docker-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consistently recommends running containers as non-root users (e.g., USER appuser, USER node) to minimize security risks.
- [SAFE]: The documentation explicitly advises pinning base image versions and scanning for vulnerabilities using tools like Docker Scout or Trivy.
- [SAFE]: Proper secret management is encouraged by including .env and .git in the .dockerignore template to prevent sensitive data from being included in image layers.
- [SAFE]: The provided Dockerfile patterns for Python, Node.js, and Go follow industry standards for multi-stage builds, which reduces the final attack surface.
- [SAFE]: Hardcoded development credentials in the Docker Compose example are clearly intended for local environment setup and do not represent a production security risk.
Audit Metadata