Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/basejb/skills/dockerfile-optimizernpx skills add basejb/skills --skill dockerfile-optimizergit clone --depth 1 https://github.com/basejb/skillsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00133 | $0.03218 |
| Opus 5 | $0.00067 | $0.01609 |
| Sonnet 5 | $0.00027 | $0.00644 |
| Haiku 4.5 | $0.00013 | $0.00322 |
Grade C, and why
dockerfile-optimizer scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Downloads and executes remote codehighSupply chain
curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.
| DFO-SEC-008 | Security | major | curl ... \| sh pattern | Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
| DFO-SEC-008 | Security | major | curl ... \| sh pattern | The source is not reproduced here
No licence file
A repository with no LICENSE is all rights reserved by default, so the body is not copied here. The metadata, the measurements and the link are.
What ships with it
58 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- README.md 8.8 KB
- references/dockerignore-base.md 1.4 KB
- references/presets-go.md 2.7 KB
- references/presets-nodejs.md 3.4 KB
- references/presets-python.md 2.8 KB
- references/report-template.md 3.1 KB
- references/rules-image-size.md 5.4 KB
- references/rules-performance.md 4.5 KB
- references/rules-reliability.md 4.5 KB
- references/rules-security.md 6.5 KB
- scripts/detect-stack.sh 2.0 KB runs code
- tests/expected/buildkit.md 305 B
- tests/expected/go-bad.md 229 B
- tests/expected/go-good.md 44 B
- tests/expected/multi-dockerfile-repo.md 307 B
- tests/expected/multi-stage-edge.md 269 B
- tests/expected/nodejs-bad.md 989 B
- tests/expected/nodejs-good.md 483 B
- tests/expected/nodejs-native.md 491 B
- tests/expected/python-pip-bad.md 254 B
- tests/expected/python-poetry-good.md 82 B
- tests/expected/python-uv-good.md 78 B
- tests/fixtures/buildkit/Dockerfile 367 B
- tests/fixtures/buildkit/package-lock.json 70 B
- tests/fixtures/buildkit/package.json 57 B
- tests/fixtures/go-bad/Dockerfile 73 B
- tests/fixtures/go-bad/go.mod 32 B
- tests/fixtures/go-good/.dockerignore 63 B
- tests/fixtures/go-good/Dockerfile 521 B
- tests/fixtures/go-good/go.mod 33 B
- tests/fixtures/multi-dockerfile-repo/apps/api/Dockerfile 95 B
- tests/fixtures/multi-dockerfile-repo/apps/api/package.json 220 B
- tests/fixtures/multi-dockerfile-repo/apps/web/.dockerignore 82 B
- tests/fixtures/multi-dockerfile-repo/apps/web/Dockerfile 457 B
- tests/fixtures/multi-dockerfile-repo/apps/web/package-lock.json 82 B
- tests/fixtures/multi-dockerfile-repo/apps/web/package.json 220 B
- tests/fixtures/multi-stage-edge/Dockerfile 177 B
- tests/fixtures/multi-stage-edge/package-lock.json 78 B
- tests/fixtures/multi-stage-edge/package.json 122 B
- tests/fixtures/nodejs-bad/Dockerfile 95 B
- tests/fixtures/nodejs-bad/package.json 227 B
- tests/fixtures/nodejs-good/.dockerignore 82 B
- tests/fixtures/nodejs-good/Dockerfile 457 B
- tests/fixtures/nodejs-good/package-lock.json 90 B
- tests/fixtures/nodejs-good/package.json 228 B
- tests/fixtures/nodejs-native/Dockerfile 87 B
- tests/fixtures/nodejs-native/package.json 104 B
- tests/fixtures/python-pip-bad/Dockerfile 93 B
- tests/fixtures/python-pip-bad/requirements.txt 33 B
- tests/fixtures/python-poetry-good/.dockerignore 90 B
- tests/fixtures/python-poetry-good/Dockerfile 868 B
- tests/fixtures/python-poetry-good/poetry.lock 0 B
- tests/fixtures/python-poetry-good/pyproject.toml 146 B
- tests/fixtures/python-uv-good/.dockerignore 90 B
- tests/fixtures/python-uv-good/Dockerfile 758 B
- tests/fixtures/python-uv-good/pyproject.toml 134 B
- tests/fixtures/python-uv-good/uv.lock 0 B
- tests/test-detect-stack.sh 4.0 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 273 lines · 133 tokens per session scan C ee258aa3b5d3
dockerfile-optimizer is a skill published in the GitHub repository basejb/skills (5 stars, last pushed 10d ago), with no licence file. It adds 133 tokens to every session and 3,218 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it C with 2 findings (downloads and executes remote code, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
rudder-data-graphs
Produces Data Graph YAML from RETL sources for Audiences. Use when designing Data Graphs, mapping RETL to entities/events, or assessing customer fit for Audiences.
rudder-transformations
Creates and manages RudderStack transformations and libraries with local testing. Use when creating, editing, or managing RudderStack transformations and transformation libraries using the Rudder CLI.
rudder-typer-workflow
Generates type-safe SDKs (Swift/Kotlin) from tracking plans with compile-time validation. Use when generating type-safe event tracking code from tracking plans using RudderTyper.
rudder-instrumentation-planning
Designs event taxonomies and instrumentation strategies from business requirements. Use when designing event taxonomy from scratch or restructuring existing instrumentation strategy.
rudder-cli-workflow
Validates, previews, and applies RudderStack resource changes via YAML specs. Use when iterating on RudderStack resources with rudder-cli - validates specs, previews changes with dry-run, and applies changes to workspaces.
rudder-code-first-instrumentation
Derives tracking plans from existing codebase types and structures. Use when instrumenting an existing product that wasn't well-instrumented or restructuring existing tracking.