CtrlK
BlogDocsLog inGet started
Tessl Logo

container-security

Comprehensive container image security scanning and remediation. Analyzes Docker images for OS package vulnerabilities, application dependencies, and Dockerfile best practices. Use when: - User asks to scan a Docker image or container - User mentions "container security" or "image vulnerabilities" - User wants to secure a Dockerfile - User asks about base image security - Agent is working with Docker, Kubernetes, or container deployments

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced skill body with a strong validation loop, but it is somewhat verbose and fails to reference the bundle files that exist in references/, weakening progressive disclosure.

Suggestions

Link the existing references/base-image-recommendations.md and references/dockerfile-best-practices.md from the relevant sections so the SKILL.md overview navigates to its bundle material.

Trim the explanatory Dockerfile best-practice comments and the duplicated result/summary templates; assume Claude knows basic Dockerfile hygiene and keep only skill-specific guidance.

Move the full Base Image Quick Reference table into base-image-recommendations.md, leaving a concise pointer inline to reduce token weight.

DimensionReasoningScore

Conciseness

Mostly efficient with concrete tool invocations and templates, but it includes padding Claude already knows (a base-image reference table, generic Dockerfile best-practice comments like 'Pin specific tags') and repeated example output templates that inflate length beyond what each token earns.

2 / 3

Actionability

Provides executable MCP tool invocations with concrete parameters (image, file, app_vulns, severity_threshold, exclude_base_image_vulns), copy-paste Dockerfile snippets, and rebuild/re-scan commands — fully actionable.

3 / 3

Workflow Clarity

Five clearly sequenced phases with numbered steps, and Phase 5 is an explicit validation feedback loop (rebuild -> re-scan -> compare before/after -> address remaining issues) that satisfies the checkpoint requirement.

3 / 3

Progressive Disclosure

The body is well-organized into sections, but two reference files exist in references/ (base-image-recommendations.md, dockerfile-best-practices.md) and are never linked or signaled from SKILL.md, so the overview doesn't navigate to its own bundle material — structure is present but disclosure is not signaled.

2 / 3

Total

10

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A well-crafted description: specific actions, explicit 'Use when' triggers, third-person voice, and a clear niche with low conflict risk. It only slightly risks verbosity but stays within bounds.

DimensionReasoningScore

Specificity

Lists multiple concrete actions: 'Analyzes Docker images for OS package vulnerabilities, application dependencies, and Dockerfile best practices' — three distinct, specific capabilities rather than vague language.

3 / 3

Completeness

Explicitly answers what ('container image security scanning and remediation' across OS packages, deps, Dockerfile) and when via a clear 'Use when:' bullet list of five trigger conditions.

3 / 3

Trigger Term Quality

Strong natural-language triggers a user would say: 'scan a Docker image', 'container security', 'image vulnerabilities', 'secure a Dockerfile', 'base image security' — broad coverage of phrasings.

3 / 3

Distinctiveness Conflict Risk

Niche is clearly container-image security scanning tied to Snyk; triggers ('Docker image', 'container security', 'base image security') are distinct and unlikely to fire for unrelated skills.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
snyk/studio-recipes
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.