CtrlK
BlogDocsLog inGet started
Tessl Logo

container-security

Comprehensive container image security scanning and remediation. Analyzes Docker images for OS package vulnerabilities, application dependencies, and Dockerfile best practices. Use when: - User asks to scan a Docker image or container - User mentions "container security" or "image vulnerabilities" - User wants to secure a Dockerfile - User asks about base image security - Agent is working with Docker, Kubernetes, or container deployments

71

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced operational skill with concrete tool invocations, commands, and a verification loop. Its main weaknesses are token efficiency — generic Docker best practices and an aging base-image table are inlined — and poor progressive disclosure: the two reference files in the bundle are never referenced, so their detail is unreachable and partially duplicated in condensed form.

Suggestions

Link the existing bundle files: replace the inline 'Base Image Quick Reference' section with a pointer to references/base-image-recommendations.md and the Step 4.4 Dockerfile practices with a pointer to references/dockerfile-best-practices.md, so the richer curated detail is actually reachable.

Move version-pinned recommendations (node:20, python:3.12, 'default: yes for v1.1090.0+') out of SKILL.md into a maintained reference file to keep the body stable as versions age.

Tighten the response templates in Steps 3.2, 4.1–4.3 (overview tables, fix blocks) to skeleton formats, cutting placeholder rows and repeated scaffolding.

DimensionReasoningScore

Conciseness

The operational core (Phases 1–5) is efficient, but the body inlines generic Docker knowledge Claude already has — the Step 4.4 Dockerfile best practices (pin tags, non-root, multi-stage, --no-install-recommends) and a 7-row Base Image Quick Reference table — and it carries time-sensitive version pins (node:20, python:3.12, "v1.1090.0+") outside any maintenance section, plus lengthy response templates. This is 'mostly efficient but includes some unnecessary explanation or could be tightened' (3); it is not 2 because there is no tutorial-style padding of basic concepts, and not 4 because the duplicated inline reference material is a real trim target.

3 / 5

Actionability

Every phase gives executable guidance: concrete MCP invocations with named parameters (image, file, app_vulns, severity_threshold, exclude_base_image_vulns), literal call syntax in the end-to-end example (snyk_container_scan(image="app:latest", app_vulns=true)), copy-paste docker build/rebuild commands, and an error-to-solution table. This matches 'fully executable; copy-paste ready code or commands; specific examples cover the common cases' — not 4, since no invocation lacks the specifics needed to run it.

5 / 5

Workflow Clarity

The skill sequences a clear 5-phase workflow (identify → scan → analyze → remediate → verify) with an explicit validation checkpoint: Phase 5 rebuilds with --no-cache, re-scans, and compares before/after counts, and the Error Handling table plus 'Remaining Issues' handling in Step 5.3 provide recovery loops. This matches 'clear sequence with explicit validation steps; feedback loops for error recovery'; scanning/remediation is not an unvalidated destructive or batch operation, so no cap applies.

5 / 5

Progressive Disclosure

The body is well-sectioned, but the two existing bundle files (references/base-image-recommendations.md, 242 lines; references/dockerfile-best-practices.md, 369 lines) are never mentioned or linked anywhere in the body, while condensed versions of their content (the Base Image Quick Reference table and Dockerfile practices section) are inlined instead. This is 'references present but not clearly signaled; content that should be separate is inline' (3); it is not 4 because the references are not merely unclearly signaled — they are entirely orphaned, so Claude would never load the richer detail — and not 2 because the body itself has solid structure and the inlined material is condensed rather than a monolithic wall.

3 / 5

Total

16

/

20

Passed

Description

96%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concrete, and specific about what it does, with an explicit multi-condition 'Use when' trigger list using natural user phrasing. The only weakness is the overly broad Docker/Kubernetes catch-all trigger, which slightly raises conflict risk with general container/Dockerfile skills.

DimensionReasoningScore

Specificity

"Comprehensive container image security scanning and remediation. Analyzes Docker images for OS package vulnerabilities, application dependencies, and Dockerfile best practices" lists multiple concrete actions (scan OS packages, scan app dependencies, analyze Dockerfile practices, remediate) with broad coverage of the domain. This matches the anchor 'Lists multiple specific concrete actions; comprehensive coverage' — it does not fall to 4 because no meaningful capability of the workflow is left unnamed.

5 / 5

Completeness

The description explicitly answers 'what' ("Analyzes Docker images for OS package vulnerabilities, application dependencies, and Dockerfile best practices") and 'when' via an explicit "Use when:" clause with five concrete trigger conditions. This mirrors the anchor-5 example pattern ('Clearly and explicitly answers both what AND when with concrete trigger phrases'); a 'when' clause is present and specific, so the level-4 anchor ('when could be more explicit') does not apply.

5 / 5

Trigger Term Quality

The trigger list covers natural phrases users would actually say: "scan a Docker image or container", "container security", "image vulnerabilities", "secure a Dockerfile", "base image security", plus Docker/Kubernetes/container deployments. Synonyms are well covered (image/container, scan/secure, Dockerfile/base image); the only minor omission is a term like "CVE" or "vulnerability report", which keeps it at the top anchor rather than revealing a gap to level 4.

5 / 5

Distinctiveness Conflict Risk

Container image security scanning is a clear niche with distinct triggers (image scan, Dockerfile security, base image), but the final trigger — "Agent is working with Docker, Kubernetes, or container deployments" — is broad enough to fire on general container work unrelated to security, and "secure a Dockerfile" could overlap a general Docker linting skill. This is 'mostly distinct; minor overlap risk with closely related skills' (4) rather than 5, whose clear-niche bar is met only by the security-specific triggers.

4 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
snyk/studio-recipes
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.