Skip to content
Back to skills

Review Dockerfiles For Risky Patterns And Bad Defaults With Hadolint

ASecurity

Catch insecure Dockerfile patterns, brittle package-install habits, and shell pitfalls before image builds ship.

  • 36 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added June 2, 2026
ai-agentsgoshellbashdockergitsecuritydocumentation

Security analysis

A100/100

Scanned June 2, 2026

npx -y skills add agentskillexchange/skills --skill review-dockerfiles-for-risky-patterns-and-bad-defaults-with-hadolint --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Review Dockerfiles For Risky Patterns And Bad Defaults With Hadolint?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Review Dockerfiles For Risky Patterns And Bad Defaults With Hadolint
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/agentskillexchange-review-dockerfiles-for-risky-patterns-and-bad-defa/badge)](https://www.skillsdirectory.com/skills/agentskillexchange-review-dockerfiles-for-risky-patterns-and-bad-defa)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "Review Dockerfiles for risky patterns and bad defaults with hadolint"
slug: "review-dockerfiles-for-risky-patterns-and-bad-defaults-with-hadolint"
description: "Catch insecure Dockerfile patterns, brittle package-install habits, and shell pitfalls before image builds ship."
github_stars: 12065
verification: "security_reviewed"
source: "https://github.com/hadolint/hadolint"
author: "hadolint"
publisher_type: "organization"
category: "Security & Verification"
framework: "Multi-Framework"
tool_ecosystem:
  github_repo: "hadolint/hadolint"
  github_stars: 12065
---

# Review Dockerfiles for risky patterns and bad defaults with hadolint

Catch insecure Dockerfile patterns, brittle package-install habits, and shell pitfalls before image builds ship.

## Prerequisites

hadolint binary and Dockerfiles

## Installation

Use the upstream install or setup path that matches your environment:
- Docker comes to the rescue, providing an easy way how to run hadolint on most
- docker run --rm -i hadolint/hadolint < Dockerfile
- docker run --rm -i ghcr.io/hadolint/hadolint < Dockerfile
- brew install hadolint

Requirements and caveats from upstream:
- [![Docker pulls][docker-img]][docker]
- A smarter Dockerfile linter that helps you build [best practice][] Docker
- Just pipe your Dockerfile to docker run:

Basic usage or getting-started notes:
- the Bash code inside RUN instructions.
- You can run hadolint locally to lint your Dockerfile.
- podman run --rm -i ghcr.io/hadolint/hadolint < Dockerfile

- Source: https://github.com/hadolint/hadolint
- Extracted from upstream docs: https://raw.githubusercontent.com/hadolint/hadolint/HEAD/README.md

## Documentation

- https://github.com/hadolint/hadolint

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/review-dockerfiles-for-risky-patterns-and-bad-defaults-with-hadolint/)

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…