container-security-scanner
Container image and Kubernetes security scanning for CVEs, misconfigurations, and compliance
npx skills add a5c-ai/babysitter --skill container-security-scanner --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# Container Security Scanner Skill ## Purpose Automated container image and Kubernetes security scanning to identify vulnerabilities, misconfigurations, secrets, and compliance issues in containerized environments. ## Capabilities ### Image Vulnerability Scanning - Scan container images for known CVEs using Trivy, Grype, or Anchore - Detect vulnerabilities in OS packages and application dependencies - Generate SBOM (Software Bill of Materials) in CycloneDX or SPDX format - Track vulnerability severity (Critical, High, Medium, Low) ### Dockerfile Security Analysis - Check Dockerfile best practices and security issues - Identify privileged container configurations - Detect hardcoded secrets in Dockerfiles - Verify base image security and freshness ### Kubernetes Security Scanning - Run Kubernetes CIS benchmark checks using kube-bench - Analyze pod security policies and standards - Check RBAC configurations for over-permissive access - Detect insecure network policies ### Secrets Detection - Scan images for embedded secrets and credentials - Identify API keys, tokens, and passwords in layers - Check environment variable configurations ### Image Signature Verification - Verify containe
- Purpose
- Capabilities
- Image Vulnerability Scanning
- Dockerfile Security Analysis
- Kubernetes Security Scanning
- Secrets Detection
- Image Signature Verification
- Compliance Reporting
- Integrations
- Target Processes
- Input Schema
- Output Schema
- Usage Example
What does the container-security-scanner skill do?
Container image and Kubernetes security scanning for CVEs, misconfigurations, and compliance
How do I install it?
Run `npx skills add a5c-ai/babysitter --skill container-security-scanner --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From a5c-ai/babysitter, a repository with 1,642 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
