Agent skill

Scanning Container Security

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Execute use when you need to work with security and compliance.

MITAuto-check passedDevOps & Cloud

Install Scanning Container Security

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill scanning-container-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace scanning-container-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/scanning-container-security .claude/skills/scanning-container-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
scanning-container-security
GitHub stars
2.8k
Token cost
~1.1k tokens
SKILL.md length
471 words
Files
6 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Execute use when you need to work with security and compliance.

  • Works in 9 steps: Identify target images for scanning:… → Lint Dockerfiles with hadolint… → Scan built images for OS-level… → …
  • You need to work with security and compliance
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Runs Python scripts from its folder; calls docker, trivy and hadolint

What it does

Scanning Container Security is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute use when you need to work with security and compliance. This skill provides security scanning and vulnerability detection with comprehensive guidance and automation. Trigger with phrases like "scan for vulnerabilities", "implement security controls", or "audit security".

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts, reference files and assets (for example `assets/README.md`, `references/README.md` and `scripts/README.md`). Compatibility notes: Designed for Claude Code

It sits in DevOps & Cloud, covering Cloud security and Containers. It works with Docker and Trivy. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • You need to work with security and compliance
  • With phrases like scan for vulnerabilities
  • Implement security controls

Example prompts

  • “scan for vulnerabilities”
  • “implement security controls”
  • “audit security”
  • “/scanning-container-security”

Requirements

  • Python 3
  • Docker
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Glob, Bash(docker:*), Bash(kubectl:*)

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Identify target images for scanning: production images, base images, and CI-built images
  2. Lint Dockerfiles with hadolint Dockerfile to catch misconfigurations before build (privileged instructions, pinned versions, shell best…
  3. Scan built images for OS-level vulnerabilities: trivy image or grype
  4. Scan for application dependency vulnerabilities: check language-specific packages (npm, pip, Maven, Go modules) embedded in the image
  5. Check for secrets accidentally baked into image layers: trivy image --scanners secret
  6. Evaluate image against CIS Docker Benchmark: verify non-root user, read-only filesystem capability, health checks defined
  7. Generate a security report with severity classification (Critical, High, Medium, Low) and CVE identifiers
  8. Produce remediation steps: upgrade base image, pin package versions, replace vulnerable dependencies
  9. Integrate scanning into CI/CD pipeline: fail builds on Critical/High vulnerabilities, generate SARIF output for GitHub Security tab

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Glob
    • Bash(docker:*)
    • Bash(kubectl:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • docker
    • trivy
    • hadolint
    • apt-get

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • aquasecurity.github.io
    • docs.docker.com
    • cisecurity.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Scanning Container Security loads about 1.1k tokens when it runs, and up to ~1.1k if it reads all its reference files. Until then it costs about 77 tokens; SKILL.md has 471 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 471 words, ~1,086 tokens.

Download SKILL.mdSave it as .claude/skills/scanning-container-security/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
scanning-container-security
description
Execute use when you need to work with security and compliance. This skill provides security scanning and vulnerability detection with comprehensive guidance and automation. Trigger with phrases like "scan for vulnerabilities", "implement security controls", or "audit security".
allowed-tools
Read, Write, Edit, Grep, Glob, Bash(docker:*), Bash(kubectl:*)
compatibility
Designed for Claude Code
version
1.27.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
devops, security, compliance, audit

Scanning Container Security

Overview

Scan container images and Dockerfiles for vulnerabilities, misconfigurations, and compliance violations using Trivy, Grype, Snyk Container, and Hadolint. Analyze base images, OS packages, application dependencies, and runtime configurations to produce actionable security reports with remediation guidance.

Prerequisites

  • Container scanning tool installed: trivy, grype, snyk, or docker scout
  • Dockerfile linter: hadolint for Dockerfile best practice validation
  • Docker daemon running for local image scanning
  • Access to the container images to scan (local, registry, or tar archive)
  • jq for parsing JSON scan results

Instructions

  1. Identify target images for scanning: production images, base images, and CI-built images
  2. Lint Dockerfiles with hadolint Dockerfile to catch misconfigurations before build (privileged instructions, pinned versions, shell best practices)
  3. Scan built images for OS-level vulnerabilities: trivy image <image:tag> or grype <image:tag>
  4. Scan for application dependency vulnerabilities: check language-specific packages (npm, pip, Maven, Go modules) embedded in the image
  5. Check for secrets accidentally baked into image layers: trivy image --scanners secret <image:tag>
  6. Evaluate image against CIS Docker Benchmark: verify non-root user, read-only filesystem capability, health checks defined
  7. Generate a security report with severity classification (Critical, High, Medium, Low) and CVE identifiers
  8. Produce remediation steps: upgrade base image, pin package versions, replace vulnerable dependencies
  9. Integrate scanning into CI/CD pipeline: fail builds on Critical/High vulnerabilities, generate SARIF output for GitHub Security tab

Output

  • Vulnerability scan report in JSON, table, or SARIF format
  • Hadolint report with Dockerfile improvement recommendations
  • Remediation Dockerfile patches (updated base image, pinned package versions)
  • CI/CD pipeline step configuration for automated image scanning
  • Security policy document defining acceptable risk thresholds
Show full SKILL.md (208 more words)Show less

Error Handling

ErrorCauseSolution
trivy: unable to pull imageImage not found locally or registry auth failurePull image first with docker pull or configure registry credentials
CRITICAL vulnerability found but no fix availableUpstream package has no patch yetDocument as accepted risk, use --ignore-unfixed flag, or switch to an alternative base image
hadolint: DL3008 pin versions in apt-get installPackages installed without version pinningAdd version pins (e.g., apt-get install nginx=1.24.0-1) or use --no-install-recommends
Scan timeout on large imageImage has many layers or large filesystemUse --timeout 15m flag; scan a specific layer or use --skip-dirs to exclude test data
False positive CVEScanner database maps CVE to a package not actually exploitableAdd to .trivyignore or Grype ignore file with justification comment

Examples

  • "Scan all production Docker images for Critical and High CVEs, generate a report, and create Jira tickets for each finding."
  • "Lint the Dockerfile for best practices: ensure multi-stage build, non-root USER, no ADD for remote URLs, and pinned base image digest."
  • "Set up a GitHub Actions step that runs Trivy on every PR, fails on Critical vulnerabilities, and uploads results to the Security tab via SARIF."

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references, assets) in skills/.curated/scanning-container-security of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • references/README.md
  • scripts/README.md
  • scripts/snyk_scan.py
  • scripts/trivy_scan.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Scanning Container Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Scanning Container Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Scanning Container Security this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMIT
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Cloud AuditCommonHuman-Lab/nyxstrike157—~1.1kAutomated safety check: PassCustom licence
Container Securityhardw00t/ai-security-arsenal105—~2.8kAutomated safety check: PassNone
Scanning Docker Images With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: WarnApache-2.0
Implementing Container Image Minimal Base With Distrolessmukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.0

Similar skills

  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Cloud Audit

    CommonHuman-Lab/nyxstrike

    Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images

    157 GitHub stars~1.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    105 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Scanning Docker Images With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Scans a Docker image with Trivy for vulnerabilities in OS packages and language dependencies, misconfiguration, exposed secrets, and licence violations, emitting SARIF, CycloneDX, or SPDX output.

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: warnings
  • Implementing Container Image Minimal Base With Distroless

    mukul975/Anthropic-Cybersecurity-Skills

    Reduces container attack surface by building application images on Google distroless base images that ship only the application runtime - no shell, package manager, or OS utilities - using…

    34k GitHub stars~1.7k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Scanning Containers With Trivy In Cicd

    mukul975/Anthropic-Cybersecurity-Skills

    Integrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Scanning Container Security

What does Scanning Container Security do?

Execute use when you need to work with security and compliance. Scanning Container Security is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute use when you need to work with security and compliance.

When should I use Scanning Container Security?

Scanning Container Security fits situations like: you need to work with security and compliance; with phrases like scan for vulnerabilities; implement security controls.

How do I install Scanning Container Security in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill scanning-container-security -a claude-code`. Or copy the skill folder (skills/.curated/scanning-container-security in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/scanning-container-security in your project. Claude Code loads it when a task matches its description.

How do I install Scanning Container Security in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill scanning-container-security -a codex`. Or copy the skill folder (skills/.curated/scanning-container-security in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/scanning-container-security in your project. Codex loads it when a task matches its description.

Can I use Scanning Container Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill scanning-container-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/scanning-container-security, .gemini/skills/scanning-container-security, .github/skills/scanning-container-security and .opencode/skills/scanning-container-security in your project.

What does Scanning Container Security need to run?

Going by SKILL.md and its folder, Scanning Container Security needs Python for the scripts in its folder and the command-line tools its instructions call (docker, trivy, hadolint and apt-get). Our summary lists: Python 3; Docker. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(docker:*), Bash(kubectl:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Scanning Container Security access the network?

SKILL.md names 4 domains. As links in the text: github.com, aquasecurity.github.io, docs.docker.com and cisecurity.org. This is read from the text; nothing was executed.

Is Scanning Container Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Scanning Container Security use?

Scanning Container Security is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Scanning Container Security use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 18 tokens, read only when the agent opens those files.

What are the alternatives to Scanning Container Security?

Skills that share tags, products or a category with Scanning Container Security: Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Cloud Audit (CommonHuman-Lab/nyxstrike, 157 stars), Container Security (hardw00t/ai-security-arsenal, 105 stars) and Scanning Docker Images With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Scanning Container Security?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.