docker-scout-scanner
Installation
SKILL.md
Docker Scout Scanner
This skill performs container security analysis for Docker projects using Docker Scout, identifying CVEs in image layers, insecure Dockerfile patterns, outdated base images, and misconfigured container builds, then mapping findings to CWE and OWASP Top 10:2021 standards. When Docker Scout is unavailable, the skill falls back to a ten-point static Dockerfile review covering the most critical container hardening checks.
When to Use
- When the user asks to "scan a Docker image for vulnerabilities" or "run Docker Scout"
- When the user mentions "container CVE scan", "image security", or "container SAST"
- When reviewing a
Dockerfileordocker-compose.ymlbefore deployment - When a pull request contains changes to
Dockerfile,.dockerignore, ordocker-compose.ymland a security check is requested - When the user wants to check for outdated base images, exposed secrets in build args, or privilege escalation risks
- When generating a Software Bill of Materials (SBOM) for a container image