Agent skill

Security Review Skill For Docker

by xwtro0tk1t-cloud in xwtro0tk1t-cloud/harness

审计 Docker/容器部署安全。检测 Dockerfile、docker-compose.yml、Kubernetes manifests 中的安全问题:特权容器、root 运行、敏感挂载、资源无限制、密钥泄露、Base Image 不合规、网络暴露等。当审计容器配置、Docker 安全、K8s 部署安全、或检查基础设施安全时使用。支持…

No licenceAuto-check: warningsDevOps & Cloud

Install Security Review Skill For Docker

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add xwtro0tk1t-cloud/harness --skill security-review-skill-for-docker -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install xwtro0tk1t-cloud/harness security-review-skill-for-docker --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/xwtro0tk1t-cloud/harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/bundled-skills/security-review-skill-for-docker .claude/skills/security-review-skill-for-docker && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-review-skill-for-docker
GitHub stars
265
Token cost
~2.8k tokens
SKILL.md length
673 words
Files
5
Skills in repo
7
Repo updated
First seen
Licence
None found

At a glance

审计 Docker/容器部署安全。检测 Dockerfile、docker-compose.yml、Kubernetes manifests 中的安全问题:特权容器、root 运行、敏感挂载、资源无限制、密钥泄露、Base Image 不合规、网络暴露等。当审计容器配置、Docker 安全、K8s 部署安全、或检查基础设施安全时使用。支持…

  • Works in 6 steps: 侦察 — 发现所有容器配置文件 → 正则扫描(必须执行) → 逐文件深度审计 → …
  • Tasks that involve Containers
  • SKILL.md covers 适用范围, 审计模式, 审计方法论 and 误报过滤, plus 3 more sections
  • Calls git and apk; needs APP_SECRET and API_KEY

What it does

Security Review Skill For Docker is an agent skill from xwtro0tk1t-cloud/harness. 审计 Docker/容器部署安全。检测 Dockerfile、docker-compose.yml、Kubernetes manifests 中的安全问题:特权容器、root 运行、敏感挂载、资源无限制、密钥泄露、Base Image 不合规、网络暴露等。当审计容器配置、Docker 安全、K8s 部署安全、或检查基础设施安全时使用。支持 Dockerfile、docker-compose.yml、Kubernetes YAML、Helm charts。

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files (for example `checks/compose-k8s-security.md`, `checks/dockerfile-security.md` and `checks/secrets-supply-chain.md`).

It sits in DevOps & Cloud, covering Containers and Container orchestration. It works with Docker, Kubernetes and Helm. The repository describes itself as: Harness is an AI Agent development guardrail Meta-Skill that establishes four layers of defense for any project in one command: knowledge management, architecture constraints…

When your agent uses it

  • Tasks that involve Containers
  • Tasks that involve Container orchestration

Example prompts

  • “/security-review-skill-for-docker”

Requirements

  • Docker
  • A credential in API_KEY

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. 侦察 — 发现所有容器配置文件
  2. 正则扫描(必须执行)
  3. 逐文件深度审计
  4. 跨文件一致性检查
  5. 攻防验证
  6. 覆盖评估

What it can do on your machine

Read from SKILL.md and the folder at commit 3e8bb50. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • apk

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • APP_SECRET
    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Review Skill For Docker loads about 2.8k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 673 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • NoteMentions a .env fileSKILL.md:87
    .*\\.env", glob="*Dockerfile*")   # 禁止复制 .env
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:90
    Grep("COPY.*\\.pem|COPY.*\\.key|COPY.*id_rsa", glob="*Dockerfile*")  # 复制私钥
  • NoteMentions a .env fileSKILL.md:160
    | F5 | 无 COPY .env | CRITICAL | 禁止 `COPY .env` / `ADD .env` / `COPY *.env` |
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:162
    | 无私钥复制 | CRITICAL | 禁止 COPY .pem/.key/id_rsa 到 final stage |
  • WarningPipes a downloaded script straight into a shellSKILL.md:168
    | F13 | 无 pipe to shell | HIGH | 禁止 `curl|bash` / `wget|sh` |
  • NoteMentions a .env fileSKILL.md:169
    MEDIUM | 项目根目录必须有 .dockerignore,排除 .git/.env/node_modules/*.key |
  • NoteMentions a .env fileSKILL.md:182
    H | `environment:` 中密钥必须引用变量 `${VAR}` 或 `.env`,不能明文写入 |
  • NoteMentions a .env fileSKILL.md:213
    4. **.dockerignore 是否排除了 .env,但 compose 中又 COPY 了** → 交叉检查

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 673 words (~2,792 tokens).

name
security-review-skill-for-docker

Read the full SKILL.md on GitHub

Files

SKILL.md and 4 other files in bundled-skills/security-review-skill-for-docker of xwtro0tk1t-cloud/harness.

  • SKILL.md
  • checks/compose-k8s-security.md
  • checks/dockerfile-security.md
  • checks/secrets-supply-chain.md
  • known-issues/common-vulnerabilities.md

Open the folder on GitHubat commit 3e8bb50

Compare with similar skills

Security Review Skill For Docker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Review Skill For Docker compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Review Skill For Docker this skillxwtro0tk1t-cloud/harness265—~2.8kAutomated safety check: WarnNone
Ama Logs Update Charts Release Notesmicrosoft/Docker-Provider174—~2.6kAutomated safety check: PassCustom licence
Containerizing Applicationsaiskillstore/marketplace430—~1.9kAutomated safety check: PassNone
Project Referencesaiskillstore/marketplace430—~2.3kAutomated safety check: NotesNone
Containerizationkid-sid/claude-spellbook190—~4.2kAutomated safety check: NotesMIT
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0

Similar skills

  • Ama Logs Update Charts Release Notes

    microsoft/Docker-Provider

    Official

    Prepare an ama-logs release PR: bump the image tag (X.Y.Z) across Helm charts, manifests, and Dockerfiles, and add a formatted ReleaseNotes.md entry.

    174 GitHub stars~2.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Containerizing Applications

    aiskillstore/marketplace

    Containerizes applications with Docker, docker-compose, and Helm charts.

    430 GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Project References

    aiskillstore/marketplace

    Look up conventions, patterns, and concrete implementations from your own GitHub repositories checked out locally under ~/projects/referenzen/.

    430 GitHub stars~2.3k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Containerization

    kid-sid/claude-spellbook

    A skill your agent uses when configuring Kubernetes resources (Deployment, Service, Ingress, ConfigMap, Secret, HPA), sizing pod resource requests and limits, setting securityContext, or packaging a…

    190 GitHub stars~4.2k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    16k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed

More from xwtro0tk1t-cloud/harness

  • Design Review

    xwtro0tk1t-cloud/harness

    Dispatch an independent challenger agent to adversarially review a spec or implementation plan against the actual codebase.

    265 GitHub stars~1.6k tokensUpdated 5 mo ago
    Auto-check passed
  • Explore

    xwtro0tk1t-cloud/harness

    Graph-driven project understanding using code-review-graph (CRG).

    265 GitHub stars~1.6k tokensUpdated 5 mo ago
    Auto-check passed
  • Graph

    xwtro0tk1t-cloud/harness

    Manage code knowledge graphs via code-review-graph (CRG). An agent skill from xwtro0tk1t-cloud/harness.

    265 GitHub stars~1.1k tokensUpdated 5 mo ago
    Auto-check passed
  • Sca AI Denoise

    xwtro0tk1t-cloud/harness

    SCA 漏洞 AI 降噪与风险优先级评估。对 Grype/Snyk/Xray 等 SCA 工具的漏洞发现进行多维度风险评估,按 P0-P3 分级,过滤噪音(DoS、本地提权、低影响信息泄露),聚焦真正可利用的高风险漏洞。当用户需要对 SCA 扫描结果降噪、漏洞优先级排序、或供应链风险评估时使用。

    265 GitHub stars~787 tokensUpdated 5 mo ago
    Auto-check passed
  • Security Review Skill Creator

    xwtro0tk1t-cloud/harness

    生成安全审计 skill。两种模式:(1) 项目模式——根据项目文档生成定制化审计 skill;(2) 通用模式——仅指定语言+框架,从参考资料库生成通用审计 skill。当用户想创建安全审计 skill、生成审计规则、或提到"生成安全审计skill"、"创建code review skill"、"生成 Java 审计 skill"时使用。

    265 GitHub stars~5.7k tokensUpdated 5 mo ago
    Auto-check passed
  • Security Review Skill For Terraform

    xwtro0tk1t-cloud/harness

    审计 Terraform / IaC 代码安全(AWS 基础设施)。检测硬编码凭据、过宽 Security Group(0.0.0.0/0)、IAM 权限过大(Action/Resource )、S3 公开访问、RDS 未加密/公开、State 文件泄露、ECS/EKS 容器特权、CloudTrail/VPC FlowLog 缺失、不安全 Provider/Module 引用等。当审计…

    265 GitHub stars~4.4k tokensUpdated 5 mo ago
    Auto-check passed

Categories

Questions about Security Review Skill For Docker

What does Security Review Skill For Docker do?

审计 Docker/容器部署安全。检测 Dockerfile、docker-compose.yml、Kubernetes manifests 中的安全问题:特权容器、root 运行、敏感挂载、资源无限制、密钥泄露、Base Image 不合规、网络暴露等。当审计容器配置、Docker 安全、K8s 部署安全、或检查基础设施安全时使用。支持…. Security Review Skill For Docker is an agent skill from xwtro0tk1t-cloud/harness.

When should I use Security Review Skill For Docker?

Security Review Skill For Docker fits situations like: tasks that involve Containers; tasks that involve Container orchestration.

How do I install Security Review Skill For Docker in Claude Code?

Run `npx skills add xwtro0tk1t-cloud/harness --skill security-review-skill-for-docker -a claude-code`. Or copy the skill folder (bundled-skills/security-review-skill-for-docker in xwtro0tk1t-cloud/harness) into .claude/skills/security-review-skill-for-docker in your project. Claude Code loads it when a task matches its description.

How do I install Security Review Skill For Docker in Codex?

Run `npx skills add xwtro0tk1t-cloud/harness --skill security-review-skill-for-docker -a codex`. Or copy the skill folder (bundled-skills/security-review-skill-for-docker in xwtro0tk1t-cloud/harness) into .agents/skills/security-review-skill-for-docker in your project. Codex loads it when a task matches its description.

Can I use Security Review Skill For Docker in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xwtro0tk1t-cloud/harness --skill security-review-skill-for-docker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review-skill-for-docker, .gemini/skills/security-review-skill-for-docker, .github/skills/security-review-skill-for-docker and .opencode/skills/security-review-skill-for-docker in your project.

What does Security Review Skill For Docker need to run?

Going by SKILL.md and its folder, Security Review Skill For Docker needs the command-line tools its instructions call (git and apk) and credentials named APP_SECRET and API_KEY. Our summary lists: Docker; A credential in API_KEY.

Does Security Review Skill For Docker access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Review Skill For Docker safe to install?

Our automated static check of SKILL.md flagged 3 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens); pipes a downloaded script straight into a shell. Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Security Review Skill For Docker use?

No licence was found for Security Review Skill For Docker or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Security Review Skill For Docker use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Review Skill For Docker?

Skills that share tags, products or a category with Security Review Skill For Docker: Ama Logs Update Charts Release Notes (microsoft/Docker-Provider, 174 stars), Containerizing Applications (aiskillstore/marketplace, 430 stars), Project References (aiskillstore/marketplace, 430 stars) and Containerization (kid-sid/claude-spellbook, 190 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Review Skill For Docker?

xwtro0tk1t-cloud (a GitHub user) maintains it in xwtro0tk1t-cloud/harness, which has 265 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on May 4, 2026.

Source: xwtro0tk1t-cloud/harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.