docker-developer

docker-developer is a cursor rule for Cursor from MN-Lizard-Team/aiyu-multi-agent. It costs 80 tokens per session (2,144 once invoked), scanned D, original, Apache-2.0.

Expert in containerization with Docker, Docker Compose, and container best practices. Builds efficient images, multi-stage builds, secure configurations, and production-ready container orchestration. Use for containerizing applications, optimizing image size, or designing container-based architectures. Triggers on…

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/mn-lizard-team/aiyu-multi-agent/docker-developer
Clone the repo
git clone --depth 1 https://github.com/MN-Lizard-Team/aiyu-multi-agent

Made for: Cursor.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for docker-developer

README.md
[![agentmods](https://agentmods.dev/badge/rules/mn-lizard-team/aiyu-multi-agent/docker-developer.svg)](https://agentmods.dev/rules/mn-lizard-team/aiyu-multi-agent/docker-developer)
Your own site
<a href="https://agentmods.dev/rules/mn-lizard-team/aiyu-multi-agent/docker-developer"><img src="https://agentmods.dev/badge/rules/mn-lizard-team/aiyu-multi-agent/docker-developer.svg" alt="Measured on agentmods" height="20"></a>
Per session 80 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,144 The whole file, excluding the scripts and references it only reads on demand.
Security scan D 2 findings. Scan, not verified.
Origin unknown No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00080 $0.02144
Opus 5 $0.00040 $0.01072
Sonnet 5 $0.00016 $0.00429
Haiku 4.5 $0.00008 $0.00214

Measured today against content hash 5940e8cc6a21, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade D, and why

docker-developer scanned grade D with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Asks for rootmediumPrivilege escalation

A mod that escalates privileges can change anything on the machine, not only the project.

# Don't run as root

Recursive force deletehighDestructive command

rm -rf with a variable or a broad path is one typo away from removing the wrong tree.

RUN cargo build --release && rm -rf src
.cursor/rules/agents/docker-developer.mdc · 334 lines

How it starts

The opening of the file, as written. The whole thing — 334 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Agent: docker-developer

Cursor Agent-Requested Rule — invoke via @docker-developer or let the AI auto-select.

Skills: clean-code, bash-linux, deployment-procedures, server-management, containerization Tools: Read, Grep, Glob, Bash, Edit, Write, memory.save, memory.load Model: inherit Memory: session


🤖 Agent Identity

When this agent is activated, you MUST announce:

🤖 Active Agent: docker-developer | Skills: clean-code, bash-linux, deployment-procedures +1 more | Rules: GEMINI, deployment-rules, documentation-rules, security-rules | Sub-agents: No

This announcement is MANDATORY — never skip it.


When to Activate

  • Docker containerization
  • multi-stage builds
  • Docker Compose
  • container architecture
  • image optimization

Docker Developer

Core Philosophy

  • Karpathy Principles: Think before coding, simplicity first, surgical changes, goal-driven execution

"Containers should be ephemeral, portable, and minimal. One process per container, no state inside, treat them as cattle not pets."

Dockerfile Best Practices

Multi-Stage Build

# ─── Build Stage ───
FROM node:20-alpine AS builder
WORKDIR /app
COPY package*.json .
RUN npm ci --only=production

COPY . .
RUN npm run build

# ─── Production Stage ───
FROM node:20-alpine AS runner

# Security: run as non-root
RUN addgroup -g 1001 -S nodejs && \
    adduser -S nextjs -u 1001

WORKDIR /app

# Only copy what's needed
COPY --from=builder --chown=nextjs:nodejs /app/dist ./dist
COPY --from=builder --chown=nextjs:nodejs /app/node_modules ./node_modules
COPY --from=builder --chown=nextjs:nodejs /app/package.json .

USER nextjs

EXPOSE 3000
ENV PORT=3000
ENV NODE_ENV=production

CMD ["node", "dist/main.js"]

Security Hardening

# Use distroless or minimal base
FROM gcr.io/distroless/nodejs20-debian12

# Or minimal alpine
FROM alpine:3.19

# Don't run as root
RUN adduser -D -u 1000 appuser
USER appuser

# Read-only filesystem where possible
# docker run --read-only --tmpfs /tmp:rw,noexec,nosuid,size=50m

# Drop capabilities
# docker run --cap-drop=ALL --cap-add=NET_BIND_SERVICE

Read the full file on GitHub · 334 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today First seen · 334 lines · 80 tokens per session scan D 5940e8cc6a21

Subscribe to this mod's changes

docker-developer is a cursor rule published in the GitHub repository MN-Lizard-Team/aiyu-multi-agent (7 stars, last pushed 3mo ago), licensed Apache-2.0. It adds 80 tokens to every session and 2,144 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it D with 2 findings (asks for root, recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.