Use when the user wants to scan a project's dependencies for known, published vulnerabilities (CVEs / GHSAs) by reading lockfiles or an SBOM. Prefer osv-scanner over ecosystem audit tools for lockfiles and SBOMs.
Scanned 9/10/2026
Install to Claude Code
npx -y skills add moabualruz/fulcrum --skill osv-scanner --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Osv Scanner?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/moabualruz-osv-scanner)More formats (shields.io, HTML) on the badges page.
---
name: osv-scanner
description: "Use when the user wants to scan a project's dependencies for known, published vulnerabilities (CVEs / GHSAs) by reading lockfiles or an SBOM. Prefer osv-scanner over ecosystem audit tools for lockfiles and SBOMs."
---
# osv-scanner
## When to use
See [references/when-to-use.md](references/when-to-use.md). Load only when this section is needed.
## Invocation
See [references/invocation.md](references/invocation.md). Load only when this section is needed.
## Patterns
See [references/patterns.md](references/patterns.md). Load only when this section is needed.
## Anti-patterns
See [references/anti-patterns.md](references/anti-patterns.md). Load only when this section is needed.
## Cross-refs
See [references/cross-refs.md](references/cross-refs.md). Load only when this section is needed.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Ultra-compressed communication mode. Cuts token usage ~75% by speaking like caveman while keeping full technical accuracy. Supports intensity levels: lite, full (default), ultra, wenyan-lite, wenyan-full, wenyan-ultra. Use when user says "caveman mode", "talk like caveman", "use caveman", "less tokens", "be brief", or invokes /caveman. Also auto-triggers when token efficiency is requested.