Scan container images, filesystems, and SBOMs for known vulnerabilities using Anchore Grype. Supports major OS package ecosystems and language-specific packages with EPSS risk scoring and OpenVEX filtering.
Scanned 6/8/2026
Install via CLI
openskills install agentskillexchange/skills---
name: "Grype Container and SBOM Vulnerability Scanner"
slug: "grype-container-sbom-vulnerability-scanner"
description: "Scan container images, filesystems, and SBOMs for known vulnerabilities using Anchore Grype. Supports major OS package ecosystems and language-specific packages with EPSS risk scoring and OpenVEX filtering."
github_stars: 11985
verification: "security_reviewed"
source: "https://github.com/anchore/grype"
category: "Security & Verification"
framework: "Claude Code"
tool_ecosystem:
github_repo: "anchore/grype"
github_stars: 11985
---
# Grype Container and SBOM Vulnerability Scanner
Scan container images, filesystems, and SBOMs for known vulnerabilities using Anchore Grype. Supports major OS package ecosystems and language-specific packages with EPSS risk scoring and OpenVEX filtering.
## Installation
Requirements and caveats from upstream:
- Supports language-specific packages (Ruby, Java, JavaScript, Python, .NET, Go, PHP, Rust, and [more](https://oss.anchore.com/docs/capabilities/all-packages/))
- Supports Docker, OCI, and [Singularity](https://github.com/sylabs/singularity) image formats
- See [Installation docs](https://oss.anchore.com/docs/installation/grype/) for more ways to get Grype, including Homebrew, Docker, Chocolatey, MacPorts, and more!
Basic usage or getting-started notes:
- New to Grype? Check out the [Getting Started guide](https://oss.anchore.com/docs/guides/vulnerability/getting-started/) for a walkthrough!
- The quickest way to get up and going:
- bash
- Source: https://github.com/anchore/grype
- Extracted from upstream docs: https://raw.githubusercontent.com/anchore/grype/HEAD/README.md
## Source
- [Agent Skill Exchange](https://agentskillexchange.com/skills/grype-container-sbom-vulnerability-scanner/)
No comments yet. Be the first to comment!
Ultra-compressed communication mode. Cuts token usage ~75% by speaking like caveman while keeping full technical accuracy. Supports intensity levels: lite, full (default), ultra, wenyan-lite, wenyan-full, wenyan-ultra. Use when user says "caveman mode", "talk like caveman", "use caveman", "less tokens", "be brief", or invokes /caveman. Also auto-triggers when token efficiency is requested.