secdevai-oci-image-security

Installation
SKILL.md

OCI Container Image Security Analysis

This skill guides systematic security analysis of OCI container images. It is structured around four core finding categories that consistently yield actionable signal when analyzing images from registries such as Red Hat, Quay.io, and Docker Hub.

When to Use This Skill

  • Reviewing container images before promotion to production or a registry
  • Triaging CVE scanner output (Trivy, Grype, ACS/RHACS) for a container image
  • Analyzing a new base image or upstream image for adoption decisions
  • Performing security review as part of a FedRAMP ConMon or ATO workflow
  • Investigating a supply chain concern involving an OCI image or package
  • Hardening a Dockerfile or image build pipeline

Analysis Workflow

Installs
2
GitHub Stars
52
First Seen
Jul 18, 2026
secdevai-oci-image-security — redhatproductsecurity/prodsec-skills