Dockerfile lint
Skill NSBen/skillfoundry/src/skillfoundry/data/starter_skills/dockerfile-lint
🔥 SkillFoundry (forge) — open, vendor-neutral toolchain for authoring, validating, testing & publishing AI agent skills. Works across Claude Code / Cursor / Codex / OpenCode / Cline. Ships 15 starter skills.
npx -y skills add NSBen/skillfoundry --skill dockerfile-lintAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- 13 days oldThe repository was created 13 days ago. New is not bad, but a brand new repository carrying a familiar-sounding name is the shape a typosquat arrives in, and there has been no time for anyone else to find a problem with it.
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Use when you are writing or reviewing a Dockerfile and want to catch brittle patterns (latest tags, root user, huge layers, leaked secrets, missing HEALTHCHECK) before building or shipping it.
The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
1.4 KB, as published. Nobody here has run it
Dockerfile Lint
When to use
Invoke this skill when authoring a Dockerfile or reviewing one in a PR, especially for production or CI images.
Steps
- Flag
FROM ...:latestand suggest pinning to a digest or minor tag. - Detect running as root; recommend a dedicated non-root user.
- Report layer bloat: combine
RUNcommands, use multi-stage builds, and order caches. - Scan for secrets in
ENV/build args/COPYand recommend build secrets. - Check for a missing
HEALTHCHECK, non-portable paths, and deprecated instructions. - Summarize issues by severity with a concrete, copy-paste fix per finding.
Examples
- "Review my Dockerfile for security and size issues"
- "Add a HEALTHCHECK and drop the image below 200MB"
References
Follow Docker's official best practices: smallest base, least privilege, reproducible builds. Validate with hadolint when it is available in the environment.