re-scan to confirm
npx osv-ui --no-open --json ./osv-report-after.json

Notes

  • Never apply fixes silently — always confirm first
  • Prefer dashboard for 10+ CVEs
  • Alpha/beta/canary versions are never suggested as fix targets
  • Add --offline if OSV.dev is unreachable

Quick reference

npx osv-ui                          # scan current dir
npx osv-ui ./frontend ./api         # multi-service
npx osv-ui --discover               # auto-detect
npx osv-ui --json=report.json --no-open  # export JSON
npx osv-ui --html=report.html --no-open  # export HTML