docker-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [SAFE]: The skill provides high-quality educational content and templates for container security, including non-root user configurations, multi-stage builds for minimal production images, and filesystem hardening tips.
- [CREDENTIALS_UNSAFE]: The Docker Compose examples include default credentials for local services (e.g.,
POSTGRES_PASSWORD: postgres). These are documented specifically for local development environments and are accompanied by explicit warnings and best-practice advice against hardcoding sensitive production secrets. - [COMMAND_EXECUTION]: The skill includes standard operational commands for container management and application building, such as
docker compose up,docker compose exec,npm ci, andnpm run build. These are provided as educational snippets for the user. - [DATA_EXFILTRATION]: The production Dockerfile template includes a local network operation (
wget -qO- http://localhost:3000/health) used as a standard container health check. This is a routine diagnostic pattern restricted to the container's internal network environment.
Audit Metadata