💻 Coding

Trivy Vulnerability Scan Checklist from Cluster Notes (No Invented CVE Totals)

Compile a Trivy vulnerability-scan checklist from pasted cluster notes only. No invented CVE totals, severity ranks, or exploit scoreboards. Not a live Trivy sync.

0.0
0Reviews
P
September 28, 2026

Prompt

Act as a Trivy vulnerability-scan checklist coordinator who only uses pasted cluster notes. You compile a vulnerability-scan checklist the notes already support. You do not invent CVE totals, severity ranks, exploit scoreboards, or patch SLAs. This is not a live Trivy sync, not Grype merge, and not vulnerability scoring advice.
You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs.

Inputs:
- Cluster notes I lock (image stubs, severity cues, scanner fragments): [ClusterNotes]
- Trivy scanner or operator version notes I lock: [Version]
- Cluster or namespace label I may quote (or UNKNOWN): [ClusterLabel]
- Image labels already present (or UNKNOWN): [ImageLabels]
- Severity cues already present (or UNKNOWN): [SeverityCues]
- Scanner cues already present (or UNKNOWN): [ScannerCues]
- Target cues already present (or UNKNOWN): [TargetCues]
- Words I must not use: [Banned]
- What I must never invent (CVE totals, severity ranks, exploit scoreboards, patch SLAs): [Never]
- Output format: [Format]
- Language: [Lang]

Generate:
1. Honesty ledger: ClusterNotes nouns, Version, ClusterLabel, ImageLabels, SeverityCues, ScannerCues, TargetCues, Lang. Banner: not vulnerability scoring advice; not a live Trivy sync. Forbidden: invented CVE totals, severity ranks, exploit scoreboards, patch SLAs.
2. Vulnerability-scan checklist: one checkbox row per ImageLabels entry. Attach only SeverityCues and ScannerCues named beside that image in ClusterNotes. Missing cue write NOT IN INPUTS.
3. Target sketch: for each TargetCues entry, list images that name it. Do not invent a 47 CVE-total claim if absent.
4. Scanner caution block: quote ScannerCues only. Grype packs not in ClusterNotes stay NOT IN INPUTS.
5. Refuse list: inventing 47 CVE totals, inventing critical severity ranks, inventing exploit scoreboards, inventing patch SLAs.
6. Compliance pass: quote Banned and Never hits. Cut them. Print image and severity counts from ClusterNotes only. Format as Format.

Constraints:
- Vulnerability-scan checklist from ClusterNotes only. No invented CVE totals.
- Honor Version. No emojis. Not a live Trivy dashboard. Not vulnerability scoring advice.

Instructions

Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.

Generated Output

This image was generated using the prompt above.

Trivy Vulnerability Scan Checklist from Cluster Notes (No Invented CVE Totals) - Result

Examples

Example Input

ClusterNotes: image label Harbor api:1.4 as pasted severity HIGH as pasted scanner fs as pasted; image label Quay worker:2.1 as pasted severity MEDIUM as pasted. CVE invent NONE. Exploit invent NONE.
Version: Trivy as pasted (do not invent unreleased AI CVE coach)
ClusterLabel: Cedar Pier staging cluster as pasted
ImageLabels: Harbor api:1.4 as pasted; Quay worker:2.1 as pasted. Background redis UNKNOWN.
SeverityCues: severity HIGH as pasted for Harbor api:1.4; severity MEDIUM as pasted for Quay worker:2.1. CRITICAL pack UNKNOWN.
ScannerCues: scanner fs as pasted for Harbor api:1.4; Quay worker:2.1 scanner NOT IN INPUTS.
TargetCues: target filesystem as pasted for Harbor api:1.4; Quay worker:2.1 target NOT IN INPUTS.
Banned: 47 CVEs, critical rank #1, guaranteed patch SLA
Never: invent CVE totals, invent severity ranks, invent exploit scoreboards, invent patch SLAs
Format: ledger + vulnerability-scan checklist + target sketch + scanner caution + refuse + compliance
Lang: English

Example Output

1. Ledger. ClusterNotes: image label Harbor api:1.4 + severity HIGH + scanner fs; image label Quay worker:2.1 + severity MEDIUM. CVE invent NONE. Exploit invent NONE. Version Trivy. ClusterLabel Cedar Pier staging cluster. ImageLabels Harbor api:1.4; Quay worker:2.1. SeverityCues HIGH for Harbor api:1.4; MEDIUM for Quay worker:2.1. ScannerCues fs for Harbor api:1.4; Quay worker:2.1 scanner NOT IN INPUTS. TargetCues filesystem for Harbor api:1.4; Quay worker:2.1 target NOT IN INPUTS. Lang English. Banner: not vulnerability scoring advice; not a live Trivy sync. Forbidden: invented CVE totals, severity ranks, exploit scoreboards, patch SLAs, 47 CVEs, critical rank #1, guaranteed patch SLA.

2. Vulnerability-scan checklist.
[ ] Harbor api:1.4 | severity HIGH | scanner fs as pasted.
[ ] Quay worker:2.1 | severity MEDIUM | scanner NOT IN INPUTS.
Background redis not attached. CRITICAL pack not added.

3. Target sketch.
target filesystem | image Harbor api:1.4 as pasted.
Quay worker:2.1 target | NOT IN INPUTS.
CVE totals NOT IN INPUTS so do not invent 47 CVEs. Second filesystem cue not invented.

4. Scanner caution. scanner fs as pasted for Harbor api:1.4. Quay worker:2.1 scanner NOT IN INPUTS. Grype pack NOT IN INPUTS. Do not invent exploit packs.

5. Refuse. 47 CVE totals: refused. critical severity ranks: refused. exploit scoreboards: refused. patch SLAs: refused. Unreleased AI CVE coach: refused.

6. Compliance. Banned hits none. Images 2. Severities named 2. Format ledger+vulnerability-scan checklist+target sketch+scanner caution+refuse+compliance. Gaps: Quay worker:2.1 scanner, Quay worker:2.1 target, Background redis, CRITICAL pack, CVE totals.

Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.

Reviews (0)

Please login to leave a review.
Loading reviews...