Install any skill in seconds. Free to start, no credit card required.
Get Started Free →A production-focused guide for building, scanning, and running containers securely — from Dockerfile authoring through runtime enforcement and supply chain integrity.
.claude/skills/container-security-hardening/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 260% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 263% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 323% | 0% |
| case-17 | ✗→✓ | ▲ Improved | 308% | 0% |
| case-21 | ✓→✗ | ▼ Worse | 299% | 0% |
A production-focused guide for building, scanning, and running containers securely — from Dockerfile authoring through runtime enforcement and supply chain integrity.
Read the detailed guide before executing this skill. It retains the complete procedure and reference material. Treat its safety, prerequisites, and validation requirements as mandatory. For focused work, load the relevant sections; for end-to-end work, read the guide completely.
github-actions-advanceddocker-expertkubernetes-architectapi-security-best-practicesUSER declared before CMD/ENTRYPOINT@sha256:... digest (not just tag)ENV, ARG, or RUN commandsHEALTHCHECK definedorg.opencontainers.image.*).dockerignore excludes .git, .env, secrets, testsENTRYPOINT uses exec form, not shell formtrivy --scanners secret).trivyignore has justified entries for accepted CVEs--read-only filesystem--cap-drop ALL (add back only what's documented as required)--security-opt no-new-privileges:true--security-opt seccomp=<profile> applied--memory, --cpus, --pids-limit)readOnlyRootFilesystem: trueallowPrivilegeEscalation: falserunAsNonRoot: true with explicit UIDcapabilities.drop: ["ALL"]requests and limits definedautomountServiceAccountToken: falserestricted levelNetworkPolicy default-deny applied| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 16,097 | 9,902 | -38% | 1 | 1 | 0% | 3,031 | 10,917 | +260% | 0 | 0 | — |
case-02 | fail→pass | 16,956 | 38,878 | +129% | 1 | 1 | 0% | 3,253 | 11,823 | +263% | 0 | 0 | — |
case-03 | fail→pass | 13,027 | 13,410 | +3% | 1 | 1 | 0% | 2,774 | 11,724 | +323% | 0 | 0 | — |
case-04 | pass→pass | 14,063 | 22,266 | +58% | 1 | 1 | 0% | 2,579 | 11,045 | +328% | 0 | 0 | — |
case-05 | pass→pass | 11,027 | 7,641 | -31% | 1 | 1 | 0% | 2,192 | 10,352 | +372% | 0 | 0 | — |
case-06 | pass→pass | 15,963 | 19,959 | +25% | 1 | 1 | 0% | 3,085 | 12,915 | +319% | 0 | 0 | — |
case-07 | pass→pass | 12,008 | 8,536 | -29% | 1 | 1 | 0% | 2,276 | 10,492 | +361% | 0 | 0 | — |
case-08 | pass→pass | 8,534 | 5,912 | -31% | 1 | 1 | 0% | 1,623 | 9,977 | +515% | 0 | 0 | — |
case-09 | pass→pass | 7,755 | 5,422 | -30% | 1 | 1 | 0% | 1,399 | 9,858 | +605% | 0 | 0 | — |
case-10 | pass→pass | 11,921 | 7,632 | -36% | 1 | 1 | 0% | 2,358 | 10,328 | +338% | 0 | 0 | — |
case-11 | pass→pass | 11,338 | 8,579 | -24% | 1 | 1 | 0% | 2,240 | 10,509 | +369% | 0 | 0 | — |
case-12 | pass→pass | 13,322 | 13,008 | -2% | 1 | 1 | 0% | 2,564 | 11,423 | +346% | 0 | 0 | — |
case-13 | pass→pass | 10,651 | 9,499 | -11% | 1 | 1 | 0% | 2,012 | 10,787 | +436% | 0 | 0 | — |
case-14 | pass→pass | 21,402 | 4,901 | -77% | 1 | 1 | 0% | 1,185 | 9,806 | +728% | 0 | 0 | — |
case-15 | pass→pass | 9,975 | 6,262 | -37% | 1 | 1 | 0% | 1,931 | 9,999 | +418% | 0 | 0 | — |
case-16 | pass→pass | 12,377 | 6,541 | -47% | 1 | 1 | 0% | 2,284 | 10,116 | +343% | 0 | 0 | — |
case-17 | fail→pass | 16,738 | 16,552 | -1% | 1 | 1 | 0% | 2,882 | 11,756 | +308% | 0 | 0 | — |
case-18 | pass→pass | 27,807 | 7,560 | -73% | 1 | 1 | 0% | 1,676 | 10,310 | +515% | 0 | 0 | — |
case-19 | pass→pass | 14,777 | 9,621 | -35% | 1 | 1 | 0% | 2,790 | 10,540 | +278% | 0 | 0 | — |
case-20 | pass→pass | 17,575 | 14,269 | -19% | 1 | 1 | 0% | 3,429 | 11,531 | +236% | 0 | 0 | — |
case-21 | pass→fail | 14,639 | 29,422 | +101% | 1 | 1 | 0% | 3,037 | 12,131 | +299% | 0 | 0 | — |
case-22 | pass→pass | 18,116 | 6,321 | -65% | 1 | 1 | 0% | 2,917 | 9,969 | +242% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +14 percentage points is the difference between those two pass rates over the 22 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
The publisher has shipped newer versions since this run, so these numbers describe v2, not the version currently listed.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
| Model | Method | Date | Lift |
|---|---|---|---|
| gemini-3.6-flash | verified | 7/28/2026 | +23% |
Other measured skills in the registry, with their headline benchmark lift.