container

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill recommends using official and well-known base images from trusted sources such as Eclipse Temurin and Debian, minimizing supply chain risks.- [SAFE]: Security posture is improved by advocating for the use of numeric non-root users (USER 1001), which prevents privilege escalation within the container and complies with modern orchestration security standards.- [SAFE]: The utilization of jlink to create a custom, minimal JRE effectively reduces the container's attack surface by excluding unnecessary binaries, shells, and package managers.- [SAFE]: Container entrypoints are correctly configured with 'exec' to ensure the JVM receives termination signals directly, supporting graceful shutdown and preventing orphaned processes.- [SAFE]: JVM parameters like 'ExitOnOutOfMemoryError' and 'MaxRAMPercentage' are used to ensure the application behaves predictably within cgroup-constrained environments, preventing kernel-level OOM kills without logging.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 03:01 PM
Security Audit — agent-trust-hub — container