CtrlK
BlogDocsLog inGet started
Tessl Logo

container-security

Comprehensive container image security scanning and remediation. Analyzes Docker images for OS package vulnerabilities, application dependencies, and Dockerfile best practices. Use when: - User asks to scan a Docker image or container - User mentions "container security" or "image vulnerabilities" - User wants to secure a Dockerfile - User asks about base image security - Agent is working with Docker, Kubernetes, or container deployments

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable and well-sequenced content with strong validation loops, but it underuses its own bundle: two reference files exist for content that is instead inlined in the body, and the example/scenario sections restate the phased workflow. Tightening redundancy and pointing to the reference files would lift the weaker dimensions.

Suggestions

Replace the inlined 'Base Image Quick Reference' table with a brief pointer to references/base-image-recommendations.md, and similarly route 'Dockerfile Best Practices' to references/dockerfile-best-practices.md, so the reference files are actually signaled one level deep.

Merge or trim the 'End-to-End Example' and 'Common Scenarios' sections, which restate the Phase 1-5 workflow, to reduce redundancy and token cost.

Drop the bare 'Quick Start' numbered list (lines 33-38) since it duplicates the phase sequence that follows immediately.

DimensionReasoningScore

Conciseness

Mostly efficient and free of concept-padding (it never explains what Docker/containers are), but the 'End-to-End Example' and 'Common Scenarios' sections substantially restate the Phase 1-5 content, and templated output blocks repeat similar structures — tightening would help.

3 / 5

Actionability

Fully executable guidance throughout: exact tool calls like 'mcp_snyk_snyk_container_scan(image="app:latest", app_vulns=true)', shell commands like 'docker build --no-cache -t myapp:fixed .', and copy-paste Dockerfile patches ('RUN apk add --no-cache openssl>=3.0.12') cover the common cases.

5 / 5

Workflow Clarity

Five clearly sequenced phases (Identify → Scan → Analyze → Remediate → Verify) with an explicit validation feedback loop in Phase 5 (rebuild → re-scan → compare results) and a Constraints checklist; the end-to-end example reinforces the fix→verify loop.

5 / 5

Progressive Disclosure

The body is well-structured into phases, but the 'Base Image Quick Reference' and 'Dockerfile Best Practices' sections are inlined even though dedicated references/base-image-recommendations.md and references/dockerfile-best-practices.md exist and are never linked or signaled from the body — content that belongs in those files is duplicated inline.

3 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-formed description: third-person voice, concrete capability list, and an explicit multi-clause 'Use when' trigger block. The leading word 'Comprehensive' is mild fluff but is backed by specific enumerated actions, so it does not drag the score down.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'security scanning and remediation', 'Analyzes Docker images for OS package vulnerabilities, application dependencies, and Dockerfile best practices' — giving comprehensive coverage of the container-security domain rather than vague language.

5 / 5

Completeness

Explicitly answers both: WHAT ('Comprehensive container image security scanning and remediation. Analyzes Docker images for...') and WHEN (a dedicated 'Use when:' block with five concrete trigger clauses), matching the top anchor.

5 / 5

Trigger Term Quality

Natural user-facing phrases abound — 'scan a Docker image or container', 'container security', 'image vulnerabilities', 'secure a Dockerfile', 'base image security', 'Docker, Kubernetes, or container deployments' — covering synonyms and runtime variations a user would actually say.

5 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (container image security scanning/remediation) with triggers scoped to Docker/container/image-vulnerability language, making conflict with unrelated skills minimal.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
snyk/studio-recipes
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.