docker
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive guidance on Docker security best practices, including using non-root users, multi-stage builds to reduce attack surface, and using BuildKit secrets to avoid leaking credentials in image layers.
- [COMMAND_EXECUTION]: The
scripts/verify.shfile executes local system commands (grep,hadolint,docker,trivy,dockle) to perform static analysis and linting of Docker artifacts. These operations are read-only, limited to the local environment, and intended for security verification. - [EXTERNAL_DOWNLOADS]: The skill references several official and well-known Docker images from trusted sources, including Docker Hub, Google Container Registry (distroless), and GitHub Container Registry (Chainguard/Wolfi and Astral-sh/uv). These are standard references for container development.
- [PROMPT_INJECTION]: No prompt injection patterns were detected. The instructions are focused on providing technical guidance and do not attempt to override agent safety filters or system prompts.
Audit Metadata