Automates Aqua Security Trivy scans against Docker images and OCI artifacts to detect CVEs, misconfigurations, and license violations. Integrates with Trivy's JSON/SARIF output for CI-gate decisions and generates remediation reports.
Scanned 6/8/2026
Install via CLI
openskills install agentskillexchange/skills---
name: "Trivy Container Vulnerability Scanner"
slug: "trivy-container-vulnerability-scanner"
description: "Automates Aqua Security Trivy scans against Docker images and OCI artifacts to detect CVEs, misconfigurations, and license violations. Integrates with Trivy's JSON/SARIF output for CI-gate decisions and generates remediation reports."
github_stars: 34488
verification: "security_reviewed"
source: "https://github.com/aquasecurity/trivy"
category: "Security & Verification"
framework: "Claude Code"
tool_ecosystem:
github_repo: "aquasecurity/trivy"
github_stars: 34488
---
# Trivy Container Vulnerability Scanner
Automates Aqua Security Trivy scans against Docker images and OCI artifacts to detect CVEs, misconfigurations, and license violations. Integrates with Trivy's JSON/SARIF output for CI-gate decisions and generates remediation reports.
## Installation
Requirements and caveats from upstream:
- ![Docker Pulls][docker-pulls]
- docker run aquasec/trivy
- There are canary builds ([Docker Hub](https://hub.docker.com/r/aquasec/trivy/tags?page=1&name=canary), [GitHub](https://github.com/aquasecurity/trivy/pkgs/container/trivy/75776514?tag=canary), [ECR](https://gallery.ec...
Basic usage or getting-started notes:
- ### Get Trivy
- Trivy is available in most common distribution channels. The full list of installation options is available in the [Installation] page. Here are a few popular examples:
- brew install trivy
- Source: https://github.com/aquasecurity/trivy
- Extracted from upstream docs: https://raw.githubusercontent.com/aquasecurity/trivy/HEAD/README.md
## Source
- [Agent Skill Exchange](https://agentskillexchange.com/skills/trivy-container-vulnerability-scanner/)
No comments yet. Be the first to comment!
Ultra-compressed communication mode. Cuts token usage ~75% by speaking like caveman while keeping full technical accuracy. Supports intensity levels: lite, full (default), ultra, wenyan-lite, wenyan-full, wenyan-ultra. Use when user says "caveman mode", "talk like caveman", "use caveman", "less tokens", "be brief", or invokes /caveman. Also auto-triggers when token efficiency is requested.