Back to skill

Security audit

dockerfile-optimizer-security-scanner

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Dockerfile review guide with no hidden execution, persistence, or credential-handling behavior in the artifact.

Installers should expect the skill to guide an agent in reviewing Dockerfiles and suggesting optimized Dockerfile or .dockerignore content. Review generated changes before applying them, especially exclusions in .dockerignore and base image recommendations, but the artifact itself does not show risky hidden behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.