agentsclimarketplace

Docker helper

Skill ondrej-merkun/skill-audit/test/fixtures/benign/docker-helper

Scan every AI agent skill on your machine for prompt injection and malicious code. Fast local rules by default, with optional local LLM review for deeper context.From the repository description

Install
npx -y skills add ondrej-merkun/skill-audit --skill docker-helper

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
  • 3 stars3 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

0.6 KB, 132 tokens by cl100k_base, as published. Nobody here has run it

docker-helper

Simplifies local Docker container and image management tasks.

<docker-helper> Use this skill to manage local Docker resources.

Commands:

  • ps — list running containers with port mappings
  • logs <container> — tail the last 50 lines of container logs
  • stop-all — gracefully stop all running containers
  • prune — remove stopped containers, dangling images, and unused volumes
  • stats — show CPU/memory usage for all running containers

Requirements: Docker Engine running locally. No Docker Hub authentication needed. All operations are local — no registry pushes or pulls are performed. </docker-helper>

What ships with it: 1 file

870 B alongside SKILL.md, 1 of them executable

Gives 0 of the 12 instructions most containers cloud skills give in 132 tokens

Counted across 607 of the 657 authors here whose files we hold, read 2026-08-07

  • Run containers as a non-root userin 66 of 607, across 46 files
  • Use multi-stage buildsin 53 of 607, across 44 files
  • Use Promise.all for independent operationsin 47 of 607, across 13 files
  • Import directly instead of barrel filesin 46 of 607, across 12 files
  • Use ternary instead of AND for conditionalsin 45 of 607, across 12 files
  • Use Set or Map for O(1) lookupsin 42 of 607, across 10 files
  • Create a .dockerignore filein 41 of 607, across 31 files
  • Read individual rule files for detailsin 39 of 607, across 9 files
  • Copy dependency files before source codein 36 of 607, across 23 files
  • Authenticate server actions like API routesin 35 of 607, across 7 files
  • Use next/dynamic for heavy componentsin 34 of 607, across 9 files
  • Use React.cache for per-request deduplicationin 34 of 607, across 10 files

Said here and by no other author read

  • list running containers with port mappings
  • tail the last 50 lines of container logs
  • gracefully stop all running containers
  • remove stopped containers dangling images and unused volumes
  • show cpu and memory usage for running containers

Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.

Keep looking

Skills are one crate of 326,861. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.