docker-development
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses Python scripts (
scripts/dockerfile_analyzer.pyandscripts/compose_validator.py) to perform static analysis on user-provided Dockerfiles and compose files. These scripts run locally using standard Python libraries to parse text and check against a set of predefined best-practice rules. - [SAFE]: The installation instructions include a one-liner that clones a repository from the author's GitHub. This follows standard skill installation patterns and targets the vendor's own infrastructure.
- [SAFE]: The Docker patterns and templates provided (e.g., Node.js, Python, Go) demonstrate security best practices such as multi-stage builds, non-root users, and secret management using BuildKit mounts.
Audit Metadata