— No reviews yet
0 installs
7 views
0.0% view→install
Install
$ agentstack add skill-vivek-viswanat-dev-arsenal-docker-image-optimizer-devops Open-source listing — not yet scanned by AgentStack. Follow the source repository for install instructions.
Security review
⚠ Flagged1 finding(s); flagged for manual review. · v0.1.0 How review works →
- • Prompt-injection patterns
- • Secret / credential exfiltration
- • Dangerous shell & filesystem operations
- • Untrusted network calls
- • Known-malicious package signatures
- high Destructive filesystem operation.
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Are you the author of Docker Image Optimizer Devops? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claimAbout
Context
Use this skill when:
- Creating a new
Dockerfile - A user complains about "slow builds" or "large images"
- Reviewing container security (reducing attack surface)
Optimization Pillars
1. Multi-Stage Strategy (The 2026 Standard)
- Separate Build from Runtime: Use a heavy image (with compilers/SDKs) for building, but copy ONLY the final binary/artifacts into a minimal runtime image (Alpine or Scratch).
- Named Stages: Use
FROM base AS builderfor readability.
2. Base Image Selection
- Prefer Minimal: Default to
alpine(≈5MB) ordebian-slim(≈30MB) overubuntu:latest(≈75MB). - Distroless: For production, suggest
gcr.io/distrolessto remove all shells and package managers.
3. Layer Management & Caching
- Order Matters: Place instructions that change least often (like
RUN apt-get update) at the top. Place source codeCOPYcommands at the bottom. - Atomic RUNs: Combine related commands using
&&and\to prevent intermediate layer bloat.
Example: RUN apt-get update && apt-get install -y --no-install-recommends pkg && rm -rf /var/lib/apt/lists/*
4. Dependency Hygiene
- No-Install-Recommends: Always use
--no-install-recommendswithapt. - Cache Cleaning: Remove package manager caches in the same layer as the installation.
- Production Only: Ensure
devDependenciesor build-only headers never reach the final stage.
5. The .dockerignore File
- Exclusion: Every Docker project MUST have a
.dockerignoreto prevent.git,node_modules,tests/, and local logs from leaking into the build context.
Instructions for the Agent
- When a user provides a Dockerfile, perform a Size Audit first.
- If the image is single-stage, provide a Refactored Multi-Stage Version.
- Check for "Magic Versions" and suggest pinning specific tags (e.g.,
node:22.1.0-alpineinstead ofnode:latest).
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: vivek-viswanat
- Source: vivek-viswanat/dev-arsenal
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.