Dockerfile / Containerfile / compose analysis plus optional Trivy / Grype / Syft composition when those binaries are present. Use when reviewing a Dockerfile PR, gating `docker build`, building an image SBOM, evaluating base-image risk, or auditing a registry image for CVEs.
日本語の概要は準備中です。原文の説明を表示しています。
Vulnetix/pix-ai-coding-assistant☆ 92026年9月28日 更新
Show what this repository has already decided about its vulnerabilities, read from the durable record rather than by scanning again — open versus resolved, the decision taken on each, and what is still waiting. Use when picking up triage after a break, auditing past decisions, onboarding to a repository with security history, or checking nothing high-severity is open before a release.
日本語の概要は準備中です。原文の説明を表示しています。
Vulnetix/pix-ai-coding-assistant☆ 92026年9月28日 更新
Dependency-conflict resolution when a `fix` version bump fails — diagnose the peer-dep tree, find a compatible safe version set, propose package-manager overrides (`overrides`/`resolutions`/`replace`/`[patch]`), fall back to safe-harbour inline patching. Use when an upgrade is blocked by transitive constraints, a peer-dep conflict surfaces, or you need to override a vulnerable transitive without bumping the parent.
日本語の概要は準備中です。原文の説明を表示しています。
Vulnetix/pix-ai-coding-assistant☆ 92026年9月28日 更新
Work through which package to add for a capability, and what each option costs — maintenance, licence, bundle weight, transitive risk, and whether the platform already does it. Use when someone needs a library for a job and has not picked one yet, when weighing two candidates, or when a package looks convenient but unmaintained.
日本語の概要は準備中です。原文の説明を表示しています。
Vulnetix/pix-ai-coding-assistant☆ 92026年9月28日 更新
IDS/IPS detection content for a CVE — Snort/Suricata-compatible rules, YARA signatures, ProjectDiscovery Nuclei templates, traffic-filter rules. Capability-aware: skips families when the binary is not installed (no Snort = no Snort output). Use when deploying defences for a CVE without a patch, augmenting SAST with active detection, or feeding the SOC engineering pipeline.
日本語の概要は準備中です。原文の説明を表示しています。
Vulnetix/pix-ai-coding-assistant☆ 92026年9月28日 更新
Generate a runnable exploit-validation command (Nuclei template, Metasploit module hint, AI-assisted Python script, or curl-based PoC) against a user-specified authorised target. Use when validating that a fix actually closed the vulnerability path, confirming a patch deployed correctly, or producing a copy-pasteable test command for QA. The skill never executes — the user runs.
日本語の概要は準備中です。原文の説明を表示しています。
Vulnetix/pix-ai-coding-assistant☆ 92026年9月28日 更新