More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Dockerfile Hardener

    1

    It uses `ubuntu:latest` as a base image (which means "whatever Ubuntu version happens to be current").

    Free

    7 installsSecurity scanned
    dockerfile-hardener

    dockerfile-hardener

    Example session with this skill installed

    "Audit this Dockerfile for security. Here's the content."

    • Read your context and instructions
    • Compiled the dockerfile-hardener
    • Generated the document

    DOCKERFILE SECURITY AUDIT: DOCKERFILE
    ═════════════════════════════════════
    Score: 32/100 (Grade: F)

    CRITICAL (4 FINDINGS)
    ─────────────────────

    • [C01] Line 8: Hardcoded secret: ARG API_KEY=sk-prod-abc123...
      Fix: Use --mount=type=secret in RUN instead of ARG
    • [C02] Line 1: No USER directive — container runs as root
      Fix: Create non-root user with RUN addgroup/adduser, add USER after deps
    • [C03] Line 1: FROM node (no tag — defaults to :latest)
      Fix: Pin to node:22.14.0-alpine or node@sha256:...
    • [C04] Line 15: Docker socket mount detected
      Fix: Remove; use Docker API over TLS if Docker access is needed

    HIGH (5 FINDINGS)
    ─────────────────

    • [H01] Line 6: npm install without version pin
      Fix: Pin each package or use package-lock.json with npm ci
    • [H02] Line 4: ADD used instead of COPY for local files
      Fix: Replace ADD with COPY (ADD has hidden tar-extraction behavior)
    • [H03] Line 10: curl | sh pattern — no integrity check
      Fix: Download

    dockerfile-hardener.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    About this skill

    The Problem

    Your Dockerfile runs as root. It uses ubuntu:latest as a base image (which means "whatever Ubuntu version happens to be current"). It pipes curl output directly to bash. It has ARG SECRET_KEY=production-key-here visible in docker history. It copies everything (including .env, .git, and node_modules) into the image because there's no .dockerignore. It has no HEALTHCHECK, no non-root user, and no layer optimization — so a 200MB runtime image balloons to 800MB.

    Each of these is a different class of problem (security, reliability, efficiency), and most Dockerfile linters catch only a subset. Running hadolint catches best practices but not always security patterns. Running Trivy catches OS vulnerabilities but not Dockerfile anti-patterns. Nobody's checking whether you're mounting the Docker socket or running apt-get install without version pins.

    What You Get

    • 18-rule audit checklist across four severity tiers — CRITICAL (hardcoded secrets, running as root, unpinned base image, exposed Docker socket), HIGH (unpinned packages, ADD vs COPY, curl-to-shell, missing healthcheck, SUID binaries, secrets in build args), MEDIUM (no multi-stage build, excessive layers, no .dockerignore, cache-busting COPY, unnecessary packages, missing metadata labels), LOW (image size, missing BuildKit syntax, redundant ENV, missing WORKDIR)
    • Security score (0-100) with letter grade — starts at 100, deducts points per finding severity (CRITICAL: -25, HIGH: -15, MEDIUM: -8, LOW: -3); grade A-F with production-readiness thresholds
    • Hardened Dockerfile template — when any CRITICAL or HIGH finding exists, generates a complete replacement with multi-stage build, non-root user, pinned versions, cache-optimized layer ordering, HEALTHCHECK, and OCI metadata labels
    • Base image security ratings — ranked table from scratch (A+) to *:latest (F) with size and use-case recommendations
    • CI/CD integration — GitHub Actions (hadolint-action), pre-commit hooks, and GitLab CI templates for automated Dockerfile linting
    • Docker Compose cross-check — flags compose-level issues (privileged mode, docker.sock mounts, cap_add) when the Dockerfile is part of a compose stack

    Why This Beats Prompting It Yourself

    A single Dockerfile can have issues across four different security domains: secret exposure (visible in layer history), runtime privilege (running as root), supply chain (unpinned packages that change between builds), and attack surface (unnecessary packages and ports). No single tool catches all four. The hardener performs a unified audit across all domains, assigns a composite security score, and generates a hardened replacement that addresses every finding simultaneously — not one-off fixes that introduce new issues.

    Example Session

    You: "Audit this Dockerfile for security. Here's the content."

    Agent:

    ═════════════════════════════════════
    Score: 32/100 (Grade: F)
    
    CRITICAL (4 FINDINGS)
    ─────────────────────
    - [C01] Line 8: Hardcoded secret: ARG API_KEY=sk-prod-abc123...
      Fix: Use --mount=type=secret in RUN instead of ARG
    - [C02] Line 1: No USER directive — container runs as root
      Fix: Create non-root user with RUN addgroup/adduser, add USER after deps
    - [C03] Line 1: FROM node (no tag — defaults to :latest)
      Fix: Pin to node:22.14.0-alpine or node@sha256:...
    - [C04] Line 15: Docker socket mount detected
      Fix: Remove; use Docker API over TLS if Docker access is needed
    
    HIGH (5 FINDINGS)
    ─────────────────
    - [H01] Line 6: npm install without version pin
      Fix: Pin each package or use package-lock.json with npm ci
    - [H02] Line 4: ADD used instead of COPY for local files
      Fix: Replace ADD with COPY (ADD has hidden tar-extraction behavior)
    - [H03] Line 10: curl | sh pattern — no integrity check
      Fix: Download
    

    Use Cases

    • Pre-deployment security review — audit every Dockerfile before deploying to production
    • Container security compliance — generate audit reports for SOC 2, PCI DSS, or internal security reviews
    • Dockerfile refactoring — transform a single-stage bloated Dockerfile into a minimal multi-stage build
    • CI/CD pipeline hardening — add hadolint pre-commit hooks or GitHub Actions to catch issues before merge
    • New project setup — start with a hardened Dockerfile template instead of fixing issues later

    Known Limitations

    The audit checks Dockerfile syntax and patterns but cannot verify base image CVEs (use Trivy or Grype for OS-level vulnerability scanning). Windows container Dockerfiles have different best practices (package managers, user creation) — the tool flags but doesn't fail on Windows-specific patterns.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    7 installs

    Downloaded by developers to date

    Free forever

    No account required to browse

    Trust & safety

    Security scanned

    Verified clean 4 months ago

    • Free to download with an account

    Listed4 months ago
    Updated9 days ago

    What's inside

    Frequently Asked Questions