Validate WCAG 2.1 Level AA compliance and accessibility best practices. Use when performing accessibility audits and WCAG certification.
日本語の概要は準備中です。原文の説明を表示しています。
Audit Dockerfiles and Compose files against the 10 common Docker mistakes — image security, build efficiency, runtime safety. Use when reviewing or hardening Docker configs. Trigger on "audit my Dockerfile", "check this Compose file", "Docker best practices", "is my container secure".
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Systematic audit of Docker configurations against the 10 most common Docker mistakes. Covers image security, build efficiency, runtime safety, and Compose best practices. Works with grep-based detection (no external tools required) plus optional deep scanning with hadolint, trivy, and dockle.
/docker-audit [path]
Find all Docker files in scope:
find . -name "Dockerfile*" -o -name "compose*.yaml" -o -name "compose*.yml" -o -name "docker-compose*.yml" -o -name "docker-compose*.yaml" -o -name ".dockerignore" | head -50
# Detect :latest or untagged images
grep -n "^FROM.*:latest" Dockerfile*
grep -n "^FROM [^ :]*$" Dockerfile*
grep -rn "image:.*:latest" compose*.yaml docker-compose*.yml 2>/dev/null
grep -rn "image: [^ :]*$" compose*.yaml docker-compose*.yml 2>/dev/null
Pass: All FROM/image directives use pinned version tags (e.g., node:22.12-alpine)
Fail: Any :latest or missing tag
# Check for bloated base images
grep -n "^FROM.*ubuntu\|^FROM.*debian\|^FROM.*centos\|^FROM.*fedora" Dockerfile*
Pass: Uses alpine, slim, or distroless variants Fail: Full OS base images without justification
# Check COPY order — dependency files should come before source
grep -n "^COPY\|^ADD" Dockerfile*
# Correct: COPY package*.json -> RUN npm install -> COPY . .
# Wrong: COPY . . -> RUN npm install
Pass: Dependency manifests (package.json, requirements.txt, go.mod, Gemfile) copied and installed before source code
Fail: COPY . . appears before dependency installation
# Check for USER directive
grep -n "^USER" Dockerfile*
# Check for user creation
grep -n "adduser\|useradd\|addgroup\|groupadd" Dockerfile*
Pass: USER directive present with non-root user Fail: No USER directive (defaults to root)
# Detect secrets in Dockerfiles
grep -in "ENV.*PASSWORD\|ENV.*SECRET\|ENV.*API_KEY\|ENV.*TOKEN\|ENV.*CREDENTIAL" Dockerfile*
grep -in "ARG.*PASSWORD\|ARG.*SECRET\|ARG.*API_KEY\|ARG.*TOKEN" Dockerfile*
# Check for COPY of secret files
grep -in "COPY.*\.env\|COPY.*credentials\|COPY.*\.pem\|COPY.*\.key\|COPY.*\.p12" Dockerfile*
Pass: No secrets in ENV/ARG/COPY directives Fail: Secret-like values found in build context
# Check existence and content
ls .dockerignore 2>/dev/null
# Check for critical exclusions
grep -c ".git\|node_modules\|__pycache__\|\.env" .dockerignore 2>/dev/null
Pass: .dockerignore exists and excludes .git, node_modules/pycache, .env, logs
Fail: Missing or incomplete .dockerignore
# Dockerfile HEALTHCHECK
grep -n "HEALTHCHECK" Dockerfile*
# Compose healthcheck
grep -A3 "healthcheck:" compose*.yaml docker-compose*.yml 2>/dev/null
Pass: HEALTHCHECK in Dockerfile or healthcheck in Compose for all services Fail: No health check defined
# Count FROM directives (multi-stage = 2+)
grep -c "^FROM" Dockerfile*
# Check for AS aliases
grep -n "^FROM.*AS\|^FROM.*as" Dockerfile*
Pass: Production Dockerfile uses multi-stage (2+ FROM with AS alias) Fail: Single FROM for production images
# Count separate RUN commands (flag if >5)
grep -c "^RUN" Dockerfile*
# Check for cleanup in same layer as install
grep -n "rm -rf.*apt\|rm -rf.*cache\|rm -rf.*tmp\|rm -rf.*lists" Dockerfile*
# Detect split update/install (bad pattern)
grep -c "apt-get update" Dockerfile*
grep -c "apt-get install" Dockerfile*
Pass: RUN commands combined where logical, cleanup in same layer as install Fail: Many separate RUN commands, no cleanup, split update/install
# Extract base images for scanning
grep "^FROM" Dockerfile* | awk -F'FROM ' '{print $2}' | awk '{print $1}'
# Trivy scan (if available)
trivy image --severity HIGH,CRITICAL <image>
# Docker Scout (if available)
docker scout cves <image>
Pass: No critical/high CVEs in base images Fail: Outdated base images with known vulnerabilities
# File naming — modern convention is compose.yaml
ls compose.yaml compose.override.yaml 2>/dev/null
ls docker-compose.yml docker-compose.yaml 2>/dev/null
# Resource limits
grep -A5 "deploy:" compose*.yaml docker-compose*.yml 2>/dev/null | grep "limits"
grep "mem_limit\|cpus:" compose*.yaml docker-compose*.yml 2>/dev/null
# Named volumes vs bind mounts
grep "\\./" compose*.yaml docker-compose*.yml 2>/dev/null # bind mounts (flag for prod)
# Deprecated CLI usage
grep "docker-compose" Makefile* scripts/*.sh 2>/dev/null # should be docker compose
# Override structure
ls compose.override.yaml compose.prod.yaml compose.staging.yaml 2>/dev/null
# Verify merge output
docker compose config 2>/dev/null
compose.yaml naming (not docker-compose.yml)compose.override.yaml) and prod (compose.prod.yaml)docker compose config produces valid merged outputdocker-compose CLI in scriptsRun when available. Fall back to grep-based checks otherwise.
# Hadolint — Dockerfile linter (primary tool)
hadolint Dockerfile
hadolint --format json Dockerfile
# Trivy — vulnerability + misconfiguration scanner
trivy config Dockerfile
trivy image <built-image>
# Docker Scout — CVE scanning
docker scout cves <image>
docker scout recommendations <image>
# Dockle — container image linter
dockle <image>
# Docker Audit Report
**Date**: YYYY-MM-DD
**Scope**: [path]
**Files Scanned**: [list]
## Summary
| Severity | Count |
| -------- | ----- |
| Critical | 0 |
| High | 0 |
| Medium | 0 |
| Low | 0 |
## Overall Score
[X/10 categories pass] — PASS / NEEDS WORK / FAIL
## Findings
### [Category] — [PASS/FAIL] (Severity)
- **File**: Dockerfile:14
- **Issue**: [description]
- **Fix**: [specific remediation]
## Dockerfile Checklist
- [ ] Image tags pinned (no :latest)
- [ ] Minimal base image (alpine/slim/distroless)
- [ ] Build cache optimized (deps before source)
- [ ] Non-root USER directive
- [ ] No secrets in Dockerfile/args
- [ ] .dockerignore exists and aggressive
- [ ] HEALTHCHECK defined
- [ ] Multi-stage build for production
- [ ] Layers combined and cleaned
- [ ] Base images scanned and current
## Compose Checklist
- [ ] Uses compose.yaml naming convention
- [ ] Override files for dev/prod separation
- [ ] Image versions pinned
- [ ] Resource limits set
- [ ] Named volumes (no bind mounts in prod)
- [ ] Healthcheck per service
- [ ] No deprecated docker-compose CLI usage
## Recommendations
### Immediate (Critical/High)
1. [action items]
### Short-Term (Medium)
1. [action items]
### Ongoing
1. [action items]
/security-scan — covers application code; /docker-audit covers container config/infrastructure-setup — creates Docker files; /docker-audit validates themrules/docker.md — always-on guardrails; this skill is the deep audit# Hadolint (macOS)
brew install hadolint
# Trivy (macOS)
brew install trivy
# Dockle
brew install goodwithtech/r/dockle
# Docker Scout (built into Docker Desktop 4.17+)
docker scout version
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Validate WCAG 2.1 Level AA compliance and accessibility best practices. Use when performing accessibility audits and WCAG certification.
日本語の概要は準備中です。原文の説明を表示しています。
Analyze feature requirements, dependencies, and security considerations. Use when starting feature implementation from GitHub issues to understand scope, technical feasibility, and risks.
日本語の概要は準備中です。原文の説明を表示しています。
Run SQL queries against psql, BigQuery, or MySQL from the terminal, including natural-language-to-SQL and schema exploration. Use when analyzing data, inspecting DB state, or debugging tables. Trigger on "query the database", "SQL", "show me data from", "explore table".
日本語の概要は準備中です。原文の説明を表示しています。
Design REST APIs or function contracts with clear request/response specifications, error handling patterns, authentication strategies, and comprehensive documentation.
日本語の概要は準備中です。原文の説明を表示しています。
Generate comprehensive API endpoint tests for REST and GraphQL APIs. Creates tests for all HTTP methods, status codes, authentication, and validation.
日本語の概要は準備中です。原文の説明を表示しています。
Design component architecture and module structure using established architectural patterns for clean, maintainable, and scalable systems.
日本語の概要は準備中です。原文の説明を表示しています。