secdevai-oci-image-security
Installation
SKILL.md
OCI Container Image Security Analysis
This skill guides systematic security analysis of OCI container images. It is structured around four core finding categories that consistently yield actionable signal when analyzing images from registries such as Red Hat, Quay.io, and Docker Hub.
When to Use This Skill
- Reviewing container images before promotion to production or a registry
- Triaging CVE scanner output (Trivy, Grype, ACS/RHACS) for a container image
- Analyzing a new base image or upstream image for adoption decisions
- Performing security review as part of a FedRAMP ConMon or ATO workflow
- Investigating a supply chain concern involving an OCI image or package
- Hardening a Dockerfile or image build pipeline