dockerfile-and-jvm-tuning
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill mandates the use of non-root users in the generated Dockerfiles, which is a key security practice to mitigate the impact of container escapes.
- [SAFE]: Instructions include creating a .dockerignore file that explicitly excludes sensitive files such as .env and secrets directories, preventing accidental credential exposure in image layers.
- [SAFE]: The skill promotes the use of minimal base images like distroless or jlink runtimes, reducing the attack surface of the final container.
- [SAFE]: All referenced Docker base images (e.g., Maven, Eclipse Temurin, Distroless) are sourced from well-known, reputable providers.
Audit Metadata