docker-patterns
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides Docker and Docker Compose templates that follow established industry best practices for container security and development workflows.
- [SAFE]: References official Docker images for Node.js, PostgreSQL, and Redis, which are well-known and widely used in the development community.
- [SAFE]: Contains explicit security recommendations, including the use of non-root users (
USER appuser), dropping Linux capabilities (cap_drop), and implementing read-only filesystems. - [SAFE]: Provides guidance on secure secret management, recommending
.envfiles and Docker secrets while explicitly warning against hardcoding credentials in Dockerfiles or Compose files. - [SAFE]: Includes standard debugging and health check commands (
wget,nslookup,pg_isready) used correctly within their respective service contexts.
Audit Metadata