openclaw-skills/vuls-linux-cve-scanner/SKILL.md
用于通过 Vuls 对 Linux、FreeBSD、容器、WordPress、库和网络设备执行 Agentless CVE 扫描。
npx skillsauth add seaworld008/commonly-used-high-value-skills vuls-linux-cve-scannerInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill when the user wants Linux or FreeBSD host vulnerability scanning, agentless CVE assessment over SSH, local host scans, package patch status review, or server fleet vulnerability reporting with Vuls.
Good trigger phrases:
Before scanning hosts, confirm:
Never scan hosts outside the user's authorized scope.
Use:
Vuls needs vulnerability intelligence before reliable scanning. Depending on setup, prepare:
With Vulsctl-style Docker workflows, use the official tutorial commands as the source of truth and avoid inventing feed paths.
Create a minimal target config:
[servers]
[servers.web01]
host = "web01.example.com"
port = "22"
user = "scanuser"
keyPath = "/home/scanner/.ssh/id_ed25519"
Keep credentials outside the repository. Use SSH agent or secure secret storage.
Example flow:
vuls configtest
vuls scan
vuls report
For local host workflows, follow the installed Vuls version's local scan syntax and document the exact command used.
For each host:
Prioritize:
sudo apt-get update
sudo apt-get upgrade --with-new-pkgs
sudo needrestart
sudo dnf update --security
sudo needs-restarting -r
## Host CVE Scan Summary
- Scan date:
- Scanner:
- Targets:
- Critical:
- High:
- Reboot required:
- Unsupported hosts:
- Top packages to patch:
- Exceptions:
## Accepted Host Vulnerability
- Host:
- CVE:
- Package:
- Reason:
- Compensating control:
- Owner:
- Review date:
tools
飞书审批:查询和处理审批待办/已办/实例,搜索可发起审批定义、查看定义详情并发起原生审批实例。当用户要处理审批任务、查看审批实例、搜索或发起审批时使用。审批待办不是飞书任务;非审批类待办走 lark-task。不负责创建审批定义;三方审批定义不走原生提单。
development
Use when a user needs reproducible repository sizing, language composition, file counts, or code-versus-comment ratios with pygount; record exclusions and verify measurement scope before interpreting results.
development
Route a development task to the official Hermes Agent skill, Graphify Codex artifact set, Open GSD Core bundle, or optional GSD Pi bundle without duplicating their installers or state machines.
development
飞书 / Lark 通讯录:按姓名 / 邮箱解析成 open_id,或按 open_id 反查姓名 / 部门 / 邮箱 / 联系方式 / 个人状态 / 签名,以及按关键词搜索当前用户可见的机器人 / 智能体(agent)。当用户提到一个名字要下一步发消息 / 排日程,或拿到 open_id 想查具体信息时使用。不负责部门树遍历、按部门列员工、组织架构图,这类需求走原生 OpenAPI。