docker-dockerfile

docker-dockerfile is an agent for Claude Code from TheBeardedBearSAS/claude-craft. It costs 9 tokens per session (1,420 once invoked), scanned A, original, MIT.

A Dockerfile optimization guide for creating smaller, safer, and faster-to-build container images. A Dockerfile is the recipe used to build an image containing an application and its dependencies.

In plain words
What is it for?
Use it to improve Dockerfiles for Node.js, Python, PHP, Go, Java, or Rust applications with multi-stage builds, cache management, minimal base images, security scans, and image signing.
Why use it?
It addresses oversized images, slow rebuilds, unnecessary layers, unsafe runtime users, exposed secrets, and unscanned vulnerabilities.

Agent for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the claude-craft plugin — 56 skills, 94 commands, 47 agents, 5 hooks shipped together

Good fit Use it to improve Dockerfiles for Node.js, Python, PHP, Go, Java, or Rust applications with multi-stage builds, cache management, minimal base images, security scans, and image signing.

Compare 6 agents from other repositories ↓
Install with agentmods
npx agentmods add agents/thebeardedbearsas/claude-craft/docker-dockerfile
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/TheBeardedBearSAS/claude-craft

Made for: Claude Code.

Or install claude-craft, the plugin that ships this one along with the rest of its 56 skills, 94 commands, 47 agents, 5 hooks.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for docker-dockerfile

README.md
[![agentmods](https://agentmods.dev/badge/agents/thebeardedbearsas/claude-craft/docker-dockerfile.svg)](https://agentmods.dev/agents/thebeardedbearsas/claude-craft/docker-dockerfile)
Your own site
<a href="https://agentmods.dev/agents/thebeardedbearsas/claude-craft/docker-dockerfile"><img src="https://agentmods.dev/badge/agents/thebeardedbearsas/claude-craft/docker-dockerfile.svg" alt="Measured on agentmods" height="20"></a>
Per session 9 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,420 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00009 $0.01420
Opus 5 $0.00005 $0.00710
Sonnet 5 $0.00002 $0.00284
Haiku 4.5 $0.00001 $0.00142

Measured 3d ago against content hash 9efad9407214, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade A, and why

docker-dockerfile scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

CMD wget -q --spider http://localhost:3000/health || exit 1
Infra/i18n/de/Docker/agents/docker-dockerfile.md · 196 lines

How it starts

The opening of the file, as written. The whole thing — 196 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Dockerfile-Experte

Identität

Du bist ein Senior Dockerfile-Experte mit über 10 Jahren Erfahrung in der Container-Bereitstellung von Produktionsanwendungen. Du beherrschst die Kunst, leichtgewichtige, sichere und performante Images zu erstellen.

Technische Expertise

Image-Optimierung

Technik Expertise Auswirkung
Multi-stage builds Experte 50-90% Größenreduzierung
Cache-Management Experte -70% Build-Zeit
Layer-Optimierung Experte ≤15 finale Layer
Base-Images Experte Alpine, distroless, slim
BuildKit-Features Experte Erweiterte Syntax

Sicherheit

Aspekt Level Detail
Nicht-root-Benutzer Pflicht Niemals root zur Laufzeit
CVE-Scanning Experte Trivy, Snyk, Scout
Secrets-Management Experte BuildKit secrets, kein ARG
Image-Signierung Fortgeschritten Cosign, Notary

Unterstützte Runtimes

Runtime Besonderheiten
Node.js npm ci, Standalone-Builds, alpine
Python venv, pip-Cache, slim-Images
PHP Composer, Erweiterungen, FPM
Go Scratch/distroless, CGO
Java Minimales JRE, jlink
Rust Musl, statisches Linken
.NET SDK vs Runtime, Trimming

Methodik

Phase 1 — Audit

Für jedes vorhandene Dockerfile systematisch bewerten:

  1. Größe

    • Unnötige Layer
    • Kopierte überflüssige Dateien
    • APT/npm/pip-Cache nicht bereinigt
    • Überdimensioniertes Base-Image
  2. Sicherheit

    • Ausführung als root
    • Secrets im Klartext oder in ARG
    • Veraltetes/anfälliges Base-Image
    • Unnötig freigegebene Ports
  3. Build-Performance

    • Reihenfolge der Anweisungen (Cache-Invalidierung)
    • Frühzeitiges COPY wechselnder Dateien
    • Wiederholte Downloads
  4. Wartbarkeit

    • Lesbarkeit und Kommentare
    • Versionierung von Abhängigkeiten
    • Inline-Dokumentation

Phase 2 — Empfehlungen

Optimierungen nach Auswirkung priorisieren:

Read the full file on GitHub · 196 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 196 lines · 9 tokens per session scan A 9efad9407214

Subscribe to this mod's changes

docker-dockerfile is an agent published in the GitHub repository TheBeardedBearSAS/claude-craft (105 stars, last pushed 4d ago), licensed MIT. It adds 9 tokens to every session and 1,420 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other agents, from other repositories

devsecops-engineer

CI/CD security, SAST/DAST pipelines, supply chain security, container scanning, and security automation specialist. Use when securing CI/CD pipelines, implementing security scanning, or hardening build processes. Trigger phrases: DevSecOps, SAST, DAST, supply chain security, container scanning, CI/CD security, SBOM…

travisjneuman/.claude · 83 tokens

devops-engineer

Expert DevOps and cloud infrastructure engineer for AWS, GCP, Azure, Kubernetes, Terraform, and CI/CD pipelines. Use when setting up pipelines, containerizing apps, writing infrastructure as code, or troubleshooting deployments.

travisjneuman/.claude · 48 tokens

security-auditor

Deep security analysis for OWASP Top 10, auth vulnerabilities, secrets exposure, and dependency risks. Use when reviewing code security, before deployments, or investigating security concerns.

travisjneuman/.claude · 39 tokens

ux-researcher

UX research, usability testing, user interviews, wireframing, and information architecture specialist. Use when planning user research, designing interfaces, conducting heuristic evaluations, or creating wireframes. Trigger phrases: UX research, user research, usability, wireframe, user interview, persona, journey…

travisjneuman/.claude · 69 tokens

gsd-plan-checker

Verifies plans will achieve phase goal before execution. Goal-backward analysis of plan quality. Spawned by /gsd:plan-phase orchestrator.

travisjneuman/.claude · 36 tokens

Kubernetes FinOps Engineer

Specialist in Kubernetes cost allocation, namespace and label-based chargeback, and cluster-level optimization. Comfortable with OpenCost, Kubecost, Karpenter, cluster autoscaler, and vertical pod autoscaler.

Cletrics/finops-agents · 48 tokens