marketplace/bundles/pm-dev-oci/skills/oci-security/SKILL.md
Use when hardening container runtime configuration, scanning for vulnerabilities, securing the image supply chain, or auditing against OWASP Docker Top 10. Covers capability dropping, read-only filesystems, image signing, SBOMs, and Trivy/Cosign/Syft workflows.
npx skillsauth add cuioss/plan-marshall oci-securityInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
REFERENCE MODE: This skill provides reference material for securing OCI containers at runtime and across the supply chain. Load specific references on-demand based on current task. Do not load all references at once.
Execution mode: Reference library; load standards on-demand for container security hardening tasks.
Prohibited actions:
Constraints:
--cap-drop=ALL) and selectively add required onesFor general image building practices (Dockerfiles, base images, multi-platform builds), see Skill: pm-dev-oci:oci-standards.
Activate when:
Load references progressively based on current task. Never load all references at once.
File: standards/owasp-container-security.md
Load When:
Contents:
Load Command:
Read standards/owasp-container-security.md
File: standards/runtime-security.md
Load When:
Cross-references OWASP controls D01, D03, D04, D05, D07, D09, D10.
Load Command:
Read standards/runtime-security.md
File: standards/supply-chain-security.md
Load When:
Cross-references OWASP controls D02, D08.
Load Command:
Read standards/supply-chain-security.md
--cap-drop=ALL with selective --cap-add--security-opt=no-new-privileges--read-only with tmpfs for write directoriesdevelopment
The single append-only change-ledger — one worktree_sha-stamped substrate for kind=build and kind=change entries — plus the first-class worktree-sha freshness API
development
Authoring standards for ASCII box diagrams in skill and doc source — box-drawing conventions, right-border alignment, and a deterministic check/fix validator over fenced/literal code blocks in .md and .adoc files
testing
Recipe for verifying and fixing alignment of ASCII box diagrams across .md skill source and .adoc documentation, one deliverable per offending file
development
Pure platform-agnostic terminal-title composition consumed by platform-runtime via PYTHONPATH