container-image-hardening
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill serves as a security auditing resource, promoting industry-standard best practices such as multi-stage builds, non-root users, and the removal of secrets from container layers.- [COMMAND_EXECUTION]: Instructions include the use of legitimate security scanning and auditing tools like Trivy, Grype, Docker Scout, and Dive. These commands are executed to identify vulnerabilities and optimize image security.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external Dockerfiles and images, which represents a potential attack surface.
- Ingestion points: External Dockerfiles and container images provided for review or hardening.
- Boundary markers: Not explicitly defined in the instructional text.
- Capability inventory: Uses shell-based tools (docker, trivy, grype, dive) to analyze the provided inputs.
- Sanitization: The skill focuses on post-hoc analysis and does not specify input sanitization techniques.
Audit Metadata