本文へ移動
cccskills
無料GitHub で公開

container-scan

Dockerfile / Containerfile / compose analysis plus optional Trivy / Grype / Syft composition when those binaries are present. Use when reviewing a Dockerfile PR, gating `docker build`, building an image SBOM, evaluating base-image risk, or auditing a registry image for CVEs.

インストール方法を見る

含まれるファイル(3)

  • SKILL.md3.9 KB
  • evals/evals.json2.5 KB
  • evals/trigger-eval.json1.3 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Vulnetix Container Scan Skill

Use when

  • Pre-build: scan a Dockerfile for misconfigurations and base-image CVEs.
  • PR review: detect EOL base images, missing USER, root processes, exposed secrets.
  • --image registry/img:tag: scan a built image for installed-package CVEs via Trivy/Grype if available.
  • Compose with Syft to produce a container SBOM (CycloneDX JSON).
  • Hardening checklist: USER directive present, healthcheck defined, pinned versions, layer minimisation.

Don't use for

  • Source-code SAST — use sast-scan.
  • Cloud-config (Terraform / k8s manifests) — use iac-scan.
  • Vulnetix CLI itself does not pull images; for --image you need binaries.docker or binaries.podman.

Conventions

Follows skills/_lib/contract.md. In short: use the vulnetix_* MCP tools when the agent has them and the CLI otherwise — both shape their own output, so there is no jq step any more. Independent calls go out as concurrent Bash tool calls in one message. One trailing suggestion, not a playbook. See the contract for surface selection, output style and memory writes.

Step 1: Load capabilities

Read .vulnetix/capabilities.yaml. Note: binaries.{docker,podman,trivy,grype,syft}, repo.{dockerfile,containerfile,compose,docker_compose}. If no container artifacts found AND no --image argument, abort with a one-liner.

Step 2: Run Vulnetix container analysis

vulnetix containers --paths "$DOCKERFILE_PATHS" -o json > .vulnetix/containers.${TIMESTAMP}.json

Or:

vulnetix scan --enable-containers --paths "$DOCKERFILE_PATHS" -o json

Captures: base-image risk, EOL bases, exposed secrets, missing USER, root processes, missing healthchecks, vulnerable system packages.

Step 3: Compose with installed scanners (conditional)

For each available binary:

  • binaries.trivy: true →
    trivy config "$DOCKERFILE_PATH" --format json > .vulnetix/containers/trivy.config.json
    trivy image "$IMAGE" --format json > .vulnetix/containers/trivy.image.json   # if --image
    
  • binaries.grype: true AND --image →
    grype "$IMAGE" -o json > .vulnetix/containers/grype.json
    
  • binaries.syft: true AND --image →
    syft "$IMAGE" -o cyclonedx-json > .vulnetix/containers/${IMAGE//[\/:]/_}.cdx.json
    

Merge findings into a unified table; de-dup by CVE+package.

Step 4: Render

| Severity | Source | Issue | File / Layer | Fix |
| Critical | trivy  | CVE-... in libxml2 2.9.10 | layer 3 | bump base to alpine:3.19 |

Plus a "Hardening checklist" section: USER directive, healthcheck, pinned versions, reduced layers.

Memory update

Write .vulnetix/containers/<timestamp>.summary.yaml with finding counts by severity.

Edge cases & gotchas

  • Trivy/Grype/Syft are optional. If absent, the skill runs Vulnetix-only checks (Dockerfile lint + base-image known-CVE list).
  • Compose files (docker-compose.yml) are scanned per-service; results are split per service-name.
  • --image requires the image to be pullable (registry auth via docker login / podman login first).
  • Trivy DB updates can take 30s on first run; subsequent invocations are cached.
  • EOL base-image detection uses vulnetix vdb product — same eol-status as eol-check.
  • Layer reordering recommendations are heuristic; if your build has a legitimate reason for the current order, the recommendation may be incorrect.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

dashboard

無料

Show what this repository has already decided about its vulnerabilities, read from the durable record rather than by scanning again — open versus resolved, the decision taken on each, and what is still waiting. Use when picking up triage after a break, auditing past decisions, onboarding to a repository with security history, or checking nothing high-severity is open before a release.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Dependency-conflict resolution when a `fix` version bump fails — diagnose the peer-dep tree, find a compatible safe version set, propose package-manager overrides (`overrides`/`resolutions`/`replace`/`[patch]`), fall back to safe-harbour inline patching. Use when an upgrade is blocked by transitive constraints, a peer-dep conflict surfaces, or you need to override a vulnerable transitive without bumping the parent.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Work through which package to add for a capability, and what each option costs — maintenance, licence, bundle weight, transitive risk, and whether the platform already does it. Use when someone needs a library for a job and has not picked one yet, when weighing two candidates, or when a package looks convenient but unmaintained.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

IDS/IPS detection content for a CVE — Snort/Suricata-compatible rules, YARA signatures, ProjectDiscovery Nuclei templates, traffic-filter rules. Capability-aware: skips families when the binary is not installed (no Snort = no Snort output). Use when deploying defences for a CVE without a patch, augmenting SAST with active detection, or feeding the SOC engineering pipeline.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

eol-check

無料

End-of-life detection for runtimes (Node, Python, Java, Go, .NET) and key packages — surfaces past-EOL items, items reaching EOL within 90 days, and EOL base images for containers. Use when planning a runtime upgrade, auditing for unsupported versions, gating a deploy against EOL deps, or producing a remediation roadmap.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Generate a runnable exploit-validation command (Nuclei template, Metasploit module hint, AI-assisted Python script, or curl-based PoC) against a user-specified authorised target. Use when validating that a fix actually closed the vulnerability path, confirming a patch deployed correctly, or producing a copy-pasteable test command for QA. The skill never executes — the user runs.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Vulnetix のスキルをすべて見る

このスキルの問題を報告する