image-security-scanner
Scans Docker images for security vulnerabilities, outdated packages, and misconfigurations. Use when checking image security, finding vulnerabilities, or hardening containers.
What this skill does
# Image Security Scanner
Scan and secure Docker images for production deployment.
## Quick Start
Scan an image:
```bash
docker scan myapp:latest
# or
trivy image myapp:latest
```
## Instructions
### Step 1: Choose Scanning Tool
**Docker Scan** (built-in):
```bash
docker scan myapp:latest
```
**Trivy** (comprehensive):
```bash
trivy image myapp:latest
```
**Grype** (fast):
```bash
grype myapp:latest
```
**Snyk** (detailed):
```bash
snyk container test myapp:latest
```
### Step 2: Run Security Scan
**Basic scan**:
```bash
docker scan myapp:latest
```
**Detailed scan with Trivy**:
```bash
trivy image --severity HIGH,CRITICAL myapp:latest
```
**Scan with JSON output**:
```bash
trivy image -f json -o results.json myapp:latest
```
### Step 3: Analyze Results
Review findings by severity:
- **CRITICAL**: Immediate action required
- **HIGH**: Fix soon
- **MEDIUM**: Plan to fix
- **LOW**: Monitor
**Common vulnerabilities**:
- Outdated base image
- Vulnerable packages
- Known CVEs
- Misconfigurations
### Step 4: Fix Vulnerabilities
**Update base image**:
```dockerfile
# Before
FROM node:18-alpine3.17
# After
FROM node:18-alpine3.18
```
**Update packages**:
```dockerfile
RUN apk upgrade --no-cache
# or
RUN apt-get update && apt-get upgrade -y
```
**Remove vulnerable packages**:
```dockerfile
RUN apk del vulnerable-package
```
**Use distroless for minimal attack surface**:
```dockerfile
FROM gcr.io/distroless/nodejs18-debian11
```
### Step 5: Implement Security Best Practices
**Run as non-root**:
```dockerfile
USER nobody
# or
RUN adduser -D appuser
USER appuser
```
**Remove unnecessary tools**:
```dockerfile
RUN apk del apk-tools
```
**Use read-only filesystem**:
```dockerfile
# In docker-compose or k8s
read_only: true
```
**Add security labels**:
```dockerfile
LABEL security.scan-date="2024-01-15"
LABEL security.scanner="trivy"
```
### Step 6: Verify Fixes
Re-scan after fixes:
```bash
docker build -t myapp:latest .
trivy image myapp:latest
```
Compare before/after:
```bash
# Before: 15 HIGH, 5 CRITICAL
# After: 2 HIGH, 0 CRITICAL
```
## Scanning Patterns
**CI/CD Integration**:
```yaml
# GitHub Actions
- name: Scan image
run: |
docker build -t myapp:${{ github.sha }} .
trivy image --exit-code 1 --severity CRITICAL myapp:${{ github.sha }}
```
**Pre-deployment scan**:
```bash
#!/bin/bash
IMAGE=$1
trivy image --severity HIGH,CRITICAL $IMAGE
if [ $? -ne 0 ]; then
echo "Security vulnerabilities found!"
exit 1
fi
```
**Scheduled scans**:
```bash
# Cron job to scan running images
0 2 * * * trivy image --severity HIGH,CRITICAL $(docker images -q)
```
## Security Hardening
**Minimal base image**:
```dockerfile
FROM alpine:3.18
# or
FROM gcr.io/distroless/static-debian11
```
**No secrets in image**:
```dockerfile
# Bad
ENV API_KEY=secret123
# Good
# Pass at runtime
docker run -e API_KEY=$API_KEY myapp
```
**Health checks**:
```dockerfile
HEALTHCHECK --interval=30s --timeout=3s \
CMD curl -f http://localhost:8080/health || exit 1
```
**Limit capabilities**:
```bash
docker run --cap-drop=ALL --cap-add=NET_BIND_SERVICE myapp
```
## Common Vulnerabilities
**Outdated base image**:
```dockerfile
# Vulnerable
FROM node:16-alpine
# Fixed
FROM node:18-alpine3.18
```
**Exposed secrets**:
```dockerfile
# Vulnerable
COPY .env .
# Fixed
# Use runtime secrets
```
**Running as root**:
```dockerfile
# Vulnerable
CMD ["node", "server.js"]
# Fixed
USER node
CMD ["node", "server.js"]
```
**Unnecessary packages**:
```dockerfile
# Vulnerable
RUN apk add curl wget git vim
# Fixed
RUN apk add --no-cache curl
```
## Scanning Tools Comparison
**Docker Scan**:
- Built into Docker
- Uses Snyk backend
- Easy to use
- Limited free scans
**Trivy**:
- Open source
- Fast and accurate
- Multiple output formats
- CI/CD friendly
**Grype**:
- Open source
- Very fast
- Good accuracy
- Simple CLI
**Snyk**:
- Commercial (free tier)
- Detailed reports
- Fix recommendations
- IDE integration
## Advanced
For production deployments:
- Implement image signing
- Use admission controllers
- Set up continuous scanning
- Monitor runtime security
- Implement security policies
Related in Image & Video
watch
IncludedWatch a video (URL or local path). Downloads with yt-dlp, extracts auto-scaled frames with ffmpeg, pulls the transcript from captions (or Whisper API fallback), and hands the result to Claude so it can answer questions about what's in the video.
physical-ai-defect-image-generation
IncludedUse when the user wants to orchestrate defect image generation, run associated setup, or handle outputs on OSMO. The Day 0 path handles cold-start with USD-to-ROI, image-edit augmentation, and AnomalyGen to create initial PCBA datasets. The Day 1 path performs inference and labeling on real images. This skill helps with first-time asset setup, creation of finetuning checkpoints, and configuring deployment. Trigger keywords: defect image generation, dig workflow, dig pipeline, defect image detection workflow, aoi pipeline, aoi anomalygen, usd2roi anomalygen, day 0 pcba, day 1 pcba, day 1 real-photo alignment, day 1 manual roi, metal surface anomaly, glass defect, anomalygen finetune, setup_pcb, setup_metal, setup_glass, setup_pretrained, dig setup, dig datasets, dig pretrained checkpoint, dig image-edit endpoint.
accelint-react-best-practices
IncludedReact performance optimization and best practices. ALWAYS use this skill when working with any React code - writing components, hooks, JSX; refactoring; optimizing re-renders, memoization, state management; reviewing for performance; fixing hydration mismatches; debugging infinite re-renders, stale closures, input focus loss, animations restarting; preventing remounting; implementing transitions, lazy initialization, effect dependencies. Even simple React tasks benefit from these patterns. Covers React 19+ (useEffectEvent, Activity, ref props). Triggers - useEffect, useState, useMemo, useCallback, memo, inline components, nested components, components inside components, re-render, performance, hydration, SSR, Next.js, useDeferredValue, combined hooks.
elevenlabs-agents
IncludedBuild conversational AI voice agents with ElevenLabs Platform using React, JavaScript, React Native, or Swift SDKs. Configure agents, tools (client/server/MCP), RAG knowledge bases, multi-voice, and Scribe real-time STT. Use when: building voice chat interfaces, implementing AI phone agents with Twilio, configuring agent workflows or tools, adding RAG knowledge bases, testing with CLI "agents as code", or troubleshooting deprecated @11labs packages, Android audio cutoff, CSP violations, dynamic variables, or WebRTC config. Keywords: ElevenLabs Agents, ElevenLabs voice agents, AI voice agents, conversational AI, @elevenlabs/react, @elevenlabs/client, @elevenlabs/react-native, @elevenlabs/elevenlabs-js, @elevenlabs/agents-cli, elevenlabs SDK, voice AI, TTS, text-to-speech, ASR, speech recognition, turn-taking model, WebRTC voice, WebSocket voice, ElevenLabs conversation, agent system prompt, agent tools, agent knowledge base, RAG voice agents, multi-voice agents, pronunciation dictionary, voice speed control, elevenlabs scribe, @11labs deprecated, Android audio cutoff, CSP violation elevenlabs, dynamic variables elevenlabs, case-sensitive tool names, webhook authentication
humanizer
IncludedHumanize AI-generated text by detecting and removing patterns typical of LLM output. Rewrites text to sound natural, specific, and human. Uses 28 pattern detectors, 560+ AI vocabulary terms across 3 tiers, and statistical analysis (burstiness, type-token ratio, readability) for comprehensive detection. Use when asked to humanize text, de-AI writing, make content sound more natural/human, review writing for AI patterns, score text for AI detection, or improve AI-generated drafts. Covers content, language, style, communication, and filler categories.
generating-mermaid-diagrams
IncludedSalesforce architecture diagrams using Mermaid with ASCII fallback. Use this skill when generating text-based diagrams for Salesforce architecture, OAuth flows, ERDs, integration sequences, or Agentforce structure. TRIGGER when: user says "diagram", "visualize", "ERD", or asks for sequence diagrams, flowcharts, class diagrams, or architecture visualizations in Mermaid. DO NOT TRIGGER when: user wants PNG/SVG image output (use generating-visual-diagrams), or asks about non-Salesforce systems.