Security-flagged skill
This skill may contain destructive commands. Do not install, copy, download, or run it before reviewing the skill details and source. Use it deliberately and only in contexts you understand.
Scanner findings
highdestructive_command
Managing Openvex
NVIDIA/cluster-readiness-engine/.claude/skills/managing-openvexsecurityOfficial
Official Provider SkillView repo
Use when adding, updating, or removing CVE/GHSA suppressions in `.openvex.json`, or when acting on a finding reported by the weekly image vulnerability scan. Triggers on "VEX", "OpenVEX", ".openvex.json", "suppress CVE", "ignore CVE", "vulnerability suppression", or any request to act on the Slack alert from `Vulnerability Scan (images)`.
Files1 files
SKILL.md421 lines
Loading editor…
Install
RecommendedOne command — your agent picks it up automatically.
Select an AI agent above to see the install command.
or
Manual Install
More stepsDownload the file and paste it into your agent's system prompt.
Skill details
Versionv1.0.0
AuthorNVIDIA
Categorysecurity
Skill IDNVIDIA/cluster-readiness-engine/.claude/skills/managing-openvex
Related skills
Cre TestUse when writing, running, or debugging tests in this repo. Covers the testutil.TestCaseParser golden-file pattern, integration tests, golden file regeneration, and the full verification suite.Release NotesUse when drafting the human-readable highlights summary for an NVCRE
release. Triggers on "release notes", "draft release notes",
"/release-notes", or any request to summarize what shipped since the last
tag into a release announcement.
Resolves the tag range from the GitHub releases API, groups changes into
thematic highlights, and writes a Markdown draft to a temp file for
hand-editing before it is pasted into the release body.Nemoclaw Maintainer Find Review PrFind high-priority open NemoClaw security PRs to review, including competing or superseded candidates.Fix Security IssueImplement an authorized fix for a reviewed security issue and open a PR that closes its issue.Review Security IssueReview an authorized security issue for validity, severity, and a remediation plan.SbomGenerate and manage Software Bill of Materials (SBOMs) for the OpenShell project. Covers SBOM generation with Syft, license resolution via public registries, and CSV export for compliance review. Trigger keywords - SBOM, sbom, bill of materials, license audit, license resolution, generate sbom, sbom csv, dependency license, supply chain, license scan.