Sca Trivy
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and…
$ npx skills add EliasOulkadi/shokunin --skill docker -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install EliasOulkadi/shokunin docker --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.pack/skills/docker .claude/skills/docker && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "docker" agent skill from https://github.com/EliasOulkadi/shokunin/tree/master/.pack/skills/docker into .claude/skills/docker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/EliasOulkadi/shokunin/tree/master/.pack/skills/dockerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add EliasOulkadi/shokunin --skill docker -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install EliasOulkadi/shokunin docker --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.pack/skills/docker .agents/skills/docker && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "docker" agent skill from https://github.com/EliasOulkadi/shokunin/tree/master/.pack/skills/docker into .agents/skills/docker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add EliasOulkadi/shokunin --skill docker -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install EliasOulkadi/shokunin docker --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.pack/skills/docker .cursor/skills/docker && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "docker" agent skill from https://github.com/EliasOulkadi/shokunin/tree/master/.pack/skills/docker into .cursor/skills/docker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/EliasOulkadi/shokunin.git --path .pack/skills/docker--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add EliasOulkadi/shokunin --skill docker -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install EliasOulkadi/shokunin docker --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.pack/skills/docker .gemini/skills/docker && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "docker" agent skill from https://github.com/EliasOulkadi/shokunin/tree/master/.pack/skills/docker into .gemini/skills/docker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install EliasOulkadi/shokunin dockerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add EliasOulkadi/shokunin --skill docker -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .github/skills && cp -r skills-src/.pack/skills/docker .github/skills/docker && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "docker" agent skill from https://github.com/EliasOulkadi/shokunin/tree/master/.pack/skills/docker into .github/skills/docker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add EliasOulkadi/shokunin --skill docker -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install EliasOulkadi/shokunin docker --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.pack/skills/docker .opencode/skills/docker && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "docker" agent skill from https://github.com/EliasOulkadi/shokunin/tree/master/.pack/skills/docker into .opencode/skills/docker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "docker", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dockerOptimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and…
Docker is an agent skill from EliasOulkadi/shokunin. Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and vulnerability scanning via docker scout/trivy. Use when user asks to write a Dockerfile, optimize image size, set up docker-compose, debug containers, harden container security, or scan for CVEs. Do NOT use for Kubernetes deployments (use kubernetes), CI/CD pipeline design (use ci-cd), or Terraform (use terraform).
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/docker-compose.template.yml`, `references/multi-arch.md` and `scripts/optimize-dockerfile.sh`). Compatibility notes: opencode
It sits in DevOps & Cloud, covering Containers and Vulnerability scanning. It works with Docker, Kubernetes, Terraform and Trivy. The repository describes itself as: 職人 Shokunin 62 AI agent skills for OpenCode, Claude Code, Cursor, Windsurf. ChromaDB memory, MCP servers, declarative self-updates. Multi-model, open source, zero cost. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4c68e5b. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadBashWriteFrom allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
dockernpmtrivynodepipFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use docker, npm and pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
opencode
From compatibility in the SKILL.md frontmatter.
Docker loads about 3.8k tokens when it runs, and up to ~5.7k if it reads all its reference files. Until then it costs about 127 tokens; SKILL.md has 1,125 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
and excludes `node_modules/`, `.git/`, `.env*`, `Dockerfile*`, `*.log`| No `.dockerignore` | Copies `.env`, `.git/`, `node_modules/` into build context | Add `.dockerignore` with common excl0%. Prevents leaking secrets from local `.env`. |allowed-tools: Read, Bash, WriteAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from EliasOulkadi/shokunin at commit 4c68e5b, republished under its MIT licence (© EliasOulkadi). 1,125 words, ~3,834 tokens.
.claude/skills/docker/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Production-grade Dockerfiles, multi-stage builds, cache optimization, security scanning, and local development. Applies Google's distroless philosophy and Docker BuildKit best practices.
Before containerizing, answer:
docker initFor new projects, run docker init in the project root. It auto-detects the language/framework and generates a Dockerfile, .dockerignore, and compose.yaml with best-practice defaults. Always review and harden the output — the generated files are a starting point, not production-ready.
| Stack | Base image | Build stage | Runtime |
|---|---|---|---|
| Node.js | node:22-slim | Full SDK | gcr.io/distroless/nodejs |
| Go | golang:1.23-alpine | Full SDK | scratch |
| Python | python:3.12-slim | Full SDK | python:3.12-slim |
| Rust | rust:1.78-slim | Full SDK | gcr.io/distroless/cc |
Decision: If the stack is listed above, use the corresponding production Dockerfile below. If not, apply the golden template in Step 2.
Use multi-stage with this exact structure:
Stage 1 (deps): COPY lock files → install production deps (--mount=type=cache)
Stage 2 (build): COPY source → compile
Stage 3 (runtime): minimal base → COPY artifacts from stages 1-2 → USER nonroot → HEALTHCHECKIf the project is a Go binary, skip Stage 1 (Go has no runtime deps) and go straight to Stage 2.
If the project has native dependencies (node-gyp, C extensions), use apt-get in the builder stage, NOT the runtime stage.
# syntax=docker/dockerfile:1.4
FROM node:22-slim AS deps
WORKDIR /app
COPY package.json package-lock.json ./
RUN --mount=type=cache,target=/root/.npm npm ci --omit=dev
FROM node:22-slim AS builder
WORKDIR /app
COPY package.json package-lock.json ./
RUN --mount=type=cache,target=/root/.npm npm ci
COPY src ./src
RUN npm run build
FROM gcr.io/distroless/nodejs22-debian12
WORKDIR /app
COPY --from=deps /app/node_modules ./node_modules
COPY --from=builder /app/dist ./dist
EXPOSE 3000
USER nonroot
HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \
CMD ["node", "-e", "require('http').get('http://localhost:3000/health', r => process.exit(r.statusCode===200?0:1))"]
CMD ["dist/index.js"]Run scripts/optimize-dockerfile.sh on any existing Dockerfile to receive optimization suggestions.
services:
app:
build: .
ports: ["3000:3000"]
develop:
watch:
- action: sync+restart
path: ./src
target: /app/src
depends_on: [db]
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:3000/health"]
db:
image: postgres:16-alpine
volumes: ["pgdata:/var/lib/postgresql/data"]
volumes: { pgdata: }Run docker compose watch for hot-reload.
See assets/docker-compose.template.yml for the full template with all services.
docker buildx build \
--platform linux/amd64,linux/arm64 \
--cache-from=type=gha \
--cache-to=type=gha,mode=max \
--tag registry/app:latest \
--push .See references/multi-arch.md for QEMU setup and platform-specific optimizations.
# Using the provided script
scripts/scan-image.sh registry/app:latest
# Or manually:
docker scout cves registry/app:latest
trivy image registry/app:latestIf critical CVEs are found: either switch base image (e.g., distroless), or add apt-get to install patched deps in builder stage.
| Error | Cause | Fix |
|---|---|---|
failed to solve with frontend dockerfile.v0 | Missing syntax directive | Add # syntax=docker/dockerfile:1.4 as first line |
exec /usr/bin/node: exec format error | Wrong platform | Build with --platform linux/amd64 matching the target |
permission denied at runtime | Missing USER nonroot or wrong file permissions | Add USER nonroot and COPY --chown=nonroot:nonroot |
| Layer cache miss every build | Changing files copied before lock files | Always COPY package.json BEFORE source code |
docker compose watch not working | Docker Engine < 24 | Upgrade Docker Engine or use docker compose up --watch |
Before deploying a Docker image:
.dockerignore exists and excludes node_modules/, .git/, .env*, Dockerfile*, *.lognode:22.14-slim, not node:22)USER nonroot (or equivalent) — never runs as rootHEALTHCHECK defined with appropriate interval--mount=type=secret, never ENV or ARGnpm ci --omit=dev (or language equivalent) for production dependenciesdocker scout quickview or trivy image scan passes with zero HIGH/CRITICAL CVEsdocker images --format "{{.Size}}" — should be <200MB for most appsdocker compose watch tested in development (sync+restart for code changes)docker compose down and docker compose up successfully recreates from scratch| Pattern | Problem | Fix | Because |
|---|---|---|---|
| Single-stage build | Final image contains build tools, SDKs, source code — 5x larger | Multi-stage: build stage → distroless runtime | Every tool in the image is an attack surface. Minimize blast radius. |
COPY . . before npm install | Cache miss on every code change, full rebuild | Copy package files first, install deps, then copy source | Docker caches by layer. Source changes should invalidate only the last COPY. |
latest tag | Image changes silently on pull | Pin full version tag (22.14-slim, not 22-slim) | latest means "whatever was pushed last". A patch update can break your app. |
| Root user in container | Compromised process = host root access | USER nonroot with distroless or RUN useradd | Container escape bugs exist. Non-root limits damage to the container. |
| Secrets in build args | docker history reveals them. BuildKit --secret exists for this | RUN --mount=type=secret in BuildKit | Build args are stored in image metadata. Anyone with image access can extract them. |
No .dockerignore | Copies .env, .git/, node_modules/ into build context | Add .dockerignore with common exclusions | 200MB of node_modules in build context = slow builds + potential secret leaks. |
| No healthcheck | Orchestrator can't detect app failures | HEALTHCHECK --interval=30s CMD curl -f http://localhost/health | Without healthcheck, Swarm/K8s only detects process crashes, not app hangs. |
npm install in production | Installs devDependencies (testing frameworks, linters, TypeScript) | npm ci --omit=dev or npm ci --production | Dev deps add 100-200MB to the image. They also increase CVEs from unused packages. |
Pinning only major version (22-slim) | Can auto-update to a new minor version that breaks your app | Pin to exact version (22.14-slim) or use digest pinning | Reproducibility: the same Dockerfile should produce the same image every time. |
| Multi-stage with wrong base | Runtime stage uses node instead of distroless | Use gcr.io/distroless/nodejs22-debian12 or node:22.14-slim | Distroless removes shells, package managers, and utilities — nothing for an attacker to exploit. |
When reviewing Dockerfiles, use Before | After | Why format:
| Before | After | Why |
|---|---|---|
FROM node:22-slim | FROM node:22.14-slim@sha256:abc... | Floating tags (22-slim) auto-update. Pin to immutable digest for reproducibility. |
COPY . . before npm ci | COPY package*.json ./ then npm ci then COPY . . | Docker caches each COPY layer. Copying source before deps invalidates cache on every code change. |
CMD ["npm", "start"] | Use node server.js directly | Avoids npm overhead in production. Use process manager (dumb-init, tini) for signal forwarding. |
No .dockerignore | .dockerignore with node_modules/, .git/, *.log, Dockerfile* | Reduces build context size by 60-90%. Prevents leaking secrets from local .env. |
# syntax=docker/dockerfile:1.4
FROM golang:1.24-alpine AS builder
WORKDIR /app
COPY go.mod go.sum ./
RUN --mount=type=cache,target=/go/pkg/mod go mod download
COPY . .
RUN CGO_ENABLED=0 GOOS=linux go build -ldflags="-s -w" -o /server ./cmd/server
FROM gcr.io/distroless/static-debian12
COPY --from=builder /server /server
EXPOSE 8080
USER nonroot
HEALTHCHECK --interval=30s CMD ["/server", "-health"] || exit 1
ENTRYPOINT ["/server"]Key decisions:
CGO_ENABLED=0 for static binary (no glibc dependency)-ldflags="-s -w" strips debug symbols (reduces binary by 30%)gcr.io/distroless/static-debian12 for CA certs + timezone data (needed for HTTPS/TLS)scratch (smaller, but no CA certs)# syntax=docker/dockerfile:1.4
FROM python:3.12-slim AS builder
WORKDIR /app
COPY requirements.txt .
RUN --mount=type=cache,target=/root/.cache/pip pip install --user -r requirements.txt
FROM python:3.12-slim
WORKDIR /app
COPY --from=builder /root/.local /root/.local
COPY src ./src
ENV PATH=/root/.local/bin:$PATH
EXPOSE 8000
RUN useradd -m app && chown -R app /app
USER app
HEALTHCHECK --interval=30s CMD python -c "import urllib.request; urllib.request.urlopen('http://localhost:8000/health')"
CMD ["gunicorn", "-w", "4", "-b", "0.0.0.0:8000", "src.main:app"]Key decisions:
pip install --user avoids polluting /usr/local in buildergunicorn with multiple workers handles concurrent requestsuseradd creates a non-root user (distroless Python not available)# syntax=docker/dockerfile:1.4
FROM rust:1.85-slim AS builder
WORKDIR /app
RUN apt-get update && apt-get install -y musl-tools && rm -rf /var/lib/apt/lists/*
COPY Cargo.toml Cargo.lock ./
RUN mkdir src && echo "fn main() {}" > src/main.rs
RUN --mount=type=cache,target=/usr/local/cargo/registry cargo build --release --target x86_64-unknown-linux-musl
RUN rm -rf src
COPY src ./src
RUN cargo build --release --target x86_64-unknown-linux-musl
FROM scratch
COPY --from=builder /app/target/x86_64-unknown-linux-musl/release/server /server
EXPOSE 8080
ENTRYPOINT ["/server"]Key decisions:
musl-tools for static linking (no glibc dependency)scratch base: smallest possible, no shell, no toolsDocker applies a default seccomp profile that blocks 44/300+ syscalls. Customize for your app:
{
"defaultAction": "SCMP_ACT_ERRNO",
"architectures": ["SCMP_ARCH_X86_64"],
"syscalls": [
{ "names": ["read","write","open","close","fstat","mmap","mprotect","munmap","brk","rt_sigaction","rt_sigprocmask","rt_sigreturn","ioctl","pread64","pwrite64","readv","writev","access","pipe","select","sched_yield","mremap","msync","mincore","madvise","shmget","shmat","shmctl","dup","dup2","pause","nanosleep","getitimer","setitimer","alarm","getpid","sendfile","socket","connect","accept","sendto","recvfrom","sendmsg","recvmsg","shutdown","bind","listen","getsockname","getpeername","socketpair","setsockopt","getsockopt","clone","fork","vfork","execve","exit","wait4","kill","uname","semget","semop","semctl","shmdt","msgget","msgsnd","msgrcv","msgctl","fcntl","flock","fsync","fdatasync","truncate","ftruncate","getdents","getcwd","chdir","fchdir","rename","mkdir","rmdir","creat","link","unlink","symlink","readlink","chmod","fchmod","chown","fchown","lchown","umask","gettimeofday","getrlimit","getrusage","sysinfo","times","preadv","pwritev","rt_sigtimedwait","futex","set_robust_list","get_robust_list","epoll_wait","epoll_ctl","epoll_create","epoll_pwait","epoll_create1","eventfd","signalfd","timerfd_create","timerfd_gettime","timerfd_settime","prctl","getcpu","process_vm_readv","process_vm_writev"], "action": "SCMP_ACT_ALLOW" }
]
}Usage: docker run --security-opt seccomp=profile.json myapp
# Full scan pipeline
docker build -t myapp:latest .
trivy image --severity HIGH,CRITICAL --exit-code 1 myapp:latest
docker scout cves --exit-code myapp:latest
# CI integration (GitHub Actions)
- uses: aquasecurity/trivy-action@master
with:
image-ref: myapp:latest
format: sarif
output: trivy-results.sarif
severity: HIGH,CRITICAL
exit-code: 1
# Continuous monitoring
docker scout enroll myorg/myapp
docker scout watch myapp:latestIf CVEs found: switch base image to newer distroless tag, rebuild, re-scan. Track with docker scout recommendations.
© EliasOulkadi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references, assets) in .pack/skills/docker of EliasOulkadi/shokunin.
Open the folder on GitHubat commit 4c68e5b
Docker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Docker this skillEliasOulkadi/shokunin | 114 | — | ~3.8k | Automated safety check: Notes | MIT | |
| Sca TrivyAgentSecOps/SecOpsAgentKit | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Custom licence | |
| Security Analyzeraiskillstore/marketplace | 433 | — | ~1.2k | Automated safety check: Notes | None | |
| Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills | 148 | — | ~2.6k | Automated safety check: Notes | Apache-2.0 | |
| Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~818 | Automated safety check: Pass | Apache-2.0 | |
| Container Securityhardw00t/ai-security-arsenal | 105 | — | ~2.8k | Automated safety check: Pass | None |
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
aiskillstore/marketplace
Comprehensive security vulnerability analysis for codebases and infrastructure.
aliyun/alibabacloud-ecs-troubleshoot-skills
Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。
mukul975/Anthropic-Cybersecurity-Skills
Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…
hardw00t/ai-security-arsenal
Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…
mukul975/Anthropic-Cybersecurity-Skills
Scores Kubernetes resource manifests with Kubesec to flag misconfiguration and privilege-escalation risk before deployment, mapping each finding back to the securityContext change that fixes it.
EliasOulkadi/shokunin
Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…
EliasOulkadi/shokunin
Build production-grade components for React, Vue 3, and Svelte 5 with all states (loading, empty, error, success, idle), TypeScript strict, WCAG 2.2 accessibility, server components (RSC), and…
EliasOulkadi/shokunin
PostgreSQL database administration — backup/restore (pgdump, PITR, WAL archiving), health monitoring (connections, bloat, cache hit ratio, dead tuples), connection pooling (PgBouncer), replication…
EliasOulkadi/shokunin
Design database schemas with Prisma/Drizzle, PostgreSQL index strategy (B-tree, GIN, GiST, BRIN, Hash), query optimization (EXPLAIN ANALYZE), migration safety (expand/contract, zero-downtime), and…
EliasOulkadi/shokunin
Design error handling, structured logging, and observability with OpenTelemetry (traces, metrics, logs), error classification, recovery patterns (retry with jitter, circuit breaker, bulkhead…
EliasOulkadi/shokunin
Deploy, manage, and debug Kubernetes in production — Deployments, Services, Gateway API, Service Mesh (Istio/Linkerd/Cilium), eBPF observability (Cilium Hubble), security hardening (Pod Security…
Works with
Categories
Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and…. Docker is an agent skill from EliasOulkadi/shokunin. Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and vulnerability scanning via docker scout/trivy.
Docker fits situations like: user asks to write a Dockerfile; optimize image size; set up docker-compose; debug containers.
Run `npx skills add EliasOulkadi/shokunin --skill docker -a claude-code`. Or copy the skill folder (.pack/skills/docker in EliasOulkadi/shokunin) into .claude/skills/docker in your project. Claude Code loads it when a task matches its description.
Run `npx skills add EliasOulkadi/shokunin --skill docker -a codex`. Or copy the skill folder (.pack/skills/docker in EliasOulkadi/shokunin) into .agents/skills/docker in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EliasOulkadi/shokunin --skill docker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/docker, .gemini/skills/docker, .github/skills/docker and .opencode/skills/docker in your project.
Going by SKILL.md and its folder, Docker needs a shell for the scripts in its folder and the command-line tools its instructions call (docker, npm, trivy, node and pip). Our summary lists: Python 3; Node.js; A Bash shell; Docker. Its frontmatter pre-approves these tools: Read, Bash, Write. Compatibility (from SKILL.md): opencode.
SKILL.md contains no URLs. Its commands use docker, npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Docker is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Docker: Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars), Security Analyzer (aiskillstore/marketplace, 433 stars), Alibabacloud Ecs Sec Userspace (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars) and Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
EliasOulkadi (a GitHub user) maintains it in EliasOulkadi/shokunin, which has 114 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 5, 2026.
Source: EliasOulkadi/shokunin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.