Security audit
dockerfile-optimizer-security-scanner
Security checks across malware telemetry and agentic risk
Overview
This skill is a straightforward Dockerfile review guide with no hidden execution, persistence, or credential-handling behavior in the artifact.
Installers should expect the skill to guide an agent in reviewing Dockerfiles and suggesting optimized Dockerfile or .dockerignore content. Review generated changes before applying them, especially exclusions in .dockerignore and base image recommendations, but the artifact itself does not show risky hidden behavior.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
