Container Security Auditor - Auto-activating skill for Security Advanced. Triggers on: container security auditor, container security auditor Part of the Security Advanced skill category.
36
Quality
3%
Does it follow best practices?
Impact
99%
1.00xAverage score across 3 eval scenarios
Passed
No known issues
Optimize this skill with Tessl
npx tessl skill review --optimize ./planned-skills/generated/04-security-advanced/container-security-auditor/SKILL.mdDockerfile security audit with standards validation
Step-by-step report structure
100%
100%
Standards reference: base image
100%
100%
Standards reference: general findings
100%
100%
Hardened base image
100%
100%
No hardcoded secrets
100%
100%
Non-root user
100%
100%
Unnecessary packages removed
100%
100%
Excessive permissions removed
100%
100%
Minimized exposed ports
100%
100%
DEBUG disabled
100%
100%
Production-ready Dockerfile
100%
100%
Risk explanation per finding
100%
100%
Without context: $0.4207 · 2m 21s · 17 turns · 18 in / 7,496 out tokens
With context: $0.5059 · 2m 41s · 25 turns · 58 in / 8,774 out tokens
SOC2/GDPR compliance assessment for containerized services
SOC 2 criteria cited
100%
100%
GDPR articles cited
100%
100%
Structured by domain
75%
62%
DB port not publicly bound
100%
100%
Redis port not publicly bound
100%
100%
Secrets removed from environment
100%
100%
Internal network isolation
100%
100%
Pinned image versions
100%
100%
Debug logging addressed
100%
100%
Production-ready compose file
100%
100%
Remediation per finding
100%
100%
Read-only filesystem recommended
100%
100%
Without context: $0.4249 · 2m 23s · 18 turns · 18 in / 8,223 out tokens
With context: $0.4724 · 2m 20s · 20 turns · 19 in / 8,469 out tokens
Container threat modeling with STRIDE analysis
Systematic methodology used
100%
100%
Trust boundaries identified
100%
100%
Container-specific threats
100%
100%
Likelihood and impact assessed
100%
100%
Unencrypted inter-service traffic threat
100%
100%
Kubernetes namespace isolation threat
100%
100%
Step-by-step structure
100%
100%
mTLS mitigation included
100%
100%
Least-privilege container mitigations
100%
100%
Production-ready mitigations
100%
100%
Prioritized mitigations
100%
100%
Image supply chain threat
100%
100%
Without context: $0.4202 · 3m 15s · 12 turns · 61 in / 10,094 out tokens
With context: $0.6955 · 3m 57s · 25 turns · 26 in / 12,643 out tokens
994edc4
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.