Skip to content

compliance

Security compliance and vulnerability analysis tools for Go projects

Plugin details

Install

/plugin install compliance@ai-helpers

Skills

Skill Description
analyze-cve Full Go CVE analysis workflow. Given a CVE identifier -- supplied directly, or resolved from a Jira ticket or JQL batch -- resolves and clones the affected repository, gathers vulnerability intelligence, analyzes codebase impact with govulncheck and call-graph reachability, generates a risk report, and optionally applies a fix and opens a GitHub pull request. Use when the user gives a CVE ID (CVE-YYYY-NNNNN), a Jira ticket (--jira=), or a JQL query (--jql=) for Go CVE triage; wants call-graph proof that a vulnerable function is reachable; or wants an automated fix and PR for a Go dependency vulnerability. Triggers on: 'analyze CVE', 'CVE impact', 'is this repo affected by CVE', 'Go vulnerability analysis', 'triage this Jira CVE ticket', 'fix this CVE and open a PR', or a bare CVE-YYYY-NNNNN identifier.
call-graph-analysis Perform definitive call graph analysis to prove whether vulnerable functions are reachable from program entry points
codebase-impact-analysis Analyze a Go codebase to determine if it is impacted by a specific CVE using multiple verification methods and assign a risk level
create-fix-pr Use when opening or updating a GitHub pull request after Phase 5 of /compliance:analyze-cve has applied and verified a CVE fix locally.
cve-intelligence-gathering Gather comprehensive vulnerability information from multiple authoritative sources with fallback strategies
image-repo-mapping Use when resolving which GitHub repository to clone for CVE analysis from a container image name in a Jira ticket summary, pscomponent label, or Downstream Component Name field.
jira-cve-extraction Use when /compliance:analyze-cve is invoked with --jira= or --jql= and needs the CVE ID, image name, branch, and enriched ticket context from a Jira issue.
remediation-planning Generate comprehensive remediation guidance including dependency updates, code changes, workarounds, and verification steps
report-to-jira Use when posting a completed CVE analysis report or PR follow-up as a Jira comment on the source ticket from /compliance:analyze-cve.