From odh-ai-helpers
Verifies that a CVE fix resolved the vulnerability by scanning compiled binaries and updated manifests. Catches transitive dep overrides and lockfile conflicts.
How this skill is triggered — by the user, by Claude, or both
Slash command
/odh-ai-helpers:cve-verifysonnetThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
After a fix is applied by `/cve-fix-apply`, verify the CVE is actually resolved
After a fix is applied by /cve-fix-apply, verify the CVE is actually resolved
by scanning the compiled output. Source-level scans can give false negatives
when transitive dependencies override the fixed version at build time.
Run scripts/verify.sh which builds the binary (Go) or regenerates lockfiles
(Node.js) and re-scans for the CVE:
bash scripts/verify.sh "${REPO_DIR}" "${CVE_ID}" "${LANG}" "${TARGET_GO_VERSION:-}" "${BUILD_LOCATION:-.}"
The script:
govulncheck -mode binary (gold standard).
Falls back to source scan if build fails.npm auditpip-auditautofix-output/cve-verify-result.jsonRead autofix-output/cve-verify-result.json and evaluate the verdict field.
| Verdict | Meaning |
|---|---|
fixed | CVE no longer detected — safe to create PR |
still_present | CVE still detected after fix — do NOT create PR |
scan_failed | Verification scan could not run — manual review needed |
Use judgment for edge cases:
still_present: the fix was insufficient. This can happen with transitive
dependency conflicts, Go replace directives overriding the fix, or lockfile
conflicts. Do NOT create a PR — add a Jira comment explaining the fix was
attempted but CVE persists, manual investigation is required.scan_failed: check the scan_output_summary for the root cause. If the
build failed due to the fix itself (e.g., incompatible version), the fix
approach may need to change.The orchestrator reads verdict:
fixed → push branch, create PRstill_present → do NOT create PR, add Jira comment explaining fix was insufficientscan_failed → skip with documentation, manual review neededstill_present verdict means do NOT create a PR — post a Jira comment instead explaining the fix was attempted but the CVE persistsnpx claudepluginhub opendatahub-io/skills-registry --plugin odh-ai-helpersScans a cloned repository for a specific CVE using version-matched toolchains for Go, Node.js, and Python. Writes structured result to a JSON file for automated triage.
Finds and fixes CVEs in Submariner Go repositories by scanning with grype, applying deterministic fixes, running tests, and printing a PR command.
Reviews security fixes and patches for completeness and correctness. Useful for verifying vulnerability remediations after audits or scans.