marketplace/bundles/pm-dev-oci/skills/oci-standards/SKILL.md
Use when writing, reviewing, or debugging Dockerfiles and Containerfiles — covers base image selection, multi-stage builds, version pinning, .dockerignore (including excluding secrets from the build context), multi-platform builds, OCI labels, certificate management, secrets management (never embedding secrets in image layers, BuildKit build-time secrets, runtime secret injection), and Quarkus distroless health probes. Activate for any container image building or build-context hardening task.
npx skillsauth add cuioss/plan-marshall oci-standardsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
REFERENCE MODE: This skill provides reference material for building OCI-compliant container images. Load specific references on-demand based on current task. Do not load all references at once.
Execution mode: Reference library; load standards on-demand for OCI container image building tasks.
Prohibited actions:
Constraints:
image-building.md define the authoritative rules for DockerfilesActivate when:
Load references progressively based on current task. Never load all references at once.
File: standards/image-building.md
Load When:
Contents:
Load Command:
Read standards/image-building.md
File: standards/quarkus-distroless-health-probes.md
Load When:
Contents:
clean package vs bare quarkus:build)Load Command:
Read standards/quarkus-distroless-health-probes.md
File: standards/certificate-management.md
Load When:
Contents:
Load Command:
Read standards/certificate-management.md
latest)org.opencontainers.image.*) presentdevelopment
Domain-owned OpenRewrite log-line finding parser for the java-cui domain — parses the
development
Domain-owned OpenRewrite marker detection for the java-cui domain — scans Java/Kotlin sources for cui-rewrite TODO markers, categorizes them by recipe, and fails the gate on any detected marker
development
Operator control surface for the marshalld build server — enrol/drop a project in the machine-global registry (the opt-in enable signal and anti-laundering wall), manage the daemon lifecycle (start, stop, drain, status, install, upgrade) version-pinned to the verified bundle copy, and inspect the daemon's per-project interaction-audit log (read-only)
tools
The tiny build-consumption client for the marshalld build server — submit a build job, bounded long-poll for its result, ping the daemon identity, and preflight registry-plus-liveness in one call; consumption only, never provisioning or enrolment