More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Docker Compose Linter

    3

    Your docker-compose.yml works on your laptop.

    Free

    7 installsSecurity scanned
    docker-compose-linter

    docker-compose-linter

    Example session with this skill installed

    "Lint this docker-compose.yml for security and reliability issues."

    • Read your context and instructions
    • Compiled the docker-compose-linter
    === Docker Compose Lint: docker-compose.yml ===
    
    [1/7] Validating YAML syntax...                          ✅ PASS
    [2/7] Checking deprecated     🟡 WARN: 'version: "3.8"' is
    'version' field...            deprecated — remove it
    ────────────────────────────  ────────────────────────────
    [3/7] Scanning for hardcoded  🔴 FAIL: POSTGRES_PASSWORD on
    secrets...                    line 14
    🔴 FAIL: REDIS_PASSWORD on
    line 21
    [4/7] Checking for            ✅ PASS
    privileged containers...
    [5/7] Checking for            🟡 WARN: No healthcheck for
    healthchecks...               'web', 'worker'
    [6/7] Checking for resource   🟡 WARN: No resource limits
    limits...                     defined
    [7/7] Checking image version  🟡 WARN: 'nginx:latest',
    pinning...                    'node:lts' unpinned
    
    === Lint complete: 2 CRITICAL, 4 WARNING, 1 PASS ===
    
    🔴 CRITICAL — Hardcoded secret: POSTGRES_PASSWORD on line 14
      → Move to env_fi
    

    Connects securely to your tools. The creator never sees your data.

    About this skill

    The Problem

    Your docker-compose.yml works on your laptop. Then a database password gets committed to git because it was hardcoded in the environment: block. Your Postgres port 5432 is mapped to the host, so anyone on the network can connect. A container runs out of memory and kills your host because there are no deploy.resources.limits. A dependency service crashes on startup but the app container doesn't wait for it because depends_on without condition: service_healthy only waits for the container to start, not to be ready.

    Docker Compose files are deceptively simple YAML that hide real security and reliability landmines. A 50-line compose file can have 14 different misconfiguration categories, and docker compose config only validates syntax — it won't tell you that privileged: true gives your container root access to the host kernel.

    What You Get

    • 14-point quality gate checklist — YAML syntax, deprecated version field, hardcoded secrets, privileged mode, exposed database ports, running as root, missing no-new-privileges, missing healthchecks, missing restart policies, missing resource limits, unpinned image tags, implicit network definitions, missing logging config, dangerous capabilities (cap_add: ALL)
    • Security audit with severity levels — 🔴 CRITICAL for hardcoded secrets and privileged containers, 🟡 WARNING for missing healthchecks and unpinned images, ✅ PASS for verified configurations
    • Secret pattern detection — flags env var names matching *(PASSWORD|SECRET|TOKEN|KEY|CREDENTIAL)* with literal (non-variable) values
    • Network architecture recommendations — flags missing explicit network definitions and suggests internal: true networks for database/internal services
    • Ready-to-use lint script — bash script (scripts/lint-compose.sh) that runs all 7 checks in sequence with pass/fail/warn output for CI integration
    • Tool integration guide — DCLint, yamllint, checkov, and docker compose config commands for deeper analysis

    Why This Beats Prompting It Yourself

    docker compose config validates that the YAML parses correctly and the compose schema is followed. It won't catch that your Postgres port is exposed to the host, that your Redis has no healthcheck, that your app container has no memory limit, or that a hardcoded password sits on line 14. The linter checks security, reliability, and operational best practices that the Docker CLI doesn't cover — 14 specific failure modes that real teams hit in production.

    Example Session

    You: "Lint this docker-compose.yml for security and reliability issues."

    Agent:

    === Docker Compose Lint: docker-compose.yml ===
    
    [1/7] Validating YAML syntax...                          ✅ PASS
    [2/7] Checking deprecated     🟡 WARN: 'version: "3.8"' is
    'version' field...            deprecated — remove it
    ────────────────────────────  ────────────────────────────
    [3/7] Scanning for hardcoded  🔴 FAIL: POSTGRES_PASSWORD on
    secrets...                    line 14
    🔴 FAIL: REDIS_PASSWORD on
    line 21
    [4/7] Checking for            ✅ PASS
    privileged containers...
    [5/7] Checking for            🟡 WARN: No healthcheck for
    healthchecks...               'web', 'worker'
    [6/7] Checking for resource   🟡 WARN: No resource limits
    limits...                     defined
    [7/7] Checking image version  🟡 WARN: 'nginx:latest',
    pinning...                    'node:lts' unpinned
    
    === Lint complete: 2 CRITICAL, 4 WARNING, 1 PASS ===
    
    🔴 CRITICAL — Hardcoded secret: POSTGRES_PASSWORD on line 14
      → Move to env_file or Docker secret
    
    🔴 CRITICAL — Hardcoded secret: REDIS_PASSWORD on line 21
      → Move to env_file or Docker secret
    
    🟡 WARNING — Image 'nginx:latest' is unpinned
      → Pin to specific version (e.g., nginx:1.27.4-alpine)
    
    🟡 WARNING — Missing healthcheck for services 'web', 'worker'
      → Add healthcheck with HTTP or TCP probe
    

    Use Cases

    • Pre-deployment security gate — run before docker compose up -d in production to catch secrets and misconfigurations
    • PR review for compose changes — lint as part of code review when docker-compose.yml is modified
    • New project setup — validate the initial compose file before the team starts building services on top of it
    • CI/CD pipeline check — integrate the lint script to fail builds on CRITICAL findings
    • Infrastructure audit — scan all compose files in a repo for accumulated misconfigurations

    Known Limitations

    The linter checks compose file contents, not the running containers themselves — runtime behavior like actual port exposure or resource consumption requires container-level monitoring tools. Some checks (like image pinning) depend on the image tag format and may produce false positives for images with unusual tagging schemes.

    Upgrade to Pro

    Free validates best practices. Docker Compose Linter Pro ($5) hardens for production: override merging, resource limits, secret audits, and dev/prod parity checks. Upgrade when compose files leave the laptop — Pro version.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    7 installs

    Downloaded by developers to date

    Free forever

    No account required to browse

    Trust & safety

    Security scanned

    Verified clean 4 months ago

    • Free to download with an account

    Listed4 months ago
    Updated9 days ago

    What's inside

    Frequently Asked Questions