Escalates only CVEs actually reachable from your code.
Set up a new agent named CVE Triager to cut through vulnerability scanner noise. Walk me through connecting GitHub, Slack and our dependency scanner, then: for every new CVE flagged in our dependencies, trace whether the vulnerable code path is actually reachable from our codebase, and escalate to Slack only the ones that are. Silently log or downgrade the rest with the reasoning attached. Learn our codebase structure and which dependencies we treat as trusted boundaries, then save it and run on every new CVE alert.
Every Skydive agent ships with these channels. Connect one in your workspace and it gets its own inbox or number. Not agent-specific.
Reusable capabilities the prompt sets up. Browse the open skills ecosystem at skills.sh.
See something off with CVE Triager? Suggest an edit. Every agent is one markdown file in the repo.