About
This skill integrates the open-source Grype vulnerability scanner into your development environment, enabling automated security audits of container images and software dependencies. It provides a comprehensive framework for identifying known vulnerabilities (CVEs) across multiple ecosystems including NPM, Maven, PyPI, and Docker/OCI images. By implementing manual scans, pre-commit hooks, and CI/CD integration, the skill helps developers maintain security compliance and catch critical risks early in the software lifecycle before code reaches production.