name: snyk description: >- Find and fix vulnerabilities in code and dependencies with Snyk. Use when a user asks to scan for security vulnerabilities, audit npm packages, check Docker images for CVEs, or integrate security into CI/CD. license: Apache-2.0 compatibility: 'Node.js, Python, Go, Java, Docker, IaC' metadata: author: terminal-skills version: 1.0.0 category: devops tags: - snyk - vulnerability - dependencies - docker - ci-cd
Snyk
Overview
Snyk finds and fixes vulnerabilities in open-source dependencies, container images, IaC configs, and code. Integrates into CLI, CI/CD, Git repos, and IDEs.
Instructions
Step 1: Setup
npm install -g snyk
snyk auth
Step 2: Scan Dependencies
snyk test # test for vulnerabilities
snyk monitor # continuous monitoring
snyk fix # auto-fix vulnerabilities
Step 3: Container Scanning
snyk container test node:20-alpine
snyk container test my-app:latest --file=Dockerfile
Step 4: IaC Scanning
snyk iac test # scan Terraform, K8s manifests
snyk iac test --report # upload to dashboard
Guidelines
- Free tier: 200 dependency tests/month, unlimited container tests.
- Use
--severity-threshold=highin CI to fail only on critical issues. snyk fixauto-generates PRs with dependency upgrades.- Alternatives: npm audit (basic), GitHub Dependabot (free), Socket.dev (supply chain).
Related skills
Security Audit Scanner
Premium
Security
Analyzes code to detect OWASP Top 10 vulnerabilities.
Claude Codeadvanced
210
87
982
OWASP Security Checklist
Security
Generates application security checklists based on the OWASP Top 10.
claudeCursorWindsurfintermediate
148
41
522
Threat Model Generator
Security
Generates threat model documents with STRIDE analysis.
claudeCursoradvanced
78
23
363