Agent skill

Docker

by EliasOulkadi in EliasOulkadi/shokunin

Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and…

MITAuto-check: notesDevOps & Cloud

Install Docker

skills CLI
$ npx skills add EliasOulkadi/shokunin --skill docker -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install EliasOulkadi/shokunin docker --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/EliasOulkadi/shokunin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.pack/skills/docker .claude/skills/docker && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
docker
GitHub stars
114
Token cost
~3.8k tokens
SKILL.md length
1,125 words
Files
5 (incl. scripts, references, assets)
Skills in repo
49
Repo updated
First seen
Licence
MIT

At a glance

Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and…

  • Works in 6 steps: Identify stack and choose template → Apply golden template → Apply BuildKit optimizations → …
  • User asks to write a Dockerfile
  • SKILL.md covers Decision Framework, Workflow, Error Handling and Pre-Flight Checklist, plus 4 more sections
  • Runs Shell scripts from its folder; calls docker, npm and trivy

What it does

Docker is an agent skill from EliasOulkadi/shokunin. Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and vulnerability scanning via docker scout/trivy. Use when user asks to write a Dockerfile, optimize image size, set up docker-compose, debug containers, harden container security, or scan for CVEs. Do NOT use for Kubernetes deployments (use kubernetes), CI/CD pipeline design (use ci-cd), or Terraform (use terraform).

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/docker-compose.template.yml`, `references/multi-arch.md` and `scripts/optimize-dockerfile.sh`). Compatibility notes: opencode

It sits in DevOps & Cloud, covering Containers and Vulnerability scanning. It works with Docker, Kubernetes, Terraform and Trivy. The repository describes itself as: 職人 Shokunin 62 AI agent skills for OpenCode, Claude Code, Cursor, Windsurf. ChromaDB memory, MCP servers, declarative self-updates. Multi-model, open source, zero cost. The licence is MIT.

When your agent uses it

  • User asks to write a Dockerfile
  • Optimize image size
  • Set up docker-compose
  • Debug containers

Example prompts

  • “/docker”

Requirements

  • Python 3
  • Node.js
  • A Bash shell
  • Docker
  • Compatibility (from SKILL.md): opencode
  • Pre-approved tools (allowed-tools): Read, Bash, Write

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Identify stack and choose template
  2. Apply golden template
  3. Apply BuildKit optimizations
  4. Configure compose for local dev
  5. Build for multiple platforms
  6. Scan for vulnerabilities

What it can do on your machine

Read from SKILL.md and the folder at commit 4c68e5b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash
    • Write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • docker
    • npm
    • trivy
    • node
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, npm and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    opencode

    From compatibility in the SKILL.md frontmatter.

Context cost

Docker loads about 3.8k tokens when it runs, and up to ~5.7k if it reads all its reference files. Until then it costs about 127 tokens; SKILL.md has 1,125 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~127
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:174
    and excludes `node_modules/`, `.git/`, `.env*`, `Dockerfile*`, `*.log`
  • NoteMentions a .env fileSKILL.md:197
    | No `.dockerignore` | Copies `.env`, `.git/`, `node_modules/` into build context | Add `.dockerignore` with common excl
  • NoteMentions a .env fileSKILL.md:212
    0%. Prevents leaking secrets from local `.env`. |
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Bash, Write

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from EliasOulkadi/shokunin at commit 4c68e5b, republished under its MIT licence (© EliasOulkadi). 1,125 words, ~3,834 tokens.

Download SKILL.mdSave it as .claude/skills/docker/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
docker
description
Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and vulnerability scanning via docker scout/trivy. Use when user asks to write a Dockerfile, optimize image size, set up docker-compose, debug containers, harden container security, or scan for CVEs. Do NOT use for Kubernetes deployments (use kubernetes), CI/CD pipeline design (use ci-cd), or Terraform (use terraform).
allowed-tools
Read, Bash, Write
compatibility
opencode
triggers
write a Dockerfile, dockerize, containerize, optimize image, multi-stage build, docker-compose, docker build, Dockerfile, docker image, docker container…
negatives
Kubernetes, CI/CD pipeline, Terraform, K8s, deploy to cluster
license
MIT
metadata.workflow
infrastructure
metadata.audience
devops
metadata.version
3.0.0
metadata.author
shokunin

Docker Architect

Production-grade Dockerfiles, multi-stage builds, cache optimization, security scanning, and local development. Applies Google's distroless philosophy and Docker BuildKit best practices.

Decision Framework

Before containerizing, answer:

  • Does the app need process isolation? → Docker
  • Will it deploy to Kubernetes? → Docker + distroless + non-root
  • Is it a monolith with simple deployment? → Docker Compose
  • Is it a static site? → Consider nginx:alpine single-stage
  • Is the team already using Docker Compose in dev? → Start there, add K8s when needed
  • Is the app latency-sensitive (sub-ms)? → Bare metal or VM; container overhead matters at extreme scale

Workflow

Quick start: docker init

For new projects, run docker init in the project root. It auto-detects the language/framework and generates a Dockerfile, .dockerignore, and compose.yaml with best-practice defaults. Always review and harden the output — the generated files are a starting point, not production-ready.

Step 1: Identify stack and choose template
StackBase imageBuild stageRuntime
Node.jsnode:22-slimFull SDKgcr.io/distroless/nodejs
Gogolang:1.23-alpineFull SDKscratch
Pythonpython:3.12-slimFull SDKpython:3.12-slim
Rustrust:1.78-slimFull SDKgcr.io/distroless/cc

Decision: If the stack is listed above, use the corresponding production Dockerfile below. If not, apply the golden template in Step 2.

Step 2: Apply golden template

Use multi-stage with this exact structure:

Stage 1 (deps):   COPY lock files → install production deps (--mount=type=cache)
Stage 2 (build):  COPY source → compile
Stage 3 (runtime): minimal base → COPY artifacts from stages 1-2 → USER nonroot → HEALTHCHECK

If the project is a Go binary, skip Stage 1 (Go has no runtime deps) and go straight to Stage 2.

If the project has native dependencies (node-gyp, C extensions), use apt-get in the builder stage, NOT the runtime stage.

Step 3: Apply BuildKit optimizations
dockerfile
# syntax=docker/dockerfile:1.4
FROM node:22-slim AS deps
WORKDIR /app
COPY package.json package-lock.json ./
RUN --mount=type=cache,target=/root/.npm npm ci --omit=dev

FROM node:22-slim AS builder
WORKDIR /app
COPY package.json package-lock.json ./
RUN --mount=type=cache,target=/root/.npm npm ci
COPY src ./src
RUN npm run build

FROM gcr.io/distroless/nodejs22-debian12
WORKDIR /app
COPY --from=deps /app/node_modules ./node_modules
COPY --from=builder /app/dist ./dist
EXPOSE 3000
USER nonroot
HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \
  CMD ["node", "-e", "require('http').get('http://localhost:3000/health', r => process.exit(r.statusCode===200?0:1))"]
CMD ["dist/index.js"]

Run scripts/optimize-dockerfile.sh on any existing Dockerfile to receive optimization suggestions.

Step 4: Configure compose for local dev
yaml
services:
  app:
    build: .
    ports: ["3000:3000"]
    develop:
      watch:
        - action: sync+restart
          path: ./src
          target: /app/src
    depends_on: [db]
    healthcheck:
      test: ["CMD", "curl", "-f", "http://localhost:3000/health"]
  db:
    image: postgres:16-alpine
    volumes: ["pgdata:/var/lib/postgresql/data"]
volumes: { pgdata: }

Run docker compose watch for hot-reload.

See assets/docker-compose.template.yml for the full template with all services.

Step 5: Build for multiple platforms
bash
docker buildx build \
  --platform linux/amd64,linux/arm64 \
  --cache-from=type=gha \
  --cache-to=type=gha,mode=max \
  --tag registry/app:latest \
  --push .

See references/multi-arch.md for QEMU setup and platform-specific optimizations.

Step 6: Scan for vulnerabilities
bash
# Using the provided script
scripts/scan-image.sh registry/app:latest

# Or manually:
docker scout cves registry/app:latest
trivy image registry/app:latest

If critical CVEs are found: either switch base image (e.g., distroless), or add apt-get to install patched deps in builder stage.

Error Handling

ErrorCauseFix
failed to solve with frontend dockerfile.v0Missing syntax directiveAdd # syntax=docker/dockerfile:1.4 as first line
exec /usr/bin/node: exec format errorWrong platformBuild with --platform linux/amd64 matching the target
permission denied at runtimeMissing USER nonroot or wrong file permissionsAdd USER nonroot and COPY --chown=nonroot:nonroot
Layer cache miss every buildChanging files copied before lock filesAlways COPY package.json BEFORE source code
docker compose watch not workingDocker Engine < 24Upgrade Docker Engine or use docker compose up --watch

Pre-Flight Checklist

Before deploying a Docker image:

  • .dockerignore exists and excludes node_modules/, .git/, .env*, Dockerfile*, *.log
  • Multi-stage build with separate build and runtime stages
  • Runtime stage uses distroless or minimal base (node:22.14-slim, not node:22)
  • USER nonroot (or equivalent) — never runs as root
  • HEALTHCHECK defined with appropriate interval
  • Secrets use --mount=type=secret, never ENV or ARG
  • npm ci --omit=dev (or language equivalent) for production dependencies
  • docker scout quickview or trivy image scan passes with zero HIGH/CRITICAL CVEs
  • Image size verified: docker images --format "{{.Size}}" — should be <200MB for most apps
  • docker compose watch tested in development (sync+restart for code changes)
  • Container starts and passes healthcheck within 30 seconds
  • Logs go to stdout/stderr (no log files inside container)
  • docker compose down and docker compose up successfully recreates from scratch

Anti-Patterns

PatternProblemFixBecause
Single-stage buildFinal image contains build tools, SDKs, source code — 5x largerMulti-stage: build stage → distroless runtimeEvery tool in the image is an attack surface. Minimize blast radius.
COPY . . before npm installCache miss on every code change, full rebuildCopy package files first, install deps, then copy sourceDocker caches by layer. Source changes should invalidate only the last COPY.
latest tagImage changes silently on pullPin full version tag (22.14-slim, not 22-slim)latest means "whatever was pushed last". A patch update can break your app.
Root user in containerCompromised process = host root accessUSER nonroot with distroless or RUN useraddContainer escape bugs exist. Non-root limits damage to the container.
Secrets in build argsdocker history reveals them. BuildKit --secret exists for thisRUN --mount=type=secret in BuildKitBuild args are stored in image metadata. Anyone with image access can extract them.
No .dockerignoreCopies .env, .git/, node_modules/ into build contextAdd .dockerignore with common exclusions200MB of node_modules in build context = slow builds + potential secret leaks.
No healthcheckOrchestrator can't detect app failuresHEALTHCHECK --interval=30s CMD curl -f http://localhost/healthWithout healthcheck, Swarm/K8s only detects process crashes, not app hangs.
npm install in productionInstalls devDependencies (testing frameworks, linters, TypeScript)npm ci --omit=dev or npm ci --productionDev deps add 100-200MB to the image. They also increase CVEs from unused packages.
Pinning only major version (22-slim)Can auto-update to a new minor version that breaks your appPin to exact version (22.14-slim) or use digest pinningReproducibility: the same Dockerfile should produce the same image every time.
Multi-stage with wrong baseRuntime stage uses node instead of distrolessUse gcr.io/distroless/nodejs22-debian12 or node:22.14-slimDistroless removes shells, package managers, and utilities — nothing for an attacker to exploit.
Show full SKILL.md (305 more words)Show less

Review Format (Required)

When reviewing Dockerfiles, use Before | After | Why format:

BeforeAfterWhy
FROM node:22-slimFROM node:22.14-slim@sha256:abc...Floating tags (22-slim) auto-update. Pin to immutable digest for reproducibility.
COPY . . before npm ciCOPY package*.json ./ then npm ci then COPY . .Docker caches each COPY layer. Copying source before deps invalidates cache on every code change.
CMD ["npm", "start"]Use node server.js directlyAvoids npm overhead in production. Use process manager (dumb-init, tini) for signal forwarding.
No .dockerignore.dockerignore with node_modules/, .git/, *.log, Dockerfile*Reduces build context size by 60-90%. Prevents leaking secrets from local .env.
Go multi-stage template
dockerfile
# syntax=docker/dockerfile:1.4
FROM golang:1.24-alpine AS builder
WORKDIR /app
COPY go.mod go.sum ./
RUN --mount=type=cache,target=/go/pkg/mod go mod download
COPY . .
RUN CGO_ENABLED=0 GOOS=linux go build -ldflags="-s -w" -o /server ./cmd/server

FROM gcr.io/distroless/static-debian12
COPY --from=builder /server /server
EXPOSE 8080
USER nonroot
HEALTHCHECK --interval=30s CMD ["/server", "-health"] || exit 1
ENTRYPOINT ["/server"]

Key decisions:

  • CGO_ENABLED=0 for static binary (no glibc dependency)
  • -ldflags="-s -w" strips debug symbols (reduces binary by 30%)
  • gcr.io/distroless/static-debian12 for CA certs + timezone data (needed for HTTPS/TLS)
  • If the binary needs nothing: use scratch (smaller, but no CA certs)
Python multi-stage template
dockerfile
# syntax=docker/dockerfile:1.4
FROM python:3.12-slim AS builder
WORKDIR /app
COPY requirements.txt .
RUN --mount=type=cache,target=/root/.cache/pip pip install --user -r requirements.txt

FROM python:3.12-slim
WORKDIR /app
COPY --from=builder /root/.local /root/.local
COPY src ./src
ENV PATH=/root/.local/bin:$PATH
EXPOSE 8000
RUN useradd -m app && chown -R app /app
USER app
HEALTHCHECK --interval=30s CMD python -c "import urllib.request; urllib.request.urlopen('http://localhost:8000/health')"
CMD ["gunicorn", "-w", "4", "-b", "0.0.0.0:8000", "src.main:app"]

Key decisions:

  • pip install --user avoids polluting /usr/local in builder
  • gunicorn with multiple workers handles concurrent requests
  • useradd creates a non-root user (distroless Python not available)
Rust multi-stage template
dockerfile
# syntax=docker/dockerfile:1.4
FROM rust:1.85-slim AS builder
WORKDIR /app
RUN apt-get update && apt-get install -y musl-tools && rm -rf /var/lib/apt/lists/*
COPY Cargo.toml Cargo.lock ./
RUN mkdir src && echo "fn main() {}" > src/main.rs
RUN --mount=type=cache,target=/usr/local/cargo/registry cargo build --release --target x86_64-unknown-linux-musl
RUN rm -rf src
COPY src ./src
RUN cargo build --release --target x86_64-unknown-linux-musl

FROM scratch
COPY --from=builder /app/target/x86_64-unknown-linux-musl/release/server /server
EXPOSE 8080
ENTRYPOINT ["/server"]

Key decisions:

  • musl-tools for static linking (no glibc dependency)
  • Dummy main.rs trick: compiles deps first, then source (cache deps)
  • scratch base: smallest possible, no shell, no tools
Seccomp profiles

Docker applies a default seccomp profile that blocks 44/300+ syscalls. Customize for your app:

json
{
  "defaultAction": "SCMP_ACT_ERRNO",
  "architectures": ["SCMP_ARCH_X86_64"],
  "syscalls": [
    { "names": ["read","write","open","close","fstat","mmap","mprotect","munmap","brk","rt_sigaction","rt_sigprocmask","rt_sigreturn","ioctl","pread64","pwrite64","readv","writev","access","pipe","select","sched_yield","mremap","msync","mincore","madvise","shmget","shmat","shmctl","dup","dup2","pause","nanosleep","getitimer","setitimer","alarm","getpid","sendfile","socket","connect","accept","sendto","recvfrom","sendmsg","recvmsg","shutdown","bind","listen","getsockname","getpeername","socketpair","setsockopt","getsockopt","clone","fork","vfork","execve","exit","wait4","kill","uname","semget","semop","semctl","shmdt","msgget","msgsnd","msgrcv","msgctl","fcntl","flock","fsync","fdatasync","truncate","ftruncate","getdents","getcwd","chdir","fchdir","rename","mkdir","rmdir","creat","link","unlink","symlink","readlink","chmod","fchmod","chown","fchown","lchown","umask","gettimeofday","getrlimit","getrusage","sysinfo","times","preadv","pwritev","rt_sigtimedwait","futex","set_robust_list","get_robust_list","epoll_wait","epoll_ctl","epoll_create","epoll_pwait","epoll_create1","eventfd","signalfd","timerfd_create","timerfd_gettime","timerfd_settime","prctl","getcpu","process_vm_readv","process_vm_writev"], "action": "SCMP_ACT_ALLOW" }
  ]
}

Usage: docker run --security-opt seccomp=profile.json myapp

CVE scanning pipeline
bash
# Full scan pipeline
docker build -t myapp:latest .
trivy image --severity HIGH,CRITICAL --exit-code 1 myapp:latest
docker scout cves --exit-code myapp:latest

# CI integration (GitHub Actions)
- uses: aquasecurity/trivy-action@master
  with:
    image-ref: myapp:latest
    format: sarif
    output: trivy-results.sarif
    severity: HIGH,CRITICAL
    exit-code: 1

# Continuous monitoring
docker scout enroll myorg/myapp
docker scout watch myapp:latest

If CVEs found: switch base image to newer distroless tag, rebuild, re-scan. Track with docker scout recommendations.

Sources

  • Dockerfile best practices (docs.docker.com)
  • BuildKit documentation
  • Google distroless images
  • Trivy vulnerability scanner
  • Docker Scout documentation
  • SLSA framework (slsa.dev)

Checklist

  • Skill loads without errors in the AI agent
  • YAML frontmatter is valid (description, compatibility, audience)
  • Workflow section provides clear step-by-step instructions
  • Error handling section covers common failure modes
  • All referenced files (references/, scripts/, assets/) exist
  • Skill triggers correctly for intended use cases
  • No broken links or missing resources

© EliasOulkadi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in .pack/skills/docker of EliasOulkadi/shokunin.

  • SKILL.md
  • assets/docker-compose.template.yml
  • references/multi-arch.md
  • scripts/optimize-dockerfile.sh
  • scripts/scan-image.sh

Open the folder on GitHubat commit 4c68e5b

Compare with similar skills

Docker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Docker compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Docker this skillEliasOulkadi/shokunin114—~3.8kAutomated safety check: NotesMIT
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence
Security Analyzeraiskillstore/marketplace433—~1.2kAutomated safety check: NotesNone
Alibabacloud Ecs Sec Userspacealiyun/alibabacloud-ecs-troubleshoot-skills148—~2.6kAutomated safety check: NotesApache-2.0
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Container Securityhardw00t/ai-security-arsenal105—~2.8kAutomated safety check: PassNone

Similar skills

  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    433 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check: notes
  • Alibabacloud Ecs Sec Userspace

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。

    148 GitHub stars~2.6k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    105 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Scanning Kubernetes Manifests With Kubesec

    mukul975/Anthropic-Cybersecurity-Skills

    Scores Kubernetes resource manifests with Kubesec to flag misconfiguration and privilege-escalation risk before deployment, mapping each finding back to the securityContext change that fixes it.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from EliasOulkadi/shokunin

All 49 skills in this repo
  • CI CD

    EliasOulkadi/shokunin

    Design CI/CD pipelines for GitHub Actions, GitLab CI, and CircleCI with matrix builds, test sharding, caching, Docker layer caching, OIDC auth, deployment strategies (rolling, blue-green, canary)…

    114 GitHub stars~3.4k tokensUpdated 5 days ago
    Auto-check: notes
  • Component Forge

    EliasOulkadi/shokunin

    Build production-grade components for React, Vue 3, and Svelte 5 with all states (loading, empty, error, success, idle), TypeScript strict, WCAG 2.2 accessibility, server components (RSC), and…

    114 GitHub stars~3.6k tokensUpdated 5 days ago
    Auto-check: notes
  • DB Admin

    EliasOulkadi/shokunin

    PostgreSQL database administration — backup/restore (pgdump, PITR, WAL archiving), health monitoring (connections, bloat, cache hit ratio, dead tuples), connection pooling (PgBouncer), replication…

    114 GitHub stars~2k tokensUpdated 5 days ago
    Auto-check: notes
  • DB Sculptor

    EliasOulkadi/shokunin

    Design database schemas with Prisma/Drizzle, PostgreSQL index strategy (B-tree, GIN, GiST, BRIN, Hash), query optimization (EXPLAIN ANALYZE), migration safety (expand/contract, zero-downtime), and…

    114 GitHub stars~3.1k tokensUpdated 5 days ago
    Auto-check: notes
  • Error Handler

    EliasOulkadi/shokunin

    Design error handling, structured logging, and observability with OpenTelemetry (traces, metrics, logs), error classification, recovery patterns (retry with jitter, circuit breaker, bulkhead…

    114 GitHub stars~3.6k tokensUpdated 5 days ago
    Auto-check: notes
  • Kubernetes

    EliasOulkadi/shokunin

    Deploy, manage, and debug Kubernetes in production — Deployments, Services, Gateway API, Service Mesh (Istio/Linkerd/Cilium), eBPF observability (Cilium Hubble), security hardening (Pod Security…

    114 GitHub stars~3.3k tokensUpdated 5 days ago
    Auto-check: notes

Categories

Questions about Docker

What does Docker do?

Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and…. Docker is an agent skill from EliasOulkadi/shokunin. Optimize Docker images with multi-stage builds, distroless bases, BuildKit cache mounts, multi-arch builds, compose watch, security hardening (non-root, seccomp, capabilities drop), and vulnerability scanning via docker scout/trivy.

When should I use Docker?

Docker fits situations like: user asks to write a Dockerfile; optimize image size; set up docker-compose; debug containers.

How do I install Docker in Claude Code?

Run `npx skills add EliasOulkadi/shokunin --skill docker -a claude-code`. Or copy the skill folder (.pack/skills/docker in EliasOulkadi/shokunin) into .claude/skills/docker in your project. Claude Code loads it when a task matches its description.

How do I install Docker in Codex?

Run `npx skills add EliasOulkadi/shokunin --skill docker -a codex`. Or copy the skill folder (.pack/skills/docker in EliasOulkadi/shokunin) into .agents/skills/docker in your project. Codex loads it when a task matches its description.

Can I use Docker in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EliasOulkadi/shokunin --skill docker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/docker, .gemini/skills/docker, .github/skills/docker and .opencode/skills/docker in your project.

What does Docker need to run?

Going by SKILL.md and its folder, Docker needs a shell for the scripts in its folder and the command-line tools its instructions call (docker, npm, trivy, node and pip). Our summary lists: Python 3; Node.js; A Bash shell; Docker. Its frontmatter pre-approves these tools: Read, Bash, Write. Compatibility (from SKILL.md): opencode.

Does Docker access the network?

SKILL.md contains no URLs. Its commands use docker, npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Docker safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Docker use?

Docker is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Docker use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.

What are the alternatives to Docker?

Skills that share tags, products or a category with Docker: Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars), Security Analyzer (aiskillstore/marketplace, 433 stars), Alibabacloud Ecs Sec Userspace (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars) and Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Docker?

EliasOulkadi (a GitHub user) maintains it in EliasOulkadi/shokunin, which has 114 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 5, 2026.

Source: EliasOulkadi/shokunin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.