Dockerfile lint
Skill NSBen/skillfoundry/src/skillfoundry/data/starter_skills/dockerfile-lint
Use when you are writing or reviewing a Dockerfile and want to catch brittle patterns (latest tags, root user, huge layers, leaked secrets, missing HEALTHCHECK) before building or shipping it.From its SKILL.md
npx -y skills add NSBen/skillfoundry --skill dockerfile-lintAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its file declares
Copied from the file, not written here
The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
1.4 KB, 219 tokens by cl100k_base, as published. Nobody here has run it
Dockerfile Lint
When to use
Invoke this skill when authoring a Dockerfile or reviewing one in a PR, especially for production or CI images.
Steps
- Flag
FROM ...:latestand suggest pinning to a digest or minor tag. - Detect running as root; recommend a dedicated non-root user.
- Report layer bloat: combine
RUNcommands, use multi-stage builds, and order caches. - Scan for secrets in
ENV/build args/COPYand recommend build secrets. - Check for a missing
HEALTHCHECK, non-portable paths, and deprecated instructions. - Summarize issues by severity with a concrete, copy-paste fix per finding.
Examples
- "Review my Dockerfile for security and size issues"
- "Add a HEALTHCHECK and drop the image below 200MB"
References
Follow Docker's official best practices: smallest base, least privilege, reproducible builds. Validate with hadolint when it is available in the environment.
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.