create-dockerfile

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructional templates for creating Dockerfiles that implement security hardening, such as configuring non-root user accounts (e.g., 'appuser' or 'nonroot') to follow the principle of least privilege.
  • [SAFE]: A detailed '.dockerignore' configuration is provided to ensure that sensitive files, such as environment variables ('.env', '.env.*') and private project metadata, are excluded from the container build context.
  • [SAFE]: Base image recommendations and dependency installation commands (e.g., 'npm ci', 'pip install', 'mvn') target official images and standard registries without any suspicious or obfuscated remote execution patterns.
  • [SAFE]: Shell commands intended for the 'Bash' tool are limited to standard container management operations, such as building and inspecting local images, and do not involve unauthorized data exfiltration or persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 12:14 PM
Security Audit — agent-trust-hub — create-dockerfile