Container Security Scanner
$2.99OfficialScan and harden container images: base image vulnerabilities, runtime permissions, distroless patterns, and admission policies.
What you get
- โ10-step procedure
- โ6 pitfalls to avoid
- โInstalls into 6 tools
- Version
- v1 โ
- Last updated
- today
- Length
- 5 min read
- Requires
- Best with a strong model (Claude Sonnet 4)
Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes ยท Handles multi-file projects
Preview
When to use
Use this skill when scanning and hardening container images: finding vulnerabilities in base images and dependencies, reducing runtime privileges, choosing minimal/distroless bases, and defining admission policies that block bad images at deploy time. It applies to any container runtime (Docker, containerd) and orchestrator (Kubernetes, ECS, Nomad). It complements supply-chain security (which covers signing and provenance) by focusing on the image's contents and runtime posture.
Inputs to gather
- Container images in scope: application images, base images, third-party images pulled from registries.
- Build setup: Dockerfile(s), base images used, build system, and where i
โฆ
๐ Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.