CtrlK
BlogDocsLog inGet started
Tessl Logo

cve-fix

Automated CVE remediation that reads vulnerability details from Jira vulnerability tickets, applies multi-strategy dependency fixes, validates results, and creates pull requests with full justification. Language-agnostic: supports Go, Node.js, Python, Java, Rust, Ruby. Use when patching CVEs, updating vulnerable dependencies, or responding to Jira vulnerability tickets. Activated by commands: /start, /scan, /patch, /validate, /pr, /backport, /close, /report.

SKILL.md
Quality
Evals
Security

CVE Fix Workflow Orchestrator

Quick Start

  1. If the user invoked a specific command (e.g. /patch, /pr), read commands/{command}.md and follow it.
  2. Otherwise, read skills/controller.md to load the workflow controller and begin with /start.

If a step fails or produces unexpected output, stop and report the error to the user. Do not advance to the next phase. Offer to retry the failed step or escalate.

For principles, hard limits, safety, and escalation rules, see guidelines.md.

Repository
flightctl/ai-workflows
Last updated
First committed

Also appears in

amir-yogev-gh/ai-workflows
In sync

since Sep 7, 2026

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.