Agent skill

Dockerfile Validator

by akin-ozer in akin-ozer/cc-devops-skills

Validate, lint, audit, or scan a Dockerfile for security and best practices.

Apache-2.0Auto-check passedDevOps & Cloud

Install Dockerfile Validator

skills CLI
$ npx skills add akin-ozer/cc-devops-skills --skill dockerfile-validator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install akin-ozer/cc-devops-skills dockerfile-validator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/akin-ozer/cc-devops-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/devops-skills-plugin/skills/dockerfile-validator .claude/skills/dockerfile-validator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dockerfile-validator
GitHub stars
319
Token cost
~2.3k tokens
SKILL.md length
691 words
Files
17 (incl. scripts, references)
Skills in repo
30
Repo updated
First seen
Licence
Apache-2.0

At a glance

Validate, lint, audit, or scan a Dockerfile for security and best practices.

  • Works in 8 steps: Preflight and Path Setup → Read the Target Dockerfile Explicitly → Run Validation Script → …
  • Tasks that involve Containers
  • SKILL.md covers Trigger Phrases, Use / Do Not Use, Local Files In This Skill and Deterministic Execution Flow…, plus 6 more sections
  • Runs Shell scripts from its folder; calls bash, rg and docker

What it does

Dockerfile Validator is an agent skill from akin-ozer/cc-devops-skills. Validate, lint, audit, or scan a Dockerfile for security and best practices.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 21 other files, including scripts and reference files (for example `references/docker_best_practices.md`, `references/optimization_guide.md` and `references/security_checklist.md`).

It sits in DevOps & Cloud, covering Containers. It works with Docker. The repository describes itself as: DevOps skills for Claude Code and Codex. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Containers

Example prompts

  • “/dockerfile-validator”

Requirements

  • Python 3
  • A Bash shell
  • Docker

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Preflight and Path Setup
  2. Read the Target Dockerfile Explicitly
  3. Run Validation Script
  4. Classify Findings by Severity (Standard)
  5. No-Issue Fast Path (Required)
  6. Reference Loading Rules (Only When Findings Exist)
  7. Produce Standard Report Output
  8. Offer Fix Application

What it can do on your machine

Read from SKILL.md and the folder at commit 276af75. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • bash
    • rg
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.docker.com
    • checkov.io
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dockerfile Validator loads about 2.3k tokens when it runs, and up to ~8k if it reads all its reference files. Until then it costs about 24 tokens; SKILL.md has 691 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~24
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from akin-ozer/cc-devops-skills at commit 276af75, republished under its Apache-2.0 licence (© akin-ozer). 691 words, ~2,313 tokens.

Download SKILL.mdSave it as .claude/skills/dockerfile-validator/SKILL.md (or your agent's skills folder). This skill also uses 16 other files; get the full folder from GitHub.
name
dockerfile-validator
description
Validate, lint, audit, or scan a Dockerfile for security and best practices.

Dockerfile Validator

Validate Dockerfiles with deterministic stages, clear severity reporting, and explicit fallbacks when tools or network access are constrained.

Trigger Phrases

Use this skill when the user asks for tasks like:

  • "validate this Dockerfile"
  • "lint/check my Dockerfile"
  • "security scan Dockerfile"
  • "optimize Docker image size/build time"
  • "review Dockerfile before merge"
  • "find issues in Dockerfile.prod/Dockerfile.dev"

Use / Do Not Use

Use this skill for:

  • Syntax and lint validation
  • Security and secrets checks
  • Best-practice and performance review
  • Dockerfile hardening before CI/CD or production

Do not use this skill for:

  • Generating a new Dockerfile from scratch (use dockerfile-generator)
  • Running containers, debugging runtime behavior, or image registry operations

Local Files In This Skill

  • Validator script: scripts/dockerfile-validate.sh
  • References:
    • references/security_checklist.md
    • references/optimization_guide.md
    • references/docker_best_practices.md
  • Example Dockerfiles: examples/*.Dockerfile

Deterministic Execution Flow (Required)

Run these steps in order. Do not skip steps unless a documented fallback branch applies.

1. Preflight and Path Setup

Assume repo root as working directory:

bash
cd /path/to/repo
SKILL_DIR="devops-skills-plugin/skills/dockerfile-validator"
TARGET_DOCKERFILE="Dockerfile"   # replace when user provides a path

Validate inputs before running tools:

bash
test -f "$SKILL_DIR/scripts/dockerfile-validate.sh"
test -f "$TARGET_DOCKERFILE"

If either check fails, stop and report the exact missing path.

2. Read the Target Dockerfile Explicitly

Use explicit file-read commands (not abstract "Read tool" wording):

bash
sed -n '1,220p' "$TARGET_DOCKERFILE"

If needed for long files:

bash
sed -n '220,440p' "$TARGET_DOCKERFILE"
3. Run Validation Script

Primary command:

bash
bash "$SKILL_DIR/scripts/dockerfile-validate.sh" "$TARGET_DOCKERFILE"

Optional captured run for structured reporting:

bash
bash "$SKILL_DIR/scripts/dockerfile-validate.sh" "$TARGET_DOCKERFILE" | tee /tmp/dockerfile-validator.out
4. Classify Findings by Severity (Standard)

Use this standard severity model:

  • Critical
    • Hardcoded secrets/credentials
    • Explicit root runtime with high-risk context
    • High-impact security policy failures
  • High
    • Checkov failures for container hardening
    • hadolint errors likely to cause insecure/unreliable builds
    • Missing or unsafe runtime-user posture (USER)
  • Medium
    • :latest image tags, missing pinning, cache-cleanup misses
    • Build cache inefficiency and layered install anti-patterns
  • Low
    • Style/info guidance and non-blocking optimization suggestions
5. No-Issue Fast Path (Required)

If validation has no actionable findings:

  • Return a concise pass summary.
  • Do not open reference files.
  • Do not generate fix diffs.

Use fast path when all are true:

  • Script reports overall pass.
  • No security failures.
  • No error/warning findings requiring user action.
6. Reference Loading Rules (Only When Findings Exist)

Only read references that match actual findings. Read each required file once.

Issue-to-reference mapping:

Issue categoryTrigger examplesRead this file
Secrets, root user, exposed sensitive ports, hardening gapsCKV_DOCKER_*, hardcoded token/password, root runtimereferences/security_checklist.md
Image size, layer count, multi-stage opportunities, cache efficiency, .dockerignore gapstoo many RUN, single-stage with build deps, cache missesreferences/optimization_guide.md
Tag pinning, instruction usage, COPY vs ADD, WORKDIR/CMD/ENTRYPOINT conventions:latest, unpinned packages, instruction-level best practicesreferences/docker_best_practices.md

Explicit read commands:

bash
sed -n '1,220p' "$SKILL_DIR/references/security_checklist.md"
sed -n '1,220p' "$SKILL_DIR/references/optimization_guide.md"
sed -n '1,220p' "$SKILL_DIR/references/docker_best_practices.md"

For targeted extraction:

bash
rg -n "USER|secrets|EXPOSE|HEALTHCHECK" "$SKILL_DIR/references/security_checklist.md"
rg -n "multi-stage|cache|layer|dockerignore" "$SKILL_DIR/references/optimization_guide.md"
rg -n "FROM|COPY|ADD|WORKDIR|CMD|ENTRYPOINT|latest" "$SKILL_DIR/references/docker_best_practices.md"
7. Produce Standard Report Output

Use this template for every non-fast-path run:

markdown
## Dockerfile Validation Report
- Target: <path>
- Command: `bash <skill-script> <target>`
- Overall result: PASS | FAIL | PARTIAL (fallback)

### Critical
- <issue or `None`>

### High
- <issue or `None`>

### Medium
- <issue or `None`>

### Low
- <issue or `None`>

### Recommended Fixes
- <specific code-level fix per actionable issue>

### References Used
- <list only files actually read>

### Fallbacks Used
- `None` or exact fallback branch + reason
8. Offer Fix Application

After reporting:

  • Ask whether to apply fixes.
  • If user approves, patch the Dockerfile and rerun validation.
Show full SKILL.md (267 more words)Show less

Fallback Behavior (Explicit)

When the primary script cannot complete, use deterministic fallback branches and report them.

Fallback A: Python/Tool Install Constraint

Condition:

  • Script exits with tool-install failure (for example Python missing, package install blocked, or restricted environment).

Action:

  1. Report primary failure and why.
  2. Run manual minimum checks:
bash
# Basic syntax signal (if Docker is available)
DOCKERFILE_DIR="$(dirname "$TARGET_DOCKERFILE")"
docker build --no-cache -f "$TARGET_DOCKERFILE" "$DOCKERFILE_DIR"

# High-value static checks
grep -nEi "^[[:space:]]*FROM[[:space:]]+.*:latest" "$TARGET_DOCKERFILE" || true
grep -nEi "^[[:space:]]*(ENV|ARG)[[:space:]].*(password|secret|token|api[_-]?key)[[:space:]]*=" "$TARGET_DOCKERFILE" || true
grep -nEi "^[[:space:]]*USER[[:space:]]+(root|0(:0)?)$" "$TARGET_DOCKERFILE" || true
grep -nEi "^[[:space:]]*HEALTHCHECK[[:space:]]+" "$TARGET_DOCKERFILE" || true
  1. Classify output with PARTIAL result and clearly label skipped checks.
Fallback B: hadolint Not Available but Docker Available

Use hadolint container image:

bash
docker run --rm -i hadolint/hadolint < "$TARGET_DOCKERFILE"
Fallback C: No Docker, No hadolint/checkov

Run only manual regex-based checks (Fallback A step 2), clearly mark as PARTIAL, and state which scanners were skipped.

Quick Command Set

Validate one Dockerfile
bash
cd /path/to/repo
bash devops-skills-plugin/skills/dockerfile-validator/scripts/dockerfile-validate.sh Dockerfile
Validate alternate file
bash
cd /path/to/repo
bash devops-skills-plugin/skills/dockerfile-validator/scripts/dockerfile-validate.sh Dockerfile.prod
Validate skill examples
bash
cd /path/to/repo/devops-skills-plugin/skills/dockerfile-validator
bash scripts/dockerfile-validate.sh examples/good-example.Dockerfile
bash scripts/dockerfile-validate.sh examples/security-issues.Dockerfile
Run regression checks (CI entrypoint)
bash
cd /path/to/repo
bash devops-skills-plugin/skills/dockerfile-validator/scripts/test_validate.sh

Optional strict mode for CI environments that must enforce ShellCheck:

bash
STRICT_SHELLCHECK=true bash devops-skills-plugin/skills/dockerfile-validator/scripts/test_validate.sh

Progressive Disclosure Rules

  • Always read the target Dockerfile first.
  • Do not read any reference files unless findings require them.
  • Read only the matching reference file(s) from the issue-to-reference mapping.
  • Do not reread the same reference unless new issue categories appear.

Done Criteria

Consider this skill execution complete only when all conditions below are satisfied:

  • Trigger matched a Dockerfile validation/lint/security/optimization request.
  • Target Dockerfile path was explicitly verified.
  • Validation command (or explicit fallback) was executed.
  • Findings were reported using severity buckets (Critical, High, Medium, Low).
  • Reference usage matched issue categories and was explicitly listed.
  • No-issue fast path skipped unnecessary reference reads.
  • If fixes were applied, validation was rerun and final status reported.

Resources

  • Script: scripts/dockerfile-validate.sh
  • CI/regression entrypoint: scripts/test_validate.sh
  • Security reference: references/security_checklist.md
  • Optimization reference: references/optimization_guide.md
  • Best-practices reference: references/docker_best_practices.md
  • Examples: examples/good-example.Dockerfile, examples/bad-example.Dockerfile, examples/security-issues.Dockerfile, examples/python-optimized.Dockerfile, examples/golang-distroless.Dockerfile

© akin-ozer, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 16 other files (scripts, references) in devops-skills-plugin/skills/dockerfile-validator of akin-ozer/cc-devops-skills.

  • SKILL.md
  • .gitignore
  • examples/.dockerignore.example
  • examples/bad-example.Dockerfile
  • examples/golang-distroless.Dockerfile
  • examples/good-example.Dockerfile
  • examples/python-optimized.Dockerfile
  • examples/security-issues.Dockerfile
  • references/docker_best_practices.md
  • references/optimization_guide.md
  • references/security_checklist.md
  • scripts/dockerfile-validate.sh
  • scripts/test_validate.sh
  • tests/fixtures/copy-before-yarn-lock-read.Dockerfile
  • tests/fixtures/copy-before-yarn.Dockerfile
  • tests/fixtures/from-platform-nonroot.Dockerfile
  • … and 1 more

Open the folder on GitHubat commit 276af75

Compare with similar skills

Dockerfile Validator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dockerfile Validator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dockerfile Validator this skillakin-ozer/cc-devops-skills319—~2.3kAutomated safety check: PassApache-2.0
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0
Build Openshell Mxc WindowsNVIDIA/OpenShell15k—~4.9kAutomated safety check: PassApache-2.0

Similar skills

  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    15k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Omnigent Docker Compose Deploy

    omnigent-ai/omnigent

    Brings up the Omnigent server and Postgres as a Docker compose stack on any Docker host, and covers the Dockerfile's runtime and host build targets for extending it to a new platform.

    11k GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from akin-ozer/cc-devops-skills

All 30 skills in this repo
  • GitHub Actions Generator

    akin-ozer/cc-devops-skills

    Create, generate, or scaffold GitHub Actions workflows, action.yml, or .github/workflows CI/CD pipelines.

    319 GitHub stars~3.1k tokensUpdated 2 mo ago
    Auto-check passed
  • Helm Generator

    akin-ozer/cc-devops-skills

    Create, scaffold, or generate Helm charts, Chart.yaml, values.yaml, templates, helpers.

    319 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Jenkinsfile Generator

    akin-ozer/cc-devops-skills

    Generate/create/scaffold Jenkinsfile — declarative, scripted, shared library, CI/CD pipelines.

    319 GitHub stars~3.7k tokensUpdated 2 mo ago
    Auto-check passed
  • GitHub Actions Validator

    akin-ozer/cc-devops-skills

    Validate, lint, audit, fix GitHub Actions workflows (.github/workflows).

    319 GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Jenkinsfile Validator

    akin-ozer/cc-devops-skills

    Validate, lint, audit, or check Jenkinsfiles and shared libraries.

    319 GitHub stars~2.7k tokensUpdated 2 mo ago
    Auto-check passed
  • K8s Debug

    akin-ozer/cc-devops-skills

    Diagnose and fix Kubernetes pods, CrashLoopBackOff, Pending, DNS, networking, storage, and rollout failures with kubectl.

    319 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Categories

Questions about Dockerfile Validator

What does Dockerfile Validator do?

Validate, lint, audit, or scan a Dockerfile for security and best practices. Dockerfile Validator is an agent skill from akin-ozer/cc-devops-skills. Validate, lint, audit, or scan a Dockerfile for security and best practices.

When should I use Dockerfile Validator?

Dockerfile Validator fits situations like: tasks that involve Containers.

How do I install Dockerfile Validator in Claude Code?

Run `npx skills add akin-ozer/cc-devops-skills --skill dockerfile-validator -a claude-code`. Or copy the skill folder (devops-skills-plugin/skills/dockerfile-validator in akin-ozer/cc-devops-skills) into .claude/skills/dockerfile-validator in your project. Claude Code loads it when a task matches its description.

How do I install Dockerfile Validator in Codex?

Run `npx skills add akin-ozer/cc-devops-skills --skill dockerfile-validator -a codex`. Or copy the skill folder (devops-skills-plugin/skills/dockerfile-validator in akin-ozer/cc-devops-skills) into .agents/skills/dockerfile-validator in your project. Codex loads it when a task matches its description.

Can I use Dockerfile Validator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add akin-ozer/cc-devops-skills --skill dockerfile-validator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dockerfile-validator, .gemini/skills/dockerfile-validator, .github/skills/dockerfile-validator and .opencode/skills/dockerfile-validator in your project.

What does Dockerfile Validator need to run?

Going by SKILL.md and its folder, Dockerfile Validator needs a shell for the scripts in its folder and the command-line tools its instructions call (bash, rg and docker). Our summary lists: Python 3; A Bash shell; Docker.

Does Dockerfile Validator access the network?

SKILL.md names 3 domains. As links in the text: docs.docker.com, checkov.io and github.com. This is read from the text; nothing was executed.

Is Dockerfile Validator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Dockerfile Validator use?

Dockerfile Validator is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dockerfile Validator use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.7k tokens, read only when the agent opens those files.

What are the alternatives to Dockerfile Validator?

Skills that share tags, products or a category with Dockerfile Validator: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars) and LangBot Deployment Guide (langbot-app/LangBot, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dockerfile Validator?

akin-ozer (a GitHub user) maintains it in akin-ozer/cc-devops-skills, which has 319 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on July 26, 2026.

Source: akin-ozer/cc-devops-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.