oci-security
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a knowledge repository for container security best practices, including OCI runtime hardening and supply chain integrity.
- [SAFE]: All included code snippets, such as Dockerfiles, docker-compose templates, and Kubernetes manifests, correctly implement industry-standard security controls like non-root users, capability dropping, and read-only filesystems.
- [SAFE]: References to external security tools (e.g., Trivy, Cosign, Syft) and CI/CD integrations (e.g., aquasecurity/trivy-action) target well-known and trusted projects.
- [SAFE]: No obfuscation, malicious network patterns, or persistence mechanisms were found.
Audit Metadata