Claude Code skills · updated 2026-10-03

OWASP Dependency-Check config skill for Claude Code — NVD key, failBuildOnCVSS

Finds why your OWASP Dependency-Check scan cannot update or never fails

owasp-dependency-check-config-lint - findings on the bundled example

On one 35-line pom.xml it printed 6 findings (3 errors, 3 warnings) from 10 rules, each with file:line, the fix and a dated source.

Get it on Whop - $12 onceGet it on Gumroad

Who it's for

For Java teams who run OWASP Dependency-Check in Maven, Gradle or CI and treat a green scan as proof the build is clean.

What breaks, and when

Below the 12.1.0 mandatory upgrade (2025-02-24) the scan can no longer update NVD data, and failBuildOnCVSS 11 means no CVE can ever fail the build.

What it printed on the bundled example

== OWASP Dependency Check Config Lint — 6 findings (3 errors, 3 warnings) in 1 file · 10 rules
  ERROR owasp-sample.xml:16  [ODC001]
        Dependency-Check below the 12.1.0 mandatory upgrade: 8.4.3 can no longer update NVD data. Replace with 13.0.0 (released 2026-08-03). Crossing 11.0.0 also needs Java 11 and a one-time purge of the H2 database. Source: Dependency-Check README + issue #7463 'Mandatory Upgrade to 12.1.0 or later' (2025-02-24).
  ERROR owasp-sample.xml:18  [ODC003]
        Hardcoded NVD API key or OSS Index password: nvdApiKey is a literal value committed to the repo. Fix: ${env.NVD_API_KEY} or <nvdApiServerId>nvd</nvdApiServerId>. Source: NVD API key terms + Dependency-Check docs (nvdApiServerId / ossIndexServerId read settings.xml).
  ERROR owasp-sample.xml:19  [ODC002]
        Legacy NVD data-feed property: this setting points at the retired NVD data feed. Fix: delete the line; set nvdApiKey (or nvdDatafeedUrl for a mirror). Source: Dependency-Check 9.0.0 (2023-11-22) moved from the NVD data feed to the NVD API.
  WARN  owasp-sample.xml:20  [ODC005]
        failBuildOnCVSS left at 11 (scan never fails the build): CVSS 11 is above the 10.0 maximum, so no CVE can ever fail the build. Fix: <failBuildOnCVSS>7</failBuildOnCVSS>. Source: dependency-check-maven configuration: failBuildOnCVSS default 11 = never fail.

What you get

Install

Unzip into ~/.claude/skills/ (all projects) or your-repo/.claude/skills/ (one repo), then ask Claude Code: "Our OWASP dependency-check scan in Maven seems to pass every time and the NVD update is slow. Can you review our build and CI config and tell me what is wrong? Don't edit anything yet.". Needs Node 16+.

unzip owasp-dependency-check-config-lint.zip -d ~/.claude/skills/

Ask Claude

“Our OWASP dependency-check scan in Maven seems to pass every time and the NVD update is slow. Can you review our build and CI config and tell me what is wrong? Don't edit anything yet.”

What it does not do

Reads build and CI files only; it does not run Dependency-Check, download NVD data or look up CVEs.

FAQ

What is a Claude Code skill?

A folder with a SKILL.md and scripts that Claude Code loads when your request matches it. You ask in plain words and Claude runs the scanner the skill carries.

How is this different from asking Claude without the skill?

The skill carries a dated rule table and a scanner that reads every file, so Claude quotes the exact date and line instead of answering from memory.

Does it send my code anywhere?

Reads build and CI files only; it does not run Dependency-Check, download NVD data or look up CVEs.

How do I install it?

Unzip into ~/.claude/skills/ (all projects) or your-repo/.claude/skills/ (one repo), then ask Claude Code: "Our OWASP dependency-check scan in Maven seems to pass every time and the NVD update is slow. Can you review our build and CI config and tell me what is wrong? Don't edit anything yet.". Needs Node 16+.

What do I get when I buy?

The zip. On Whop it is in your library as a download lesson with the zip attached; on Gumroad it is the product file.