用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-docker-v170-4-10命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-docker-v170-4.10 |
| description | Ensure secrets are not stored in Dockerfiles |
| category | cis-docker |
| version | 1.7.0 |
| author | cyberstrike-official |
| tags | ["cis","docker","images","configuration","secrets"] |
| cis_id | 4.10 |
| cis_benchmark | CIS Docker Benchmark v1.7.0 |
| tech_stack | ["docker"] |
| cwe_ids | ["CWE-312"] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Do not store any secrets in Dockerfiles.
Docker images are not opaque and contain information about the commands used to build them. As such secrets should not be included in Dockerfiles used to build images as they will be visible to any users of the image.
A proper secrets management process will be required for Docker image building.
Run the below command to get the list of images:
docker images
Run the below command for each image in the list above, and look for any secrets:
docker history <IMAGE_ID>
Alternatively, if you have access to Dockerfile for the image, verify that there are no secrets as described above.
Do not store any kind of secrets within Dockerfiles. Where secrets are required during the build process, make use of a secrets management tool, such as the buildkit builder included with Docker.
By default, there are no restrictions on storing config secrets in the Dockerfiles.
v8:
v7:
Manual