owasp/docksec ? reverse-engineered prompt

Reverse engineered prompt

Build me a Docker security scanner that feels easy to use, even if you are not a security expert.

I want to point it at a Dockerfile or container image and get back a simple summary of what is risky, what should be fixed first, and why it matters in plain English. It should run local checks with tools like Trivy, Hadolint, and Docker Scout, then rank the results by severity and likelihood so the most important issues show up first. If AI is enabled, it should explain the findings in a human way and suggest concrete fixes I can copy and run. If AI is not enabled, it should still work in scan only mode.

Please include nice reports I can open or share, like HTML, PDF, JSON, CSV, Markdown, SARIF, and SBOM output. Make sure it works from the command line and also in Docker, with everything happening locally unless I choose to send redacted content to an AI provider.

Are you gonna build this?

make sure you review the code using arcumet

Try freeSponsored — opens Arcumet in a new tab